Vulnerability index

Browse CVEs

29 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Endpoint Security HIGH 7.8
CVE-2025-14963

A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system p…

Fix: after 34.0.0
Fix from $1,950 2026-02-24
System Information Reporter MEDIUM 5.5
CVE-2025-3773

A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to …

Fix: after 1.0.3
Fix from $1,600 2025-06-26
System Information Reporter HIGH 7.1
CVE-2025-3771

A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite system f…

Fix: after 1.0.3
Fix from $1,950 2025-06-26
Enterprise Security Manager CRITICAL 9.8
CVE-2024-11482

A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command inject…

No fix yet
Fix from $2,300 2024-11-29
Enterprise Security Manager HIGH 8.2
CVE-2024-11481

A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, inse…

Mitigation only
Fix from $1,950 2024-11-29
Intrusion Prevention System Manager HIGH 7.5
CVE-2024-5957

This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.

Fix: 11.1.7.97+
Fix from $1,950 2024-09-05
Intrusion Prevention System Manager MEDIUM 5.3
CVE-2024-5956

This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manage…

Mitigation only
Fix from $1,600 2024-09-05
Xconsole MEDIUM 5.4
CVE-2024-4176

An Cross site scripting vulnerability in the EDR XConsole before this release allowed an attacker to potentially leverage an XSS/HTML-Injection using…

Fix: after 2024-05-17
Fix from $1,600 2024-06-13
Central Management System MEDIUM 5.4
CVE-2023-6072

A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authenticated attacker to craft CM dashb…

Fix: 9.1.3.97129+
Fix from $1,600 2024-02-13
Endpoint Security Web Control MEDIUM 6.1
CVE-2024-0310

A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response hea…

Fix: 10.7.0+
Fix from $1,600 2024-01-10
Anti Malware Engine HIGH 7.8
CVE-2024-0206

A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to pot…

Mitigation only
Fix from $1,950 2024-01-09
Agent HIGH 7.8
CVE-2024-0213

A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause a Denial o…

Fix: 5.8.1+
Fix from $1,950 2024-01-09
Enterprise Security Manager HIGH 7.2
CVE-2023-6071

An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administrator to execut…

Fix: 11.6.9+
Fix from $1,950 2023-11-30
Application And Change Control HIGH 7.2
CVE-2023-5607

An improper limitation of a path name to a restricted directory (path traversal) vulnerability in the TACC ePO extension, for on-premises ePO servers…

Fix: 8.4.0+
Fix from $1,950 2023-11-27
Getsusp HIGH 7.8
CVE-2023-6119

An Improper Privilege Management vulnerability in Trellix GetSusp prior to version 5.0.0.27 allows a local, low privilege attacker to gain access to …

Fix: 5.0.0.27+
Fix from $1,950 2023-11-16
Endpoint Security HIGH 7.8
CVE-2023-3665

A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component via envir…

Fix: after 10.7.0
Fix from $1,950 2023-10-04
Data Loss Prevention HIGH 7.1
CVE-2023-4814

A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for which the u…

Mitigation only
Fix from $1,950 2023-09-14
Enterprise Security Manager HIGH 8.8
CVE-2023-3314

A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands u…

Fix: 11.6.7+
Fix from $1,950 2023-07-03
Enterprise Security Manager HIGH 7.8
CVE-2023-3313

An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed an unauthor…

Fix: 11.6.7+
Fix from $1,950 2023-07-03
Move HIGH 7.8
CVE-2023-3438

An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install service (mvagtsce.exe). The misconf…

Fix: after 4.10.0
Fix from $1,950 2023-07-03
Agent HIGH 8.1
CVE-2023-1388

A heap-based overflow vulnerability in TA prior to version 5.7.9 allows a remote user to alter the page heap in the macmnsvc process memory block, re…

Fix: 5.7.9+
Fix from $1,950 2023-06-07
Agent HIGH 7.8
CVE-2023-0976

A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file into the /Library/Trellix/Age…

Fix: 5.7.9+
Fix from $1,950 2023-06-07
Agent HIGH 7.8
CVE-2023-0975

A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace o…

Fix: after 5.7.8
Fix from $1,950 2023-04-03
Agent MEDIUM 6.5
CVE-2023-0977

A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote user to alter the page heap in th…

Fix: after 5.7.8
Fix from $1,600 2023-04-03
Data Loss Prevention HIGH 8.2
CVE-2023-0400

The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP controls when …

Fix: 11.10.0+
Fix from $1,950 2023-02-02
Skyhigh Secure Web Gateway MEDIUM 6.1
CVE-2023-0214

A cross-site scripting vulnerability in Skyhigh SWG in main releases 11.x prior to 11.2.6, 10.x prior to 10.2.17, and controlled release 12.x prior t…

Fix: 10.2.17 / 11.2.6+
Fix from $1,600 2023-01-18
Endpoint Security MEDIUM 6.0
CVE-2022-4326

Improper preservation of permissions vulnerability in Trellix Endpoint Agent (xAgent) prior to V35.31.22 on Windows allows a local user with administ…

Fix: 35.31.22+
Fix from $1,600 2022-12-16
Agent MEDIUM 6.7
CVE-2022-3859

An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8. This allows an attacker with admin ac…

Fix: 5.7.8+
Fix from $1,600 2022-11-30
Intrusion Prevention System Manager HIGH 7.2
CVE-2022-3340

XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 allows a remote authenticated administrator to perform XXE attack in …

Fix: 10.1+
Fix from $1,950 2022-11-04