Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

640 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.13%—Avast AntivirusAVG Antivirus4/10/202417/6/2026
An null-pointer-derefrence in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed xar file to crash the application during file processing.
AnalizadaMedia (5.5)0.13%—Avast AntivirusAVG Antivirus4/10/202417/6/2026
A null-pointer-dereference in the signature verification module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS may allow a malformed xar file to crash the application during processing.
AnalizadaMedia (5.5)0.13%—Avast AntivirusAVG Antivirus4/10/202417/6/2026
An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed Mach-O file to crash the application during file processing.
AnalizadaMedia (5.5)0.13%—Avast AntivirusAVG Antivirus4/10/202417/6/2026
An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed eml file to crash the application during file processing.
AplazadaAlta (7.5)0.11%—AVG AntivirusAIAvast AntivirusAI3/10/202417/6/2026
The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via an COM hijack in a time-of-check to time-of-use (TOCTOU) when self protection is disabled.
AnalizadaMedia (5.3)0.23%—Msoftplugins Security Antivirus Firewall5/9/202417/6/2026
The Security, Antivirus, Firewall – S.A.F plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.3.5. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the…
ModificadaMedia (5.5)0.20%—Eset Internet SecurityEset Nod32Eset SecurityEset Smart Security+416/7/202417/6/2026
Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET’s security product inoperable, provided non-default preconditions were met.
AplazadaMedia (5.3)0.36%—Mcafee Security Antivirus VPNAI11/6/202417/6/2026
Improper exception handling in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to cause a denial of service through the use of a malformed deep link.
AplazadaCrítica (9.1)0.47%—Mcafee Security Antivirus VPNAI11/6/202417/6/2026
Improper deep link validation in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to launch an arbitrary URL within the app.
ModificadaAlta (7.3)0.22%—Avast Antivirus10/6/202417/6/2026
A sym-linked file accessed via the repair function in Avast Antivirus <24.2 on Windows may allow user to elevate privilege to delete arbitrary files or run processes as NT AUTHORITY\SYSTEM. The vulnerability exists within the "Repair" (settings -> troubleshooting -> repair) feature, which attempts to delete a file in…
AplazadaAlta (7.8)0.18%—Microworld Technologies Escan AntivirusAI3/5/202417/6/2026
A kernel handle leak issue in ProcObsrvesx.sys 4.0.0.49 in MicroWorld Technologies Inc eScan Antivirus could allow privilege escalation for low-privileged users.
AnalizadaAlta (7.8)0.52%—Vipre Antivirus3/5/202417/6/2026
VIPRE Antivirus Plus FPQuarTransfer Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…
AnalizadaAlta (7.8)0.52%—Vipre Antivirus3/5/202417/6/2026
VIPRE Antivirus Plus TelFileTransfer Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…
AnalizadaAlta (7.8)0.71%—Vipre Antivirus3/5/202417/6/2026
VIPRE Antivirus Plus DeleteHistoryFile Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacker must first obtain the ability to execute low-privileged code on the target system in order…
AnalizadaAlta (7.8)0.71%—Vipre Antivirus3/5/202417/6/2026
VIPRE Antivirus Plus SetPrivateConfig Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacker must first obtain the ability to execute low-privileged code on the target system in order…
AnalizadaAlta (7.8)0.51%—Vipre Antivirus3/5/202417/6/2026
VIPRE Antivirus Plus Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
AplazadaAlta (7.9)0.19%—Webroot AntivirusAI1/5/202417/6/2026
Privilege Escalation in WRSA.EXE in Webroot Antivirus 8.0.1X- 9.0.35.12 on Windows64 bit and 32 bit allows malicious software to abuse WRSA.EXE to delete arbitrary and protected files.
AplazadaMedia (5.5)0.17%—Watchdog AntivirusAI23/4/202417/6/2026
Watchdog Antivirus v1.6.415 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002014 IOCTL code of the wsdk-driver.sys driver.
AnalizadaAlta (7.8)0.20%—Bitdefender AntivirusBitdefender Antivirus PlusBitdefender Internet SecurityBitdefender Total Security1/4/202417/6/2026
A configuration setting issue in seccenter.exe as used in Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus Plus, Bitdefender Antivirus Free allows an attacker to change the product's expected behavior and potentially load a third-party library upon execution. This issue affects Total…
ModificadaAlta (7.8)0.55%—Eset Endpoint AntivirusEset Endpoint SecurityEset File SecurityEset Internet Security+515/2/202417/6/2026
Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission.
ModificadaMedia (5.5)0.16%—Filseclab Twister Antivirus13/2/202417/6/2026
Twister Antivirus v8.17 is vulnerable to an Out-of-bounds Read vulnerability by triggering the 0x801120B8 IOCTL code of the filmfd.sys driver.
ModificadaMedia (5.5)0.20%—Filseclab Twister Antivirus13/2/202417/6/2026
Twister Antivirus v8.17 is vulnerable to a Denial of Service vulnerability by triggering the 0x80112067, 0x801120CB 0x801120CC 0x80112044, 0x8011204B, 0x8011204F, 0x80112057, 0x8011205B, 0x8011205F, 0x80112063, 0x8011206F, 0x80112073, 0x80112077, 0x80112078, 0x8011207C and 0x80112080 IOCTL codes of the fildds.sys…
ModificadaMedia (5.5)0.28%—Eset Endpoint AntivirusEset Endpoint SecurityEset Internet SecurityEset Mail Security+231/1/202417/6/2026
Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with the NT AUTHORITY\NetworkService permissions.
ModificadaAlta (7.8)0.64%—Trendmicro AIR SupportTrendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum Security+129/1/202417/6/2026
Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable to a DLL hijacking/proxying vulnerability, which if exploited could allow an attacker to impersonate and modify a library to execute code on the system and ultimately escalate…
ModificadaAlta (8.6)0.38%—Eset Endpoint AntivirusEset Endpoint SecurityEset File SecurityEset Internet Security+521/12/202317/6/2026
Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.
Orbitaley — Vulnerabilidades