Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
404 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.26% | — | Bitdefender Antivirus | 30/1/2020 | 17/6/2026 | A privilege escalation vulnerability in BDLDaemon as used in Bitdefender Antivirus for Mac allows a local attacker to obtain authentication tokens for requests submitted to the Bitdefender Cloud. This issue affects: Bitdefender Bitdefender Antivirus for Mac versions prior to 8.0.0. | |
| Modificada | Alta (7.8) | 0.65% | — | Bitdefender Endpoint Security Tools | 27/1/2020 | 17/6/2026 | An Untrusted Search Path vulnerability in EPSecurityService.exe as used in Bitdefender Endpoint Security Tools versions prior to 6.6.11.163 allows an attacker to load an arbitrary DLL file from the search path. This issue affects: Bitdefender EPSecurityService.exe versions prior to 6.6.11.163. | |
| Modificada | Crítica (9.8) | 4.2% | — | Bitdefender BOX 2 Firmware | 27/1/2020 | 17/6/2026 | A command injection vulnerability has been discovered in the bootstrap stage of Bitdefender BOX 2, versions 2.1.47.42 and 2.1.53.45. The API method `/api/download_image` unsafely handles the production firmware URL supplied by remote servers, leading to arbitrary execution of system commands. In order to exploit the… | |
| Modificada | Crítica (9.8) | 2.1% | — | Bitdefender BOX 2 FirmwareBitdefender Central | 27/1/2020 | 17/6/2026 | A OS Command Injection vulnerability in the bootstrap stage of Bitdefender BOX 2 allows the manipulation of the `get_image_url()` function in special circumstances to inject a system command. | |
| Modificada | Media (5.5) | 0.26% | — | Bitdefender Antivirus | 27/1/2020 | 17/6/2026 | An Incorrect Default Permissions vulnerability in the BDLDaemon component of Bitdefender AV for Mac allows an attacker to elevate permissions to read protected directories. This issue affects: Bitdefender AV for Mac versions prior to 8.0.0. | |
| Modificada | Alta (8.1) | 1.9% | — | Bitdefender BOX 2 Firmware | 27/1/2020 | 17/6/2026 | An exploitable command execution vulnerability exists in the recovery partition of Bitdefender BOX 2, version 2.0.1.91. The API method `/api/update_setup` does not perform firmware signature checks atomically, leading to an exploitable race condition (TOCTTOU) that allows arbitrary execution of system commands. This… | |
| Modificada | Media (6.5) | 0.34% | — | Bitdefender Total Security 2020 | 27/1/2020 | 17/6/2026 | An Untrusted Search Path vulnerability in bdserviceshost.exe as used in Bitdefender Total Security 2020 allows an attacker to execute arbitrary code. This issue does not affect: Bitdefender Total Security versions prior to 24.0.12.69. | |
| Modificada | Alta (7.8) | 0.33% | — | Bitdefender BOX Firmware | 31/10/2019 | 17/6/2026 | An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that allows an attacker to pass arbitrary code to the BOX appliance via the web API. In order to exploit this vulnerability, an attacker needs presence in Bitdefender BOX setup network and Bitdefender BOX be in setup mode. | |
| Modificada | Media (4.4) | 0.32% | — | Bitdefender BOX Firmware | 17/10/2019 | 17/6/2026 | An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that affects the general reliability of the product. Specially crafted packets sent to the miniupnpd implementation in result in the device allocating memory without freeing it later. This behavior can cause the miniupnpd component to… | |
| Modificada | Alta (7.5) | 4.1% | — | Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection | 23/9/2019 | 17/6/2026 | A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denial of Service Vulnerability'. | |
| Modificada | Alta (7.8) | 1.4% | — | Bitdefender Antivirus 2020 | 21/8/2019 | 17/6/2026 | An Untrusted Search Path vulnerability in the ServiceInstance.dll library versions 1.0.15.119 and lower, as used in Bitdefender Antivirus Free 2020 versions prior to 1.0.15.138, allows an attacker to load an arbitrary DLL file from the search path. | |
| Modificada | Alta (7.1) | 0.95% | — | Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection | 14/8/2019 | 17/6/2026 | An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted command that could exploit the vulnerability and delete… | |
| Modificada | Media (6.7) | 0.57% | — | Bitdefender Antivirus PlusBitdefender Endpoint Security ToolBitdefender Internet SecurityBitdefender Total Security | 30/7/2019 | 17/6/2026 | An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions prior to 6.6.8.115; and Bitdefender Antivirus Plus, Bitdefender Internet Security, and Bitdefender Total Security versions prior to 23.0.24.120) that can lead to local code injection. A local attacker with… | |
| Modificada | Alta (8.8) | 3.7% | — | Bitdefender Safepay | 3/6/2019 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of… | |
| Modificada | Alta (8.8) | 3.8% | — | Bitdefender Safepay | 3/6/2019 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of… | |
| Modificada | Alta (8.8) | 3.7% | — | Bitdefender Safepay | 3/6/2019 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of… | |
| Modificada | Media (5.3) | 0.97% | — | Bitdefender Scan Engines | 24/5/2019 | 17/6/2026 | An issue was discovered in Bitdefender Engines before 7.76808. A vulnerability has been discovered in the dalvik.xmd parser that results from a lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. Paired with other vulnerabilities, this can result in… | |
| Modificada | Media (5.3) | 0.97% | — | Bitdefender Scan Engines | 24/5/2019 | 17/6/2026 | An issue was discovered in Bitdefender Engines before 7.76675. A vulnerability has been discovered in the rar.xmd parser that results from a lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. Paired with other vulnerabilities, this can result in… | |
| Modificada | Media (5.3) | 0.93% | — | Bitdefender Scan Engines | 24/5/2019 | 17/6/2026 | An issue was discovered in Bitdefender Engines before 7.76662. A vulnerability has been discovered in the iso.xmd parser that results from a lack of proper validation of user-supplied data, which can result in a division-by-zero circumstance. Paired with other vulnerabilities, this can result in denial-of-service.… | |
| Modificada | Crítica (9.8) | 1.5% | — | Bitdefender Gravityzone | 30/10/2018 | 17/6/2026 | Bitdefender GravityZone VMware appliance before 6.2.1-35 might allow attackers to gain access with root privileges via unspecified vectors. | |
| Modificada | Crítica (9.8) | 4.3% | — | Bitdefender Gravityzone | 24/10/2018 | 17/6/2026 | The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which allows remote attackers to execute arbitrary code by changing the filename while leaving the file's digital signature unchanged. | |
| Modificada | Alta (7.8) | 0.95% | — | Opswat Metadefender | 31/8/2018 | 17/6/2026 | OPSWAT MetaDefender before v4.11.2 allows CSV injection. | |
| Modificada | Alta (8.8) | 63% | 💥 Exploit | Microsoft Exchange ServerMicrosoft Security EssentialsMicrosoft Forefront Endpoint Protection 2010Microsoft Intune Endpoint Protection+2 | 4/4/2018 | 17/6/2026 | A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender, Windows Intune Endpoint Protection,… | |
| Modificada | Alta (7.8) | 0.29% | — | Bitdefender Total Security | 12/3/2018 | 17/6/2026 | BitDefender Total Security 2018 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of an "insecurely created named pipe". Ensures full access to Everyone users group. | |
| Modificada | Alta (8.8) | 3.7% | — | Bitdefender Internet Security 2018 | 21/12/2017 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender Internet Security 2018. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within emulator 0x102 in… |