Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2017-11386EPSS 24%
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x4707 due to lack of proper user input validatio…
Control Manager
Patch available
CRITICAL 9.8
CVE-2017-11389EPSS 27%
Directory traversal vulnerability in Trend Micro Control Manager 6.0 allows remote code execution by attackers able to drop arbitrary files in a web-…
Control Manager
Patch available
HIGH 8.8
CVE-2017-11388EPSS 14%
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when RestfulServiceUtility.NET.dll doesn't properly validate user provi…
Control Manager
Patch available
HIGH 7.5
CVE-2017-11387EPSS 15%
Authentication Bypass in Trend Micro Control Manager 6.0 causes Information Disclosure when authentication validation is not done for functionality t…
Control Manager
Patch available
HIGH 7.5
CVE-2017-11390
XML external entity (XXE) processing vulnerability in Trend Micro Control Manager 6.0, if exploited, could lead to information disclosure. Formerly Z…
Control Manager
Patch available
CRITICAL 9.8
CVE-2017-11380
Backup archives were found to be encrypted with a static password across different installations, which suggest the same password may be used in all …
Deep Discovery Director
Patch available
CRITICAL 9.8
CVE-2017-11381
A command injection vulnerability exists in Trend Micro Deep Discovery Director 1.1 that allows an attacker to restore accounts that can access the p…
Deep Discovery Director
Patch available
HIGH 7.5
CVE-2017-11379
Configuration and database backup archives are not signed or validated in Trend Micro Deep Discovery Director 1.1.
Deep Discovery Director
Patch available
HIGH 7.8
CVE-2017-9036
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows local users to gain privileges by leveraging an unrestricted quarantine directory.
Serverprotect
Patch available
HIGH 7.4
CVE-2017-9035
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to eavesdrop and tamper with updates by leveraging unencrypted communications…
Serverprotect
Patch available
MEDIUM 6.1
CVE-2017-9037
Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allow remote attackers to inject arbitr…
Serverprotect
Patch available
CRITICAL 9.8
CVE-2017-9034EPSS 6%
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to write to arbitrary files and consequently execute arbitrary code with root…
Serverprotect
Patch available
HIGH 8.8
CVE-2017-9033
Cross-site request forgery (CSRF) vulnerability in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows remote attackers to hijack the authe…
Serverprotect
Patch available
MEDIUM 6.1
CVE-2017-9032
Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allow remote attackers to inject arbitr…
Serverprotect
Patch available
MEDIUM 6.1
CVE-2017-8801
Trend Micro OfficeScan 11.0 before SP1 CP 6325 (with Agent Module Build before 6152) and XG before CP 1352 has XSS via a crafted URI using a blocked …
Officescan
Mitigation only
HIGH 8.8
CVE-2017-5481
Trend Micro OfficeScan 11.0 before SP1 CP 6325 and XG before CP 1352 allows remote authenticated users to gain privileges by leveraging a leak of an …
Officescan
Patch available
CRITICAL 9.8
CVE-2016-8584EPSS 6%
Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication…
Threat Discovery Appliance
after 2.6.1062
HIGH 8.8
CVE-2016-8585EPSS 7%
admin_sys_time.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as th…
Threat Discovery Appliance
after 2.6.1062
HIGH 8.8
CVE-2016-8586EPSS 6%
detected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary …
Threat Discovery Appliance
after 2.6.1062
HIGH 8.8
CVE-2016-8589EPSS 6%
log_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the…
Threat Discovery Appliance
after 2.6.1062
HIGH 8.8
CVE-2016-8590EPSS 6%
log_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the…
Threat Discovery Appliance
after 2.6.1062
HIGH 8.8
CVE-2016-8591EPSS 6%
log_query.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the roo…
Threat Discovery Appliance
after 2.6.1062
HIGH 8.8
CVE-2016-8592EPSS 6%
log_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as …
Threat Discovery Appliance
after 2.6.1062
HIGH 8.8
CVE-2016-8593EPSS 7%
Directory traversal vulnerability in upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to…
Threat Discovery Appliance
after 2.6.1062
HIGH 7.3
CVE-2016-8587
dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code vi…
Threat Discovery Appliance
after 2.6.1062
HIGH 7.3
CVE-2016-8588
The hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code vi…
Threat Discovery Appliance
after 2.6.1062
MEDIUM 6.1
CVE-2017-7896
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 before CP 1644 has XSS.
Interscan Messaging Security Virtual Appliance
after 9.1
CRITICAL 9.8
CVE-2016-7547EPSS 93%
A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cgi interf…
Threat Discovery Appliance
Patch available
CRITICAL 9.8
CVE-2016-7552EPSS 93%
On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated at…
Threat Discovery Appliance
Patch available
MEDIUM 6.5
CVE-2017-6338
Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user…
Interscan Web Security Virtual Appliance
after 6.5