Skip to main content

Vendor/product archive

trendmicro / apex_central CVEs

Beta · best-effort

35 CVEs tagged to trendmicro / apex_central4 Critical, 10 High, 21 Medium, 0 Low, 0 Unrated.

CVE-2025-30679

Published Jun 17, 2025

A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modOSCE component could allow an attacker to manipulate certain parameters leading to i…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-30678

Published Jun 17, 2025

A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modTMSM component could allow an attacker to manipulate certain parameters leading to i…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-49220

Published Jun 17, 2025

An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note t…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-49219

Published Jun 17, 2025

An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-47867

Published Jun 17, 2025

A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an attacker to include arbitrary files to execute as PHP code and…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-52331

Published Jan 23, 2024

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central could allow an attacker to interact with internal or local services directly.…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-52329

Published Jan 23, 2024

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-52328

Published Jan 23, 2024

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-52327

Published Jan 23, 2024

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-52326

Published Jan 23, 2024

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-52325

Published Jan 23, 2024

A local file inclusion vulnerability in one of Trend Micro Apex Central's widgets could allow a remote attacker to execute arbitrary code on affected installations. Please note…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-52324

Published Jan 23, 2024

An unrestricted file upload vulnerability in Trend Micro Apex Central could allow a remote attacker to create arbitrary files on affected installations. Please note: although a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38627

Published Jan 23, 2024

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38626

Published Jan 23, 2024

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38625

Published Jan 23, 2024

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38624

Published Jan 23, 2024

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32605

Published Jun 26, 2023

Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and san…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32604

Published Jun 26, 2023

Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and san…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32537

Published Jun 26, 2023

Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and san…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 35 CVEsPage 1 of 2