Currently exploited vulnerabilities

CVE ID CVSS3.1 Exploitable Vendor Product Vulnerability Date added
CVE-2025-54948 9.4 True Trend Micro Apex One Trend Micro Apex One OS Command Injection Vulnerability 2025-08-18 00:00:00
CVE-2023-41179 7.2 True Trend Micro Apex One and Worry-Free Business Security Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability 2023-09-21 00:00:00
CVE-2022-40139 7.2 True Trend Micro Apex One and Apex One as a Service Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability 2022-09-15 00:00:00
CVE-2022-26871 9.8 True Trend Micro Apex Central Trend Micro Apex Central Arbitrary File Upload Vulnerability 2022-03-31 00:00:00
CVE-2021-36741 8.8 True Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security Trend Micro Multiple Products Improper Input Validation Vulnerability 2021-11-03 00:00:00
CVE-2021-36742 7.8 True Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security Trend Micro Multiple Products Improper Input Validation Vulnerability 2021-11-03 00:00:00
CVE-2020-8599 9.8 True Trend Micro Apex One and OfficeScan Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability 2021-11-03 00:00:00
CVE-2020-24557 7.8 True Trend Micro Apex One, OfficeScan, and Worry-Free Business Security Trend Micro Multiple Products Improper Access Control Vulnerability 2021-11-03 00:00:00
CVE-2020-8468 8.8 True Trend Micro Apex One, OfficeScan and Worry-Free Business Security Agents Trend Micro Multiple Products Content Validation Escape Vulnerability 2021-11-03 00:00:00
CVE-2020-8467 8.8 True Trend Micro Apex One and OfficeScan Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability 2021-11-03 00:00:00
CVE-2019-18187 8.8 True Trend Micro OfficeScan Trend Micro OfficeScan Directory Traversal Vulnerability 2021-11-03 00:00:00

AVET INS is an owner of VULNDBASE brand and website. This product uses data from the NVD API but is not endorsed or certified by the NVD. See NVD page for more information. CVE is a registered trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE site. CWE is a registered trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE page. KEV (Known Exploited Vulnerabilities) is a catalog maintained by CISA. EUVD is the official EU repository for timely, curated cybersecurity vulnerability intelligence and remediation guidance run by ENISA. DORA (Digital Operational Resilience Act) is and EU directive.

Copyright AVET INS 1997 - 2026