Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
640 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.32% | — | Bitdefender Antivirus PlusBitdefender Internet SecurityBitdefender Total Security | 18/2/2022 | 17/6/2026 | A Process Control vulnerability in ProductAgentUI.exe as used in Bitdefender Antivirus Plus allows an attacker to tamper with product settings via a specially crafted DLL file. This issue affects: Bitdefender Antivirus Plus versions prior to 24.0.26.136. Bitdefender Internet Security versions prior to 24.0.26.136.… | |
| Modificada | Alta (7.8) | 0.60% | — | Eset Endpoint AntivirusEset Endpoint SecurityEset File SecurityEset Internet Security+5 | 9/2/2022 | 17/6/2026 | ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM. | |
| Modificada | Alta (8.8) | 1.2% | — | Owncloud Files Antivirus | 15/1/2022 | 17/6/2026 | The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a public share) are supposed to be deleted upon detection. | |
| Modificada | Alta (7.2) | 2.1% | — | Owncloud Files Antivirus | 15/1/2022 | 17/6/2026 | The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings. | |
| Modificada | Alta (7.8) | 0.37% | — | Watchguard Panda Antivirus | 13/1/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Free Antivirus 20.2.0.0. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the use of named… | |
| Modificada | Alta (7.8) | 0.32% | — | Avast Antivirus | 27/12/2021 | 17/6/2026 | Privilege escalation vulnerability in Avast Antivirus prior to 20.4 allows a local user to gain elevated privileges by "hollowing" trusted process which could lead to the bypassing of Avast self-defense. | |
| Modificada | Alta (7.8) | 0.38% | — | Avast Antivirus | 27/12/2021 | 17/6/2026 | Multiple privilege escalation vulnerabilities in Avast Antivirus prior to 20.4 allow a local user to gain elevated privileges by calling unnecessarily powerful internal methods of the main antivirus service which could lead to the (1) arbitrary file delete, (2) write and (3) reset security. | |
| Modificada | Alta (8.8) | 0.43% | — | Avast Antivirus | 27/12/2021 | 17/6/2026 | Privilege escalation vulnerability in the Self-Defense driver of Avast Antivirus prior to 20.8 allows a local user with SYSTEM privileges to gain elevated privileges by "hollowing" process wsc_proxy.exe which could lead to acquire antimalware (AM-PPL) protection. | |
| Modificada | Alta (8.8) | 0.46% | — | Avast Antivirus | 27/12/2021 | 17/6/2026 | Privilege escalation vulnerability in the Sandbox component of Avast Antivirus prior to 20.4 allows a local sandboxed code to gain elevated privileges by using system IPC interfaces which could lead to exit the sandbox and acquire SYSTEM privileges. | |
| Modificada | Alta (8.8) | 0.38% | — | Avast Antivirus | 27/12/2021 | 17/6/2026 | Sandbox component in Avast Antivirus prior to 20.4 has an insecure permission which could be abused by local user to control the outcome of scans, and therefore evade detection or delete arbitrary system files. | |
| Modificada | Alta (7.1) | 0.41% | — | Trendmicro Antivirus+ Security 2021Trendmicro Internet Security 2021Trendmicro Maximum Security 2021Trendmicro Premium Security 2021 | 16/12/2021 | 17/6/2026 | A link following denial-of-service (DoS) vulnerability in the Trend Micro Security (Consumer) 2021 familiy of products could allow an attacker to abuse the PC Health Checkup feature of the product to create symlinks that would allow modification of files which could lead to a denial-of-service. | |
| Modificada | Media (5.5) | 0.21% | — | Trendmicro Antivirus+ SecurityTrendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security | 3/12/2021 | 17/6/2026 | Trend Micro Security 2021 v17.0 (Consumer) contains a vulnerability that allows files inside the protected folder to be modified without any detection. | |
| Modificada | Alta (7.8) | 0.33% | — | Trendmicro Antivirus | 30/11/2021 | 17/6/2026 | Trend Micro Antivirus for Mac 2021 v11 (Consumer) is vulnerable to an improper access control privilege escalation vulnerability that could allow an attacker to establish a connection that could lead to full local privilege escalation within the application. Please note that an attacker must first obtain the ability… | |
| Modificada | Media (5.5) | 0.23% | — | Eset Cyber SecurityEset Endpoint AntivirusEset Endpoint Security | 8/11/2021 | 17/6/2026 | ESET was made aware of a vulnerability in its consumer and business products for macOS that enables a user logged on to the system to stop the ESET daemon, effectively disabling the protection of the ESET security product until a system reboot. | |
| Modificada | Alta (7.4) | 50% | 💥 PoC | OpensslDebian LinuxNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+28 | 24/8/2021 | 17/6/2026 | ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a… | |
| Modificada | Crítica (9.8) | 88% | — | OpensslDebian LinuxNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+27 | 24/8/2021 | 17/6/2026 | In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the… | |
| Modificada | Media (6.5) | 2.0% | — | Xmlsoft Libxml2Redhat Jboss Core ServicesOracle ZFS Storage Appliance KITNetapp Active IQ Unified Manager+15 | 9/7/2021 | 17/6/2026 | A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service. | |
| Modificada | Alta (7.5) | 0.54% | — | Bitdefender Antivirus PlusBitdefender Internet SecurityBitdefender Total Security | 22/6/2021 | 17/6/2026 | Improper Certificate Validation vulnerability in the Online Threat Prevention module as used in Bitdefender Total Security allows an attacker to potentially bypass HTTP Strict Transport Security (HSTS) checks. This issue affects: Bitdefender Total Security versions prior to 25.0.7.29. Bitdefender Internet Security… | |
| Modificada | Alta (7.8) | 2.0% | — | Xmlsoft XmllintDebian LinuxFedoraproject FedoraRedhat Jboss Core Services+5 | 1/6/2021 | 17/6/2026 | There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidentiality, integrity, and availability. | |
| Modificada | Alta (8.6) | 17% | — | Xmlsoft Libxml2Redhat Jboss Core ServicesRedhat Enterprise LinuxFedoraproject Fedora+24 | 19/5/2021 | 17/6/2026 | There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application… | |
| Modificada | Alta (8.8) | 22% | — | Xmlsoft Libxml2Debian LinuxRedhat Jboss Core ServicesRedhat Enterprise Linux+14 | 18/5/2021 | 17/6/2026 | There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability. | |
| Modificada | Media (5.9) | 3.5% | — | Xmlsoft Libxml2Redhat Jboss Core ServicesRedhat Enterprise LinuxDebian Linux+15 | 14/5/2021 | 17/6/2026 | A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this… | |
| Modificada | Alta (8.8) | 2.8% | — | Synology Antivirus Essential | 28/4/2021 | 17/6/2026 | Externally controlled reference to a resource in another sphere in quarantine functionality in Synology Antivirus Essential before 1.4.8-2801 allows remote authenticated users to obtain privilege via unspecified vectors. | |
| Modificada | Alta (7.8) | 0.53% | — | Trendmicro Antivirus | 22/4/2021 | 17/6/2026 | Trend Micro Antivirus for Mac 2020 v10.5 and 2021 v11 (Consumer) is vulnerable to an improper access control privilege escalation vulnerability that could allow an attacker to establish a connection that could lead to full local privilege escalation within the application. Please note that an attacker must first… | |
| Modificada | Alta (7.2) | 2.6% | — | Trendmicro Antivirus+ Security 2020Trendmicro Antivirus+ Security 2021Trendmicro Internet Security 2020Trendmicro Internet Security 2021+4 | 10/2/2021 | 17/6/2026 | The Trend Micro Security 2020 and 2021 families of consumer products are vulnerable to a code injection vulnerability which could allow an attacker to disable the program's password protection and disable protection. An attacker must already have administrator privileges on the machine to exploit this vulnerability. |