Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
251 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.33% | — | Watchdog Anti-virus | 17/3/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Watchdog Anti-Virus 1.4.214.0. Affected by this vulnerability is the function 0x80002004/0x80002008 in the library wsdk-driver.sys of the component IoControlCode Handler. The manipulation leads to denial of service. An attack has to be approached locally. The… | |
| Modificada | Media (6.5) | 0.68% | — | Watchdog Anti-virus | 4/11/2022 | 17/6/2026 | Incorrect access control in the anti-virus driver wsdkd.sys of Watchdog Antivirus v1.4.158 allows attackers to write arbitrary files. | |
| Modificada | Alta (7.8) | 0.47% | — | Watchdog Anti-virus | 16/9/2022 | 17/6/2026 | Incorrect access control in Watchdog Anti-Virus v1.4.158 allows attackers to perform a DLL hijacking attack and execute arbitrary code via a crafted binary. | |
| Modificada | Crítica (9.8) | 3.1% | — | Kaspersky Anti-virusKaspersky Endpoint SecurityKaspersky Internet SecurityKaspersky Security Cloud+2 | 1/4/2022 | 17/6/2026 | Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data parsing module that potentially allowed an attacker to execute arbitrary code. The fix was delivered automatically. Credits: Georgy Zaytsev (Positive Technologies). | |
| Modificada | Media (5.5) | 0.20% | — | Kaspersky Anti-virusKaspersky Endpoint SecurityKaspersky Internet SecurityKaspersky Security Cloud+2 | 1/4/2022 | 17/6/2026 | A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security. A local user could cause Windows crash by running a specially crafted binary module. The fix was delivered automatically. Credits: (Straghkov Denis, Kurmangaleev Shamil,… | |
| Modificada | Alta (8.8) | 2.4% | — | Escanav Escan Anti-virus | 1/4/2022 | 17/6/2026 | An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerability is due to invalid arguments and insufficient execution conditions related to "runasroot" command. This vulnerability can induce remote attackers to exploit root privileges by manipulating parameter values. | |
| Modificada | Alta (8.8) | 2.0% | — | Anti-virus FOR Sophos CentralAnti-virus FOR Sophos Home | 17/4/2020 | 17/6/2026 | Mac Endpoint for Sophos Central before 9.9.6 and Mac Endpoint for Sophos Home before 2.2.6 allow Privilege Escalation. | |
| Modificada | Media (6.1) | 2.1% | — | Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+1 | 26/11/2019 | 17/6/2026 | Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component did not adequately inform the user about the threat of redirecting to an untrusted site. Bypass. | |
| Modificada | Media (6.5) | 1.6% | — | Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+1 | 26/11/2019 | 17/6/2026 | Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component was vulnerable to remote disclosure of various information about the user's system (like Windows version and version… | |
| Modificada | Media (4.3) | 0.77% | — | Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+1 | 26/11/2019 | 17/6/2026 | Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attacker remotely disable various anti-virus protection features. DoS, Bypass. | |
| Modificada | Media (4.3) | 0.84% | — | Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+1 | 26/11/2019 | 17/6/2026 | Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attacker remotely disable such product's security features as private browsing and anti-banner. Bypass. | |
| Modificada | Media (6.7) | 0.66% | — | Mcafee Anti-virus PlusMcafee Internet SecurityMcafee Total Protection | 13/11/2019 | 17/6/2026 | A Privilege Escalation vulnerability in the Microsoft Windows client in McAfee Total Protection 16.0.R22 and earlier allows administrators to execute arbitrary code via carefully placing malicious files in specific locations protected by administrator permission. | |
| Modificada | Media (6.1) | 0.85% | — | AVG Anti-virus | 1/11/2019 | 17/6/2026 | A Cross Site Scripting (XSS) issue exists in AVG AntiVirus (Internet Security Edition) 19.3.3084 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to execute JavaScript code via an SSID Name. | |
| Modificada | Media (5.5) | 0.38% | — | Totaldefense Anti-virus | 31/10/2019 | 17/6/2026 | The quarantine restoration function in Total Defense Anti-virus 11.5.2.28 is vulnerable to symbolic link attacks, allowing files to be written to privileged directories. | |
| Modificada | Media (5.9) | 0.56% | — | Totaldefense Anti-virus | 31/10/2019 | 17/6/2026 | The malware scan function in Total Defense Anti-virus 11.5.2.28 is vulnerable to a TOCTOU bug; consequently, symbolic link attacks allow privileged files to be deleted. | |
| Modificada | Alta (7.8) | 0.55% | — | Avast AntivirusAVG Anti-virus | 23/10/2019 | 17/6/2026 | An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8. A DLL Preloading vulnerability allows an attacker to implant %WINDIR%\system32\wbemcomn.dll, which is loaded into a protected-light process (PPL) and might bypass some of the self-defense mechanisms. This affects all components that… | |
| Modificada | Alta (7.8) | 0.59% | — | Totaldefense Anti-virus | 24/9/2019 | 17/6/2026 | In Total Defense Anti-virus 9.0.0.773, resource acquisition from the untrusted search path C:\ used by caschelp.exe allows local attackers to hijack ccGUIFrm.dll, which leads to code execution. SYSTEM-level code execution can be achieved when the ccSchedulerSVC service runs the affected executable. | |
| Modificada | Alta (7.8) | 0.38% | — | Totaldefense Anti-virus | 24/9/2019 | 17/6/2026 | In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS\9\bd\TDUpdate2\ used by AMRT.exe allows local attackers to hijack bdcore.dll, which leads to privilege escalation when the AMRT service loads the DLL. | |
| Modificada | Alta (7.8) | 0.36% | — | Totaldefense Anti-virus | 24/9/2019 | 17/6/2026 | In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS\9\ used by ccschedulersvc.exe allows local attackers to hijack dotnetproxy.exe, which leads to privilege escalation when the ccSchedulerSVC service runs the executable. | |
| Modificada | Media (4.3) | 2.2% | — | Kaspersky Anti-virusKaspersky Free Anti-virusKaspersky Internet SecurityKaspersky Small Office Security+1 | 18/7/2019 | 17/6/2026 | Information Disclosure in Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security versions up to 2019 could potentially disclose unique Product ID by forcing victim to visit a specially crafted webpage (for example, via clicking phishing link). Vulnerability has CVSS v3.0 base score 2.6 | |
| Modificada | Crítica (9.8) | 1.5% | — | Escanav Escan Anti-virus | 20/12/2018 | 17/6/2026 | eScan Agent Application (MWAGENT.EXE) 4.0.2.98 in MicroWorld Technologies eScan 14.0 allows remote or local attackers to execute arbitrary commands by sending a carefully crafted payload to TCP port 2222. | |
| Modificada | Media (4.4) | 0.53% | — | Mcafee Anti-virus PlusMcafee Endpoint SecurityMcafee Host Intrusion PreventionMcafee Internet Security+2 | 3/4/2018 | 17/6/2026 | Maliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee process via manipulation of registry parameters. | |
| Modificada | Alta (7.8) | 0.40% | — | Escanav Anti-virus | 25/1/2018 | 17/6/2026 | In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x8300210C. | |
| Modificada | Alta (7.8) | 0.40% | — | Escanav Anti-virus | 25/1/2018 | 17/6/2026 | In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020F8. | |
| Modificada | Alta (7.8) | 0.40% | — | Escanav Anti-virus | 25/1/2018 | 17/6/2026 | In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020E0 or 0x830020E4. |