NA - CVE-2025-47867 - A Local File Inclusion vulnerability in a Trend...
A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an attacker to include arbitrary files to execute as PHP code and lead to remote...
NA - CVE-2025-49219 - An insecure deserialization operation in Trend...
An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this...
NA - CVE-2025-49220 - An insecure deserialization operation in Trend...
An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this...
NA - CVE-2025-34509 - Sitecore Experience Manager (XM) and Experience...
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE...
NA - CVE-2025-34510 - Sitecore Experience Manager (XM), Experience...
Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected by a Zip Slip vulnerability. A remote,...
NA - CVE-2025-34511 - Sitecore PowerShell Extensions, an add-on to...
Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue. A remote,...
NA - CVE-2025-49154 - An insecure access control vulnerability in...
An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have...
NA - CVE-2025-49155 - An uncontrolled search path vulnerability in...
An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to arbitrary code execution on affected...
NA - CVE-2025-49156 - A link following vulnerability in the Trend...
A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privileges on affected installations. Please note: an attacker must first obtain...
NA - CVE-2025-49157 - A link following vulnerability in the Trend...
A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a local attacker to escalation privileges on affected installations. Please note: an attacker must...