Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

41 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.8)0.20%—ELI Anti-malware Security AND Brute-force FirewallAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eli Anti-Malware Security and Brute-Force Firewall gotmls allows Reflected XSS.This issue affects Anti-Malware Security and Brute-Force Firewall: from n/a through <= 4.23.89.
AplazadaAlta (8.8)0.52%—Anti-malware Security AND Brute-force FirewallAIPHPAI15/6/202617/6/2026
Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions.
AplazadaAlta (7.2)0.54%—K7 Security Anti-malwareAIK7 Rkscan.sysAI9/9/202517/6/2026
K7RKScan.sys 23.0.0.10, part of the K7 Security Anti-Malware suite, allows an admin-privileged user to send crafted IOCTL requests to terminate processes that are protected through a third-party implementation. This is caused by insufficient caller validation in the driver's IOCTL handler, enabling unauthorized…
AplazadaAlta (7.5)0.40%—Emsisoft Anti-malwareAI5/8/202517/6/2026
A vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024.12 allows attackers on a remote server to obtain Net-NTLMv2 hash information via a specially created A2S (Emsisoft Custom Scan) extension file.
AplazadaMedia (5.6)0.23%—K7 Security Anti-malwareAIK7 Rkscan.sysAI11/6/202517/6/2026
A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL requests to terminate a wide range of processes running with administrative or system-level privileges, with the exception of those inherently protected by the operating…
AplazadaCrítica (9)0.87%—ELI Scheetz Anti-malware Security AND Brute-force FirewallAI25/4/202417/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Eli Scheetz Anti-Malware Security and Brute-Force Firewall gotmls allows Code Injection.This issue affects Anti-Malware Security and Brute-Force Firewall: from n/a through 4.21.96.
ModificadaAlta (7.8)0.18%—Trellix Anti-malware Engine9/1/202417/6/2026
A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation of privileges. This was achieved by adding an entry to the registry under the Trellix ENS registry folder with a symbolic link to files that…
ModificadaMedia (6.1)1.3%—Anti-malware Security AND Brute-force Firewall Project Anti-malware Security AND Brute-force Firewall29/8/202217/6/2026
The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.21.83 does not sanitise and escape some parameters before outputting them back in an admin dashboard, leading to Reflected Cross-Site Scripting
ModificadaMedia (6.1)3.1%—Download Anti-malware Security AND Brute-force Firewall Project Download Anti-malware Security AND Brute-force Firewall25/4/202217/6/2026
The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters
ModificadaMedia (4.8)0.60%—Anti-malware Security AND Brute-force Firewall Project Anti-malware Security AND Brute-force Firewall21/2/202217/6/2026
The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST data before outputting it back in attributes of an admin page, leading to a Reflected Cross-Site scripting. Due to the presence of specific parameter value, available to admin users, this can only…
ModificadaMedia (5.5)2.9%—Avira Anti-malware SDKAvira Antivirus ServerAvira Antivirus FOR EndpointAvira Antivirus FOR Small Business+420/2/202017/6/2026
Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for Endpoint, Antivirus for Small Business, Exchange Security (Gateway), Internet Security Suite for Windows, Prime, Free Security Suite for Windows, and Cross Platform…
ModificadaAlta (7.5)4.9%—Emsisoft Anti-malware8/2/201917/6/2026
EPP.sys in Emsisoft Anti-Malware prior to version 2018.12 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEVICE_SECURE_OPEN and therefore files and directories "inside" the \\.\EPP device are not properly protected, leading to unintended impersonation or object creation. This…
ModificadaAlta (7.8)1.1%—Malwarebytes Anti-malware21/3/201817/6/2026
A vulnerability in the encryption and permission implementation of Malwarebytes Anti-Malware consumer version 2.2.1 and prior (fixed in 3.0.4) allows an attacker to take control of the whitelisting feature (exclusions.dat under %SYSTEMDRIVE%\ProgramData) to permit execution of unauthorized applications including…
ModificadaAlta (7.8)0.40%—Watchdogdevelopment Anti-malware5/2/201817/6/2026
In WatchDog Anti-Malware 2.74.186.150, the driver file (ZAMGUARD32.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x80002054.
ModificadaAlta (7.8)0.40%—Watchdogdevelopment Anti-malware5/2/201817/6/2026
In WatchDog Anti-Malware 2.74.186.150, the driver file (ZAMGUARD32.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x80002010.
ModificadaAlta (7.8)0.40%—Malwarefox Anti-malware16/1/201817/6/2026
In Malwarefox Anti-Malware 2.72.169, the driver file (zam64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x80002054.
ModificadaAlta (7.8)1.1%—Malwarefox Anti-malware16/1/201817/6/2026
In Malwarefox Anti-Malware 2.72.169, the driver file (zam64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x80002010.
ModificadaAlta (7.5)7.6%—Watchdogdevelopment Anti-malwareWatchdogdevelopment Online Security PRO30/10/201717/6/2026
In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer dereference vulnerability that gets triggered when sending an operation to ioctl 0x80002010. This is due to the input buffer being NULL or the input buffer size being 0 as they are not validated.
ModificadaAlta (7.5)7.6%—Watchdogdevelopment Anti-malwareWatchdogdevelopment Online Security PRO30/10/201717/6/2026
In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer dereference vulnerability that gets triggered when sending an operation to ioctl 0x80002054. This is due to the input buffer being NULL or the input buffer size being 0 as they are not validated.
ModificadaAlta (7.3)0.29%—Mcafee Anti-malware Scan Engine31/3/201717/6/2026
Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local attackers to bypass local security protection via a crafted input file.
ModificadaAlta (7.3)0.36%—Mcafee Anti-malware Scan Engine28/3/201717/6/2026
Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local users to bypass local security protection via a crafted input file.
ModificadaAlta (9.3)17%—Malwarebytes Anti-exploitMalwarebytes Anti-malware16/12/201417/6/2026
The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE) consumer 1.04.1.1012 and earlier allow man-in-the-middle attackers to execute arbitrary code by spoofing the update server and uploading an executable.
ModificadaMedia (4.3)98%—Ahnlab V3 Internet SecurityAladdin EsafeAVG Anti-virusCAT Quick Heal+621/3/201216/6/2026
The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus…
ModificadaMedia (4.3)92%—Anti-virus Vba32Authentium Command AntivirusAVG Anti-virusBitdefender+1621/3/201216/6/2026
The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky…
ModificadaMedia (4.3)100%—Ahnlab V3 Internet SecurityAlwil Avast AntivirusAnti-virus Vba32Antiy AVL SDK+3021/3/201216/6/2026
The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424,…