CVE Tools

Trellix

10 CVEs tracked since 2023. Since Jul 2023, none of them reached CISA KEV.

Trellix CVEs per month

Jul 2023 to Nov 2023. Point at a month, or focus the strip and use the arrow keys.
Trellix CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-0740
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-1160

Products

The products that kept showing up in Trellix's monthly top three, with their CVEs summed over those months.

  1. Enterprise Security Manager42 months
  2. Epolicy Orchestrator21 month
  3. Esm11 month
  4. Move11 month
  5. Trellix Epo11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Trellix.

  1. CVE-2026-12588An attacker with access to an HX 10.0.0  and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger decompression of a large file that con...—
  2. CVE-2025-7958A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can execute arbitrary code using the web interface and Alert artifact details.—
  3. CVE-2025-14963A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system privileges. Utilization of a Bring Your Own Vuln...7.8
  4. CVE-2025-0664A locally authenticated, privileged user can craft a malicious OpenSSL configuration file, potentially leading the agent to load an arbitrary local library. This may impair endpoint defenses and al...—
  5. CVE-2025-5967A stored cross-site scripting vulnerability in ENS HX 10.0.4 allows a malicious user to inject arbitrary HTML into the ENS HX Malware Scan Name field, resulting in the exposure of sensitive data.—
  6. CVE-2025-3773A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to extract sensitive information stored in a regist...5.5
  7. CVE-2025-3722A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privileged user to issue malicious ePO post requests to System Information Report...4.4
  8. CVE-2025-3771A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite system files with SIR backup files, which can potentiall...7.1
  9. CVE-2025-0618A malicious third party could invoke a persistent denial of service vulnerability in FireEye EDR agent by sending a specially-crafted tamper protection event to the HX service to trigger an excepti...6.5
  10. CVE-2025-0617An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger file parsing containing exponential en...5.9
  11. CVE-2024-5955Cross-site scripting vulnerability in Trellix ePolicy Orchestrator prior to ePO 5.10 Service Pack 1 Update 3 allows a remote authenticated attacker to craft requests causing arbitrary content to be...5.4
  12. CVE-2024-9679A Hardcoded Cryptographic key vulnerability existed in DLP Extension 11.11.1.3 which allowed the decryption of previously encrypted user credentials.5.3
  13. CVE-2024-9678An SQL Injection vulnerability existed in DLP Extension 11.11.1.3. The vulnerability allowed an attacker to perform arbitrary SQL queries potentially leading to command execution.4.9
  14. CVE-2024-11482A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.9.8
  15. CVE-2024-11481A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, insecure forwarding to an AJP backend without adequa...8.2

The record

Peak rank
#130 in Nov 2023
Busiest month shown
Nov 2023, 6 CVEs
Months with a KEV entry
0 since Jul 2023
Monthly snapshots
2 since 2023
Trellix's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store