Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
251 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 2.6% | 💥 Exploit | Kaspersky Anti-virus FOR Linux Server | 17/7/2017 | 17/6/2026 | In Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312), the scriptName parameter of the licenseKeyInfo action method is vulnerable to cross-site scripting (XSS). | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Kaspersky Anti-virus FOR Linux Server | 17/7/2017 | 17/6/2026 | The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312) to read arbitrary files with kluser privileges. | |
| Modificada | Crítica (9.8) | 10% | 💥 Exploit | Kaspersky Anti-virus FOR Linux Server | 17/7/2017 | 17/6/2026 | The kluser is able to interact with the kav4fs-control binary in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). By abusing the quarantine read and write operations, it is possible to elevate the privileges to root. | |
| Modificada | Alta (8.8) | 1.9% | 💥 Exploit | Kaspersky Anti-virus FOR Linux Server | 17/7/2017 | 17/6/2026 | There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). This would allow an attacker to submit authenticated requests when an authenticated user browses an attacker-controlled domain. | |
| Modificada | Alta (7.5) | 1.3% | — | AVG Anti-virus | 12/7/2017 | 17/6/2026 | AVG AntiVirus for MacOS with scan engine before 4668 might allow remote attackers to bypass malware detection by leveraging failure to scan inside disk image (aka DMG) files. | |
| Modificada | Media (6.7) | 0.62% | — | AVG Anti-virusAVG Internet SecurityAVG Ultimate | 21/3/2017 | 17/6/2026 | Code injection vulnerability in AVG Ultimate 17.1 (and earlier), AVG Internet Security 17.1 (and earlier), and AVG AntiVirus FREE 17.1 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any AVG process via a "DoubleAgent" attack. One perspective… | |
| Modificada | Media (5.5) | 0.57% | — | Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Total Security | 6/1/2017 | 17/6/2026 | A local denial of service vulnerability exists in window broadcast message handling functionality of Kaspersky Anti-Virus software. Sending certain unhandled window messages, an attacker can cause application termination and in the same way bypass KAV self-protection mechanism. | |
| Modificada | Crítica (9.1) | 19% | 💥 Exploit | Symantec Anti-virus Engine | 19/5/2016 | 17/6/2026 | The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory access violation and system crash) via a malformed PE header file. | |
| Modificada | Alta (7.2) | 1.0% | 💥 Exploit | K7computing K7sentry.sysK7computing Anti-virus PlusK7computing Total SecurityK7computing Ultimate Security | 6/2/2015 | 17/6/2026 | K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x95002570, 0x95002574, 0x95002580, 0x950025a8, 0x950025ac, or 0x950025c8 IOCTL call. | |
| Modificada | Media (4.3) | 4.5% | — | Sophos Anti-virus | 22/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the web UI in Sophos Anti-Virus for Linux before 9.6.1 allow local users to inject arbitrary web script or HTML via the (1) newListList:ExcludeFileOnExpression, (2) newListList:ExcludeFilesystems, or (3) newListList:ExcludeMountPaths parameter to… | |
| Modificada | Alta (7.5) | 1.2% | — | F-secure Anti-virusF-secure Email AND Server SecurityF-secure Server Security | 18/4/2014 | 17/6/2026 | SQL injection vulnerability in an unspecified DLL in the FSDBCom ActiveX control in F-Secure Anti-Virus for Microsoft Exchange Server before HF02, Anti-Virus for Windows Servers 9.00 before HF09, Anti-Virus for Citrix Servers 9.00 before HF09, and F-Secure Email and Server Security and F-Secure Server Security 9.20… | |
| Modificada | Baja (2.1) | 0.29% | — | F-secure Anti-virusF-secure PSB Workstation SecurityF-secure Safe Anywhere | 18/4/2014 | 16/6/2026 | F-Secure Anti-Virus, Safe Anywhere, and PSB Workstation Security before 11500 for Mac OS X allows local users to disable the Mac OS X firewall via unspecified vectors. | |
| Modificada | Media (5.6) | 0.97% | — | Sophos Scanning EngineSophos Anti-virus | 10/2/2014 | 17/6/2026 | Sophos Anti-Virus engine (SAVi) before 3.50.1, as used in VDL 4.97G 9.7.x before 9.7.9, 10.0.x before 10.0.11, and 10.3.x before 10.3.1 does not set an ACL for certain global and session objects, which allows local users to bypass anti-virus protection, cause a denial of service (resource consumption, CPU consumption,… | |
| Modificada | Media (6.2) | 0.29% | — | Anti-virus Virusblockada32 | 25/8/2012 | 16/6/2026 | Race condition in VBA32 Personal 3.12.12.4 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an… | |
| Modificada | Media (6.4) | 2.6% | — | F-secure Anti-virus | 22/8/2012 | 16/6/2026 | F-Secure Anti-Virus does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for remote attackers to execute arbitrary code via malware that is correctly detected by this product, but with a detection approach that occurs too late to stop the code… | |
| Modificada | Media (6.4) | 2.6% | — | AVG Anti-virus | 22/8/2012 | 16/6/2026 | AVG Anti-Virus does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for remote attackers to execute arbitrary code via malware that is correctly detected by this product, but with a detection approach that occurs too late to stop the code… | |
| Modificada | Media (4.3) | 94% | — | Ahnlab V3 Internet SecurityAladdin EsafeAuthentium Command AntivirusBitdefender+8 | 21/3/2012 | 16/6/2026 | The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Norman Antivirus… | |
| Modificada | Media (4.3) | 98% | — | Ahnlab V3 Internet SecurityAladdin EsafeAVG Anti-virusCAT Quick Heal+6 | 21/3/2012 | 16/6/2026 | The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus… | |
| Modificada | Media (4.3) | 92% | — | Anti-virus Vba32Authentium Command AntivirusAVG Anti-virusBitdefender+16 | 21/3/2012 | 16/6/2026 | The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky… | |
| Modificada | Media (4.3) | 94% | — | Aladdin EsafeAnti-virus Vba32Antiy AVL SDKAuthentium Command Antivirus+4 | 21/3/2012 | 16/6/2026 | The Gzip file parser in Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, and VBA32 3.12.14.2 allows remote attackers to bypass malware detection via a .tar.gz file with stray… | |
| Modificada | Media (4.3) | 100% | — | Ahnlab V3 Internet SecurityAlwil Avast AntivirusAnti-virus Vba32Antiy AVL SDK+30 | 21/3/2012 | 16/6/2026 | The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424,… | |
| Modificada | Media (4.3) | 74% | — | ClamavSophos Anti-virus | 21/3/2012 | 16/6/2026 | The Microsoft CHM file parser in ClamAV 0.96.4 and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a crafted reset interval in the LZXC header of a CHM file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred… | |
| Modificada | Media (4.3) | 98% | — | Aladdin EsafeAlwil Avast AntivirusAnti-virus Vba32Antiy AVL SDK+24 | 21/3/2012 | 16/6/2026 | The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus… | |
| Modificada | Media (4.3) | 100% | — | Aladdin EsafeAVG Anti-virusCAT Quick HealComodo Antivirus+16 | 21/3/2012 | 16/6/2026 | The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky… | |
| Modificada | Media (4.3) | 98% | — | Antiy AVL SDKCA Etrust VET AntivirusDrweb Dr.web AntivirusEmsisoft Anti-malware+10 | 21/3/2012 | 16/6/2026 | The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7,… |