Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2857▼ 164 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.31% | — | Malwarebytes Endpoint Detection AND ResponseMalwarebytes | 30/6/2023 | 17/6/2026 | The Malwarebytes EDR 1.0.11 for Linux driver doesn't properly ensure whitelisting of executable libraries loaded by executable files, allowing arbitrary code execution. The attacker can set LD_LIBRARY_PATH, set LD_PRELOAD, or run an executable file in a debugger. | |
| Modificada | Alta (7.1) | 0.40% | — | Malwarebytes Anti-exploit | 30/6/2023 | 17/6/2026 | Malwarebytes Anti-Exploit 4.4.0.220 is vulnerable to arbitrary file deletion and denial of service via an ALPC message in which FullFileNamePath lacks a '\0' character. | |
| Modificada | Alta (7.8) | 0.68% | — | Malwarebytes Binisoft Windows Firewall Control | 26/6/2023 | 17/6/2026 | Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0 allows local unprivileged users to bypass Windows Firewall restrictions via the user interface's rules tab. NOTE: the vendor's perspective is "this is intended behavior as the application can be locked using a password." | |
| Modificada | Alta (7.8) | 0.49% | — | Malwarebytes Adwcleaner | 29/3/2023 | 17/6/2026 | Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs\AdwCleaner_Debug.log in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link. | |
| Modificada | Alta (7.8) | 0.47% | — | Malwarebytes | 23/3/2023 | 17/6/2026 | In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine system. It can also lead to privilege escalation in certain scenarios. | |
| Modificada | Crítica (9.1) | 21% | — | Generalbytes Crypto Application Server | 22/3/2023 | 17/6/2026 | General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary Java code by uploading a Java application to the /batm/app/admin/standalone/deployments directory, aka BATM-4780, as exploited in the wild in March 2023. This is fixed in… | |
| Modificada | Media (4.3) | 0.42% | — | Bytesforall Atahualpa | 23/6/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in Atahualpa Theme. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. | |
| Modificada | Media (5.4) | 0.54% | — | Bytesforall Atahualpa | 23/6/2022 | 17/6/2026 | A vulnerability has been found in Atahualpa Theme and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting. The attack can be launched remotely. | |
| Modificada | Alta (7.8) | 0.45% | — | Malwarebytes Binisoft Windows Firewall Control | 14/2/2022 | 17/6/2026 | In Malwarebytes Binisoft Windows Firewall Control before 6.8.1.0, programs executed from the Tools tab can be used to escalate privileges. | |
| Modificada | Alta (7) | 0.27% | — | Malwarebytes | 15/1/2021 | 17/6/2026 | An issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged action within the Malwarebytes launch daemon. The privileged service improperly validated XPC connections by relying on the PID instead of the audit token. An attacker can construct a situation where… | |
| Modificada | Alta (7.5) | 1.4% | — | OS STR Bytes Project OS STR Bytes | 31/12/2020 | 17/6/2026 | An issue was discovered in the os_str_bytes crate before 2.0.0 for Rust. It has false expectations about char::from_u32_unchecked behavior. | |
| Modificada | Alta (7.1) | 0.77% | — | Malwarebytes Endpoint ProtectionMalwarebytes | 22/12/2020 | 17/6/2026 | In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system. | |
| Modificada | Alta (8.8) | 2.0% | — | Geniusbytes Genius Server | 29/4/2020 | 17/6/2026 | An application plugin in Genius Bytes Genius Server (Genius CDDS) 3.2.2 allows remote authenticated users to gain admin privileges. | |
| Modificada | Alta (7.2) | 2.4% | — | Geniusbytes Genius Server | 29/4/2020 | 17/6/2026 | The BPM component in Genius Bytes Genius Server (Genius CDDS) 3.2.2 allows remote authenticated users to execute arbitrary commands. | |
| Modificada | Alta (7.8) | 0.88% | — | Malwarebytes Adwcleaner | 6/4/2020 | 17/6/2026 | An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner 8.0.3 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded. | |
| Modificada | Alta (7.8) | 0.87% | — | Malwarebytes Adwcleaner | 23/12/2019 | 17/6/2026 | An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner before 8.0.1 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded by the product. | |
| Modificada | Alta (8.8) | 9.9% | — | Malwarebytes Antimalware | 3/6/2019 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Malwarebytes Antimalware 3.6.1.2711. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page. There is an issue with the way the product handles URIs within certain… | |
| Modificada | Alta (7.8) | 1.1% | — | Malwarebytes Anti-malware | 21/3/2018 | 17/6/2026 | A vulnerability in the encryption and permission implementation of Malwarebytes Anti-Malware consumer version 2.2.1 and prior (fixed in 3.0.4) allows an attacker to take control of the whitelisting feature (exclusions.dat under %SYSTEMDRIVE%\ProgramData) to permit execution of unauthorized applications including… | |
| Modificada | Alta (7.8) | 0.48% | — | Malwarebytes | 8/1/2018 | 17/6/2026 | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e02c. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows… | |
| Modificada | Baja (3.3) | 0.39% | — | Malwarebytes | 8/1/2018 | 17/6/2026 | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e00c. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows… | |
| Modificada | Alta (7.8) | 0.42% | — | Malwarebytes | 8/1/2018 | 17/6/2026 | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e000. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows… | |
| Modificada | Alta (7.8) | 0.42% | — | Malwarebytes | 8/1/2018 | 17/6/2026 | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e018. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows… | |
| Modificada | Alta (7.8) | 0.42% | — | Malwarebytes | 8/1/2018 | 17/6/2026 | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C40E020. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows… | |
| Modificada | Alta (7.8) | 0.42% | — | Malwarebytes | 8/1/2018 | 17/6/2026 | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C40E024. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows… | |
| Modificada | Alta (7.8) | 0.42% | — | Malwarebytes | 8/1/2018 | 17/6/2026 | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e014. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows… |