Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
640 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7) | 0.19% | — | Avast AVG Antivirus | 8/11/2023 | 17/6/2026 | A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be further exploited, allowing an attacker to gain full local privilege escalation on the system.This issue affects Avast/Avg Antivirus: 23.8. | |
| Modificada | Alta (7.8) | 0.18% | — | Eset Endpoint AntivirusEset Endpoint SecurityEset Internet SecurityEset Mail Security+4 | 14/8/2023 | 17/6/2026 | The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or move files without having proper permissions. | |
| Modificada | Media (5.5) | 0.17% | — | Avast Antivirus | 11/7/2023 | 9/7/2026 | Buffer Overflow vulnerability in Avast AntiVirus before v.19.7 allows a local attacker to cause a denial of service via a crafted request to the aswSnx.sys driver. | |
| Modificada | Alta (7.8) | 0.37% | — | Trendmicro Antivirus+ Security 2021Trendmicro Internet Security 2021Trendmicro Maximum Security 2021Trendmicro Premium Security 2021+8 | 26/6/2023 | 17/6/2026 | Trend Micro Security 2021, 2022, and 2023 (Consumer) are vulnerable to a DLL Hijacking vulnerability which could allow an attacker to use a specific executable file as an execution and/or persistence mechanism which could execute a malicious program each time the executable file is started. | |
| Modificada | Alta (7.8) | 0.15% | — | Eset Cyber SecurityEset Endpoint AntivirusEset Server Security | 15/6/2023 | 17/6/2026 | During internal security analysis, a local privilege escalation vulnerability has been identified. On a machine with the affected ESET product installed, it was possible for a user with lower privileges due to improper privilege management to trigger actions with root privileges. ESET remedied this possible attack… | |
| Modificada | Baja (3.7) | 2.2% | — | Haxx CurlFedoraproject FedoraApple MacosNetapp Clustered Data Ontap+5 | 26/5/2023 | 17/6/2026 | An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which… | |
| Modificada | Media (5.9) | 1.8% | — | Haxx CurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+6 | 26/5/2023 | 17/6/2026 | An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private… | |
| Modificada | Media (5.9) | 2.7% | — | Haxx CurlApple MacosNetapp Clustered Data OntapNetapp Ontap Antivirus Connector+4 | 26/5/2023 | 17/6/2026 | A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this,… | |
| Modificada | Alta (7.5) | 2.5% | — | Haxx CurlApple MacosNetapp Clustered Data OntapNetapp Ontap Antivirus Connector+4 | 26/5/2023 | 17/6/2026 | A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprint before it returns an error message containing the (now freed) hash. This flaw risks inserting… | |
| Modificada | Media (5.5) | 0.33% | — | Filseclab Twister Antivirus | 24/5/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Twister Antivirus 8. This issue affects the function 0x804f2158/0x804f2154/0x804f2150/0x804f215c/0x804f2160/0x80800040/0x804f214c/0x804f2148/0x804f2144/0x801120e4/0x804f213c/0x804f2140 in the library filppd.sys of the component IoControlCode… | |
| Modificada | Alta (7.8) | 0.36% | — | Filseclab Twister Antivirus | 24/5/2023 | 17/6/2026 | A vulnerability classified as critical was found in Twister Antivirus 8. This vulnerability affects the function 0x804f2143/0x804f217f/0x804f214b/0x80800043 in the library filppd.sys of the component IoControlCode Handler. The manipulation leads to memory corruption. Local access is required to approach this attack.… | |
| Modificada | Alta (7.8) | 0.19% | — | Bitdefender Antivirus PlusBitdefender Internet SecurityBitdefender Total Security | 24/5/2023 | 17/6/2026 | Unquoted Search Path or Element vulnerability in the Vulnerability Scan component of Bitdefender Total Security, Bitdefender Internet Security, and Bitdefender Antivirus Plus allows an attacker to elevate privileges to SYSTEM. This issue affects: Bitdefender Total Security versions prior to 26.0.10.45. Bitdefender… | |
| Modificada | Media (5.5) | 0.30% | — | Avira Antivirus | 19/4/2023 | 17/6/2026 | A vulnerability within the Avira network protection feature allowed an attacker with local execution rights to cause an overflow. This could corrupt the data on the heap and lead to a denial-of-service situation. Issue was fixed with Endpointprotection.exe version 1.0.2303.633 | |
| Modificada | Media (5.5) | 0.21% | — | Avast AntivirusAVG Anti-virus | 19/4/2023 | 17/6/2026 | Avast and AVG Antivirus for Windows were susceptible to a NULL pointer dereference issue via RPC-interface. The issue was fixed with Avast and AVG Antivirus version 22.11 | |
| Modificada | Media (4.7) | 0.21% | — | Avast AntivirusAVG Anti-virus | 19/4/2023 | 17/6/2026 | Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the restore process leading to arbitrary file creation. The issue was fixed with Avast and AVG Antivirus version 22.11 | |
| Modificada | Media (6.3) | 0.17% | — | Avast AntivirusAVG Anti-virus | 19/4/2023 | 17/6/2026 | Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the Quarantine process, leading to arbitrary file/directory deletion. The issue was fixed with Avast and AVG Antivirus version 22.11 and virus definitions from 14 February 2023 or later. | |
| Modificada | Media (5.5) | 0.35% | — | Jiangmin Antivirus | 25/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in JiangMin Antivirus 16.2.2022.418. This affects the function 0x222010 in the library kvcore.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the… | |
| Modificada | Media (5.5) | 0.32% | — | Jiangmin Antivirus | 25/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in JiangMin Antivirus 16.2.2022.418. Affected by this issue is the function 0x222000 in the library kvcore.sys of the component IOCTL Handler. The manipulation leads to denial of service. Local access is required to approach this attack. The exploit… | |
| Modificada | Media (5.5) | 0.32% | — | Jiangmin Antivirus | 25/3/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in Jianming Antivirus 16.2.2022.418. Affected is an unknown function in the library kvcore.sys of the component IoControlCode Handler. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed… | |
| Modificada | Media (5.5) | 0.32% | — | Jiangmin Antivirus | 25/3/2023 | 17/6/2026 | A vulnerability was found in Jianming Antivirus 16.2.2022.418. It has been rated as problematic. This issue affects some unknown processing in the library kvcore.sys of the component IoControlCode Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit… | |
| Modificada | Alta (7.8) | 0.34% | — | Jiangmin Antivirus | 25/3/2023 | 17/6/2026 | A vulnerability was found in Jianming Antivirus 16.2.2022.418. It has been declared as critical. This vulnerability affects unknown code in the library kvcore.sys of the component IoControlCode Handler. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to… | |
| Modificada | Alta (7.8) | 0.43% | — | Jiangmin Antivirus | 25/3/2023 | 17/6/2026 | A vulnerability classified as critical was found in JiangMin Antivirus 16.2.2022.418. Affected by this vulnerability is the function 0x222010 in the library kvcore.sys of the component IOCTL Handler. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to… | |
| Modificada | Media (5.5) | 0.37% | — | Filseclab Twister Antivirus | 17/3/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in Filseclab Twister Antivirus 8. Affected is the function 0x80112053 in the library fildds.sys of the component IoControlCode Handler. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the… | |
| Modificada | Media (6.5) | 1.3% | — | Filseclab Twister Antivirus | 17/3/2023 | 17/6/2026 | A vulnerability was found in Filseclab Twister Antivirus 8. It has been rated as critical. This issue affects the function 0x8011206B in the library fildds.sys of the component IoControlCode Handler. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Modificada | Alta (7.5) | 1.6% | — | Filseclab Twister Antivirus | 17/3/2023 | 17/6/2026 | A vulnerability was found in Filseclab Twister Antivirus 8. It has been declared as problematic. This vulnerability affects the function 0x80112053 in the library fildds.sys of the component IoControlCode Handler. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been… |