Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
640 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.7) | 0.41% | — | Comodo Antivirus | 28/8/2019 | 17/6/2026 | A use-after-free flaw in the sandbox container implemented in cmdguard.sys in Comodo Antivirus 12.0.0.6870 can be triggered due to a race condition when handling IRP_MJ_CLEANUP requests in the minifilter for directory change notifications. This allows an attacker to cause a denial of service (BSOD) when an executable… | |
| Modificada | Alta (7.8) | 1.2% | — | Trendmicro Antivirus + Security 2019Trendmicro Internet Security 2019Trendmicro Maximum Security 2019Trendmicro Premium Security 2019+1 | 21/8/2019 | 17/6/2026 | A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products (v15) Folder Shield component and the standalone Trend Micro Ransom Buster (1.0) tool in which, if exploited, would allow an attacker to load a malicious DLL, leading to elevated privileges. | |
| Modificada | Alta (7.8) | 0.59% | — | Trendmicro Antivirus + Security 2019Trendmicro Internet Security 2019Trendmicro Maximum Security 2019Trendmicro Premium Security 2019 | 21/8/2019 | 17/6/2026 | A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would allow an attacker to manipulate a specific product feature to load a malicious service. | |
| Modificada | Alta (7.8) | 1.4% | — | Bitdefender Antivirus 2020 | 21/8/2019 | 17/6/2026 | An Untrusted Search Path vulnerability in the ServiceInstance.dll library versions 1.0.15.119 and lower, as used in Bitdefender Antivirus Free 2020 versions prior to 1.0.15.138, allows an attacker to load an arbitrary DLL file from the search path. | |
| Modificada | Media (6.7) | 0.57% | — | Bitdefender Antivirus PlusBitdefender Endpoint Security ToolBitdefender Internet SecurityBitdefender Total Security | 30/7/2019 | 17/6/2026 | An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions prior to 6.6.8.115; and Bitdefender Antivirus Plus, Bitdefender Internet Security, and Bitdefender Total Security versions prior to 23.0.24.120) that can lead to local code injection. A local attacker with… | |
| Modificada | Alta (7.1) | 0.46% | — | Comodo AntivirusComodo FirewallComodo Internet Security | 25/7/2019 | 17/6/2026 | Comodo Antivirus through 12.0.0.6870, Comodo Firewall through 12.0.0.6870, and Comodo Internet Security Premium through 12.0.0.6870, with the Comodo Container feature, are vulnerable to Sandbox Escape. | |
| Modificada | Media (4.4) | 0.54% | — | Avast Antivirus | 18/7/2019 | 17/6/2026 | In Avast Antivirus before 19.4, a local administrator can trick the product into renaming arbitrary files by replacing the Logs\Update.log file with a symlink. The next time the product attempts to write to the log file, the target of the symlink is renamed. This defect can be exploited to rename a critical product… | |
| Modificada | Media (5.5) | 0.39% | — | Comodo Antivirus | 17/7/2019 | 17/6/2026 | Comodo Antivirus versions 11.0.0.6582 and below are vulnerable to Denial of Service affecting CmdGuard.sys via its filter port "cmdServicePort". A low privileged process can crash CmdVirth.exe to decrease the port's connection count followed by process hollowing a CmdVirth.exe instance with malicious code to obtain a… | |
| Modificada | Media (5.5) | 0.39% | — | Comodo Antivirus | 17/7/2019 | 17/6/2026 | Comodo Antivirus versions 12.0.0.6810 and below are vulnerable to Denial of Service affecting CmdAgent.exe via an unprotected section object "<GUID>_CisSharedMemBuff". This section object is exposed by CmdAgent and contains a SharedMemoryDictionary object, which allows a low privileged process to modify the object… | |
| Modificada | Media (5.5) | 0.37% | — | Comodo Antivirus | 17/7/2019 | 17/6/2026 | Comodo Antivirus versions up to 12.0.0.6810 are vulnerable to a local Denial of Service affecting CmdVirth.exe via its LPC port "cmdvrtLPCServerPort". A low privileged local process can connect to this port and send an LPC_DATAGRAM, which triggers an Access Violation due to hardcoded NULLs used for Source parameter in… | |
| Modificada | Media (5.5) | 0.40% | — | Comodo Antivirus | 17/7/2019 | 17/6/2026 | Comodo Antivirus versions up to 12.0.0.6810 are vulnerable to Arbitrary File Write due to Cavwp.exe handling of Comodo's Antivirus database. Cavwp.exe loads Comodo antivirus definition database in unsecured global section objects, allowing a local low privileged process to modify this data directly and change virus… | |
| Modificada | Alta (7.8) | 0.56% | — | Comodo Antivirus | 17/7/2019 | 17/6/2026 | Comodo Antivirus versions up to 12.0.0.6810 are vulnerable to Local Privilege Escalation due to CmdAgent's handling of COM clients. A local process can bypass the signature check enforced by CmdAgent via process hollowing which can then allow the process to invoke sensitive COM methods in CmdAgent such as writing to… | |
| Modificada | Crítica (9.8) | 3.5% | — | Pandasecurity Panda AntivirusPandasecurity Panda Antivirus PROPandasecurity Panda DomePandasecurity Panda Global Protection+2 | 23/5/2019 | 17/6/2026 | Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda products before 18.07.03 allow attackers to queue an event (as an encrypted JSON string) to the system service AgentSvc.exe, which leads to privilege escalation when the… | |
| Modificada | Media (5.5) | 0.32% | — | Symantec Antivirus Engine | 8/5/2019 | 17/6/2026 | Symantec AV Engine, prior to 13.0.9r17, may be susceptible to an arbitrary file deletion issue, which is a type of vulnerability that could allow an attacker to delete files on the resident system without elevated privileges. | |
| Modificada | Alta (8.8) | 4.3% | — | Kaspersky Antivirus Engine | 8/5/2019 | 17/6/2026 | Kaspersky Lab Antivirus Engine version before 04.apr.2019 has a heap-based buffer overflow vulnerability that potentially allow arbitrary code execution | |
| Modificada | Alta (7.8) | 0.31% | — | Avast Free Antivirus | 21/3/2019 | 17/6/2026 | Avast Free Antivirus prior to 19.1.2360 stores user credentials in memory upon login, which allows local users to obtain sensitive information by dumping AvastUI.exe application memory and parsing the data. | |
| Modificada | Media (5.9) | 17% | — | OpensslCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+78 | 27/2/2019 | 17/6/2026 | If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid… | |
| Modificada | Alta (7.8) | 1.8% | 💥 PoC | Trendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security | 5/2/2019 | 17/6/2026 | A DLL hijacking vulnerability in Trend Micro Security 2019 (Consumer) versions below 15.0.0.1163 and below could allow an attacker to manipulate a specific DLL and escalate privileges on vulnerable installations. | |
| Modificada | Media (6.8) | 0.52% | — | Symantec Endpoint ProtectionSymantec Endpoint Protection CloudSymantec Norton Antivirus | 29/11/2018 | 17/6/2026 | Norton prior to 22.15; Symantec Endpoint Protection (SEP) prior to 12.1.7454.7000 & 14.2; Symantec Endpoint Protection Small Business Edition (SEP SBE) prior to NIS-22.15.1.8 & SEP-12.1.7454.7000; and Symantec Endpoint Protection Cloud (SEP Cloud) prior to 22.15.1 may be susceptible to an AV bypass issue, which is a… | |
| Modificada | Alta (7.8) | 0.40% | — | Symantec Endpoint ProtectionSymantec Endpoint Protection CloudSymantec Norton Antivirus | 29/11/2018 | 17/6/2026 | Norton prior to 22.15; Symantec Endpoint Protection (SEP) prior to 12.1.7454.7000 & 14.2; Symantec Endpoint Protection Small Business Edition (SEP SBE) prior to NIS-22.15.1.8 & SEP-12.1.7454.7000; and Symantec Endpoint Protection Cloud (SEP Cloud) prior to 22.15.1 may be susceptible to an AV bypass issue, which is a… | |
| Modificada | Alta (7.8) | 0.58% | — | Trendmicro Antivirus FOR MAC 2017Trendmicro Antivirus FOR MAC 2018Trendmicro Antivirus FOR MAC 2019 | 23/10/2018 | 17/6/2026 | A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. The issue results from the lack of proper validation function on 0x6F4E offset user-supplied… | |
| Modificada | Alta (7.8) | 0.56% | — | Trendmicro Antivirus FOR MAC 2017Trendmicro Antivirus FOR MAC 2018Trendmicro Antivirus FOR MAC 2019 | 23/10/2018 | 17/6/2026 | A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. The issue results from the lack of proper validation function on 0x6F6A offset user-supplied… | |
| Modificada | Alta (7.8) | 0.56% | — | Trendmicro Antivirus FOR MAC 2017Trendmicro Antivirus FOR MAC 2018Trendmicro Antivirus FOR MAC 2019 | 23/10/2018 | 17/6/2026 | A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. The issue results from the lack of proper validation function on 0x6eDC offset user-supplied… | |
| Modificada | Alta (7.8) | 0.56% | — | Trendmicro Antivirus FOR MAC 2017Trendmicro Antivirus FOR MAC 2018Trendmicro Antivirus FOR MAC 2019 | 23/10/2018 | 17/6/2026 | A ctl_set KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target… | |
| Modificada | Alta (7.8) | 0.54% | — | Trendmicro Antivirus FOR MAC 2017Trendmicro Antivirus FOR MAC 2018Trendmicro Antivirus FOR MAC 2019 | 23/10/2018 | 17/6/2026 | A UrlfWTPPagePtr KERedirect Use-After-Free Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system… |