Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
281 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.32% | — | Maxpcsecure Anti Virus Plus | 18/3/2023 | 17/6/2026 | A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. It has been declared as problematic. This vulnerability affects the function 0x220019 in the library MaxProc64.sys of the component IoControlCode Handler. The manipulation of the argument SystemBuffer leads to denial of service. Attacking locally is a… | |
| Modificada | Media (5.5) | 0.30% | — | Maxpcsecure Anti Virus Plus | 18/3/2023 | 17/6/2026 | A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. It has been classified as critical. This affects the function 0x220020 in the library MaxCryptMon.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. Local access is required to approach this attack. The… | |
| Modificada | Media (5.5) | 0.30% | — | Maxpcsecure Anti Virus Plus | 18/3/2023 | 17/6/2026 | A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1 and classified as critical. Affected by this issue is the function 0x220020 in the library SDActMon.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. An attack has to be approached locally. The exploit has… | |
| Modificada | Alta (7.1) | 0.33% | — | Watchdog Anti-virus | 17/3/2023 | 17/6/2026 | A vulnerability was found in Watchdog Anti-Virus 1.4.214.0. It has been rated as critical. Affected by this issue is the function 0x80002008 in the library wsdk-driver.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. Attacking locally is a requirement. The exploit has… | |
| Modificada | Media (5.5) | 0.33% | — | Watchdog Anti-virus | 17/3/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Watchdog Anti-Virus 1.4.214.0. Affected by this vulnerability is the function 0x80002004/0x80002008 in the library wsdk-driver.sys of the component IoControlCode Handler. The manipulation leads to denial of service. An attack has to be approached locally. The… | |
| Modificada | Media (6.5) | 0.68% | — | Watchdog Anti-virus | 4/11/2022 | 17/6/2026 | Incorrect access control in the anti-virus driver wsdkd.sys of Watchdog Antivirus v1.4.158 allows attackers to write arbitrary files. | |
| Modificada | Alta (7.8) | 0.47% | — | Watchdog Anti-virus | 16/9/2022 | 17/6/2026 | Incorrect access control in Watchdog Anti-Virus v1.4.158 allows attackers to perform a DLL hijacking attack and execute arbitrary code via a crafted binary. | |
| Modificada | Crítica (9.8) | 3.1% | — | Kaspersky Anti-virusKaspersky Endpoint SecurityKaspersky Internet SecurityKaspersky Security Cloud+2 | 1/4/2022 | 17/6/2026 | Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data parsing module that potentially allowed an attacker to execute arbitrary code. The fix was delivered automatically. Credits: Georgy Zaytsev (Positive Technologies). | |
| Modificada | Media (5.5) | 0.20% | — | Kaspersky Anti-virusKaspersky Endpoint SecurityKaspersky Internet SecurityKaspersky Security Cloud+2 | 1/4/2022 | 17/6/2026 | A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security. A local user could cause Windows crash by running a specially crafted binary module. The fix was delivered automatically. Credits: (Straghkov Denis, Kurmangaleev Shamil,… | |
| Modificada | Alta (8.8) | 2.4% | — | Escanav Escan Anti-virus | 1/4/2022 | 17/6/2026 | An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerability is due to invalid arguments and insufficient execution conditions related to "runasroot" command. This vulnerability can induce remote attackers to exploit root privileges by manipulating parameter values. | |
| Modificada | Alta (8.8) | 2.0% | — | Anti-virus FOR Sophos CentralAnti-virus FOR Sophos Home | 17/4/2020 | 17/6/2026 | Mac Endpoint for Sophos Central before 9.9.6 and Mac Endpoint for Sophos Home before 2.2.6 allow Privilege Escalation. | |
| Modificada | Alta (7.8) | 0.46% | — | Maxpcsecure Anti Virus Plus | 3/12/2019 | 17/6/2026 | Max Secure Anti Virus Plus 19.0.4.020 has Insecure Permissions on the installation directory. Local attackers can replace a .exe or .dll file to achieve privilege escalation. | |
| Modificada | Media (6.1) | 2.1% | — | Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+1 | 26/11/2019 | 17/6/2026 | Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component did not adequately inform the user about the threat of redirecting to an untrusted site. Bypass. | |
| Modificada | Media (6.5) | 1.6% | — | Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+1 | 26/11/2019 | 17/6/2026 | Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component was vulnerable to remote disclosure of various information about the user's system (like Windows version and version… | |
| Modificada | Media (4.3) | 0.77% | — | Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+1 | 26/11/2019 | 17/6/2026 | Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attacker remotely disable various anti-virus protection features. DoS, Bypass. | |
| Modificada | Media (4.3) | 0.84% | — | Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+1 | 26/11/2019 | 17/6/2026 | Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attacker remotely disable such product's security features as private browsing and anti-banner. Bypass. | |
| Modificada | Media (6.7) | 0.66% | — | Mcafee Anti-virus PlusMcafee Internet SecurityMcafee Total Protection | 13/11/2019 | 17/6/2026 | A Privilege Escalation vulnerability in the Microsoft Windows client in McAfee Total Protection 16.0.R22 and earlier allows administrators to execute arbitrary code via carefully placing malicious files in specific locations protected by administrator permission. | |
| Modificada | Media (6.1) | 0.85% | — | AVG Anti-virus | 1/11/2019 | 17/6/2026 | A Cross Site Scripting (XSS) issue exists in AVG AntiVirus (Internet Security Edition) 19.3.3084 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to execute JavaScript code via an SSID Name. | |
| Modificada | Media (5.5) | 0.38% | — | Totaldefense Anti-virus | 31/10/2019 | 17/6/2026 | The quarantine restoration function in Total Defense Anti-virus 11.5.2.28 is vulnerable to symbolic link attacks, allowing files to be written to privileged directories. | |
| Modificada | Media (5.9) | 0.56% | — | Totaldefense Anti-virus | 31/10/2019 | 17/6/2026 | The malware scan function in Total Defense Anti-virus 11.5.2.28 is vulnerable to a TOCTOU bug; consequently, symbolic link attacks allow privileged files to be deleted. | |
| Modificada | Alta (7.8) | 0.55% | — | Avast AntivirusAVG Anti-virus | 23/10/2019 | 17/6/2026 | An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8. A DLL Preloading vulnerability allows an attacker to implant %WINDIR%\system32\wbemcomn.dll, which is loaded into a protected-light process (PPL) and might bypass some of the self-defense mechanisms. This affects all components that… | |
| Modificada | Alta (7.8) | 0.59% | — | Totaldefense Anti-virus | 24/9/2019 | 17/6/2026 | In Total Defense Anti-virus 9.0.0.773, resource acquisition from the untrusted search path C:\ used by caschelp.exe allows local attackers to hijack ccGUIFrm.dll, which leads to code execution. SYSTEM-level code execution can be achieved when the ccSchedulerSVC service runs the affected executable. | |
| Modificada | Alta (7.8) | 0.38% | — | Totaldefense Anti-virus | 24/9/2019 | 17/6/2026 | In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS\9\bd\TDUpdate2\ used by AMRT.exe allows local attackers to hijack bdcore.dll, which leads to privilege escalation when the AMRT service loads the DLL. | |
| Modificada | Alta (7.8) | 0.36% | — | Totaldefense Anti-virus | 24/9/2019 | 17/6/2026 | In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS\9\ used by ccschedulersvc.exe allows local attackers to hijack dotnetproxy.exe, which leads to privilege escalation when the ccSchedulerSVC service runs the executable. | |
| Modificada | Media (4.3) | 2.2% | — | Kaspersky Anti-virusKaspersky Free Anti-virusKaspersky Internet SecurityKaspersky Small Office Security+1 | 18/7/2019 | 17/6/2026 | Information Disclosure in Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security versions up to 2019 could potentially disclose unique Product ID by forcing victim to visit a specially crafted webpage (for example, via clicking phishing link). Vulnerability has CVSS v3.0 base score 2.6 |