Vulnerability Database

309,359

Total vulnerabilities in the database

CVE-2025-47867

A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an attacker to include arbitrary files to execute as PHP code and lead to remote code execution on affected installations.

  • Published: Jun 17, 2025
  • Updated: Nov 16, 2025
  • CVE: CVE-2025-47867
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CWEs:

Software From Fixed in
trendmicro / apex_central 2019 2019.x
trendmicro / apex_central 2019-build_3752 2019-build_3752.x
trendmicro / apex_central 2019-build_5158 2019-build_5158.x
trendmicro / apex_central 2019-build_6016 2019-build_6016.x
trendmicro / apex_central 2019-build_6288 2019-build_6288.x
trendmicro / apex_central 2019-build_6394 2019-build_6394.x
trendmicro / apex_central 2019-build_6481 2019-build_6481.x
trendmicro / apex_central 2019-build_6511 2019-build_6511.x
trendmicro / apex_central 2019-build_6571 2019-build_6571.x
trendmicro / apex_central 2019-build_6658 2019-build_6658.x
trendmicro / apex_central 2019-build_6660 2019-build_6660.x
trendmicro / apex_central 2019-build_6890 2019-build_6890.x