Vulnerability index

Browse CVEs

541 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Email Encryption Gateway HIGH 8.8
CVE-2018-10354EPSS 13%

A command injection remote command execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbit…

Fix: after 5.5
Fix from $1,950 2018-05-23
Email Encryption Gateway HIGH 8.8
CVE-2018-10356EPSS 10%

A SQL injection remote code execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to execute arbitrary SQL stat…

Fix: after 5.5
Fix from $1,950 2018-05-23
Endpoint Application Control HIGH 8.8
CVE-2018-10357EPSS 73%

A directory traversal vulnerability in Trend Micro Endpoint Application Control 2.0 could allow a remote attacker to execute arbitrary code on vulner…

Mitigation only
Fix from $1,950 2018-05-23
Email Encryption Gateway HIGH 7.0
CVE-2018-10355

An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover user passwords on vulnerable …

Fix: after 5.5
Fix from $1,950 2018-05-23
Email Encryption Gateway MEDIUM 6.5
CVE-2018-10353

A SQL injection information disclosure vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to disclose sensitive …

Fix: after 5.5
Fix from $1,600 2018-05-23
Email Encryption Gateway CRITICAL 9.8
CVE-2018-6228EPSS 10%

A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload a…

Patch available
Fix from $2,300 2018-03-15
Email Encryption Gateway CRITICAL 9.8
CVE-2018-6229EPSS 10%

A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker to execute SQL commands to up…

Patch available
Fix from $2,300 2018-03-15
Smart Protection Server CRITICAL 9.8
CVE-2018-6231EPSS 7%

A server auth command injection authentication bypass vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.3 and below could …

Fix: after 3.3
Fix from $2,300 2018-03-15
Email Encryption Gateway MEDIUM 6.8
CVE-2018-6230

A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 search configuration script could allow an attacker to execute SQL comma…

Patch available
Fix from $1,600 2018-03-15
Email Encryption Gateway MEDIUM 5.4
CVE-2018-6226

Reflected cross-site scripting (XSS) vulnerabilities in two Trend Micro Email Encryption Gateway 5.5 configuration files could allow an attacker to i…

Patch available
Fix from $1,600 2018-03-15
Email Encryption Gateway MEDIUM 5.4
CVE-2018-6227

A stored cross-site scripting (XSS) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject client-side scripts i…

Patch available
Fix from $1,600 2018-03-15
Email Encryption Gateway CRITICAL 9.8
CVE-2018-6220EPSS 10%

An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbitrary data, which may lead to…

Patch available
Fix from $2,300 2018-03-15
Email Encryption Gateway CRITICAL 9.8
CVE-2018-6223EPSS 10%

A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to manipulate t…

Patch available
Fix from $2,300 2018-03-15
Email Encryption Gateway HIGH 8.8
CVE-2018-6224

A lack of cross-site request forgery (CSRF) protection vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to submit au…

Patch available
Fix from $1,950 2018-03-15
Email Encryption Gateway HIGH 8.1
CVE-2018-6221EPSS 6%

An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle attacker to tamper with an u…

Patch available
Fix from $1,950 2018-03-15
Email Encryption Gateway HIGH 7.8
CVE-2018-6222

Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log files and be manipulated to exe…

Patch available
Fix from $1,950 2018-03-15
Email Encryption Gateway MEDIUM 6.5
CVE-2018-6219

An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdrop and tamper with certain ty…

No fix yet
Fix from $1,600 2018-03-15
Interscan Messaging Security Virtual Appliance HIGH 8.1
CVE-2018-3609EPSS 21%

A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could allow an unauthenticated user t…

No fix yet
Fix from $1,950 2018-02-16
Deep Security HIGH 7.0
CVE-2018-6218

A DLL Hijacking vulnerability in Trend Micro's User-Mode Hooking Module (UMH) could allow an attacker to run arbitrary code on a vulnerable system.

Mitigation only
Fix from $1,950 2018-02-16
Control Manager HIGH 8.8
CVE-2018-3606EPSS 49%

XXXStatusXXX, XXXSummary, TemplateXXX and XXXCompliance method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manag…

Patch available
Fix from $1,950 2018-02-09
Control Manager HIGH 8.8
CVE-2018-3607EPSS 14%

XXXTreeNode method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to exec…

Patch available
Fix from $1,950 2018-02-09
Control Manager CRITICAL 9.8
CVE-2018-3601

A password hash usage authentication bypass vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to bypass authentication o…

Patch available
Fix from $2,300 2018-02-09
Control Manager HIGH 8.8
CVE-2018-3602EPSS 8%

An AdHocQuery_Processor SQL injection remote code execution (RCE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to e…

Patch available
Fix from $1,950 2018-02-09
Control Manager HIGH 8.8
CVE-2018-3603EPSS 8%

A CGGIServlet SQL injection remote code execution (RCE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arb…

Patch available
Fix from $1,950 2018-02-09
Control Manager HIGH 8.8
CVE-2018-3604EPSS 68%

GetXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute a…

Patch available
Fix from $1,950 2018-02-09
Control Manager HIGH 8.8
CVE-2018-3605EPSS 20%

TopXXX, ViolationXXX, and IncidentXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow…

Patch available
Fix from $1,950 2018-02-09
Control Manager MEDIUM 6.5
CVE-2018-3600

A external entity processing information disclosure (XXE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to disclose …

Patch available
Fix from $1,600 2018-02-09
Smart Protection Server CRITICAL 9.8
CVE-2017-14094EPSS 19%

A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command executio…

Fix: after 3.2
Fix from $2,300 2018-01-19
Smart Protection Server CRITICAL 9.8
CVE-2017-14097EPSS 13%

An improper access control vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to decryp…

Fix: after 3.2
Fix from $2,300 2018-01-19
Smart Protection Server HIGH 8.8
CVE-2017-11398EPSS 8%

A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauth…

Fix: after 3.2
Fix from $1,950 2018-01-19