Products › IT administration and security
IT administration and security
Security products
Antivirus, EDR, SIEM, sandboxes and other security tools: attackers target them too.
For example: Microsoft Defender, Trend Micro, FortiSandbox, Splunk.
-
8 vulnerabilities added in the last 12 months
-
30 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
Affected brands
In alphabetical order, with their number of vulnerabilities in this category.
- Fortinet 2 vulnerabilities · 2 in the last 12 months
- Fortra 2 vulnerabilities
- IBM 3 vulnerabilities
- McAfee 1 vulnerability
- Microsoft 6 vulnerabilities · 3 in the last 12 months
- Sophos 1 vulnerability
- Splunk 1 vulnerability · 1 in the last 12 months
- TeamT5 1 vulnerability · 1 in the last 12 months
- Trend Micro 12 vulnerabilities · 1 in the last 12 months
- Wazuh 1 vulnerability
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
See also
- Monitoring, ITSM and asset management 78 vulnerabilities
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.
Rank 1Fortinet FortiSandbox
CVE-2026-25089Hunt for compromise (CISA)
Fortinet FortiSandbox OS Command Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jul 16, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 2Fortinet FortiSandbox
CVE-2026-39808Hunt for compromise (CISA)
Fortinet FortiSandbox OS Command Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jul 16, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 3Splunk Enterprise
CVE-2026-20253Splunk Enterprise Missing Authentication for Critical Function Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jun 18, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 4Microsoft Defender
CVE-2026-41091Microsoft Defender Link Following Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- May 20, 2026
- CISA deadline
- 14 days
- CVSS severity
- 7.8 (high)
Rank 5Microsoft Defender
CVE-2026-33825Ransomware
Microsoft Defender Insufficient Granularity of Access Control Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Apr 22, 2026
- CISA deadline
- 14 days
- CVSS severity
- 7.8 (high)
Rank 6Microsoft Defender
CVE-2026-45498Microsoft Defender Denial of Service Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- May 20, 2026
- CISA deadline
- 14 days
- CVSS severity
- 7.5 (high)
Rank 7TeamT5 ThreatSonar Anti-Ransomware
CVE-2024-7694CVE from 2024, added in 2026
TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Feb 17, 2026
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Rank 8Trend Micro Apex One (ex-OfficeScan)
CVE-2026-34926Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- May 21, 2026
- CISA deadline
- 14 days
- CVSS severity
- 6.7 (medium)
Rank 9Wazuh Server
CVE-2025-24016Wazuh Server Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 10, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.9 (critical)
Rank 10Trend Micro Apex One (ex-OfficeScan)
CVE-2025-54948Trend Micro Apex One OS Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 18, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Show 20 more vulnerabilities
Rank 11Sophos Web Appliance
CVE-2023-1671Sophos Web Appliance Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 16, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 12Fortra Cobalt Strike
CVE-2022-42948Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 30, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 13Trend Micro Apex Central
CVE-2022-26871Trend Micro Apex Central Arbitrary File Upload Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 31, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 14IBM Data Risk Manager
CVE-2020-4427IBM Data Risk Manager Security Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 15Trend Micro Apex One (ex-OfficeScan)
CVE-2020-8599Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 16IBM Data Risk Manager
CVE-2020-4428IBM Data Risk Manager Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.1 (critical)
Rank 17Trend Micro Apex One (ex-OfficeScan)
CVE-2020-8467Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 8.8 (high)
Rank 18Trend Micro Apex One (ex-OfficeScan)
CVE-2020-8468Trend Micro Multiple Products Content Validation Escape Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 8.8 (high)
Rank 19Trend Micro Apex One (ex-OfficeScan)
CVE-2021-36741Trend Micro Multiple Products Improper Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 8.8 (high)
Rank 20Microsoft Defender
CVE-2017-8540CVE from 2017, added in 2022
Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 21Trend Micro Apex One (ex-OfficeScan)
CVE-2020-24557Trend Micro Multiple Products Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.8 (high)
Rank 22Microsoft Defender
CVE-2021-1647Microsoft Defender Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 7.8 (high)
Rank 23McAfee Total Protection (MTP)
CVE-2021-23874McAfee Total Protection (MTP) Improper Privilege Management Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 7.8 (high)
Rank 24Trend Micro Apex One (ex-OfficeScan)
CVE-2021-36742Trend Micro Multiple Products Improper Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 7.8 (high)
Rank 25Trend Micro Apex One (ex-OfficeScan)
CVE-2019-18187CVE from 2019, added in 2021
Trend Micro OfficeScan Directory Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.5 (high)
Rank 26Trend Micro Apex One (ex-OfficeScan)
CVE-2023-41179Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 21, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Rank 27Trend Micro Apex One (ex-OfficeScan)
CVE-2022-40139Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 15, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Rank 28Fortra Cobalt Strike
CVE-2022-39197Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 30, 2023
- CISA deadline
- 21 days
- CVSS severity
- 6.1 (medium)
Rank 29Microsoft Defender
CVE-2022-44698Ransomware
Microsoft Defender SmartScreen Security Feature Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 13, 2022
- CISA deadline
- 21 days
- CVSS severity
- 5.4 (medium)
Rank 30IBM Data Risk Manager
CVE-2020-4430IBM Data Risk Manager Directory Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 4.3 (medium)
Follow and verify
Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.