Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2835▲ 33 respecto a la semana anterior
Críticas / altas1495▲ 276 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 451 respecto a la semana anterior
–

40 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.5)0.22%—Malwarebytes19/6/202629/9/2026
Malwarebytes 4.5 contains an unquoted service path vulnerability in the MBAMService executable that allows local attackers to escalate privileges by injecting malicious code into the system root path. Attackers can place executable files in unquoted path directories that execute with LocalSystem privileges during…
AplazadaAlta (7.5)0.22%—MalwarebytesAIMalwarebytes NebulaAI9/6/202623/7/2026
An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). There is a Heap buffer overflow in various buffer encryption utilities.
AplazadaMedia (6.2)0.12%—MalwarebytesAIMalwarebytes NebulaAIMozilla FirefoxAI9/6/202623/7/2026
An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). A large number of Firefox preference files can cause the parser to ignore other browser configuration files, leading to a denial of service.
AplazadaAlta (8.2)0.12%—Malwarebytes EDRAI9/6/202623/7/2026
The utility functions used by Malwarebytes EDR 1.0.11 on Linux for calculating a cryptographic hash of data bytes truncate the hashed data if it exceeds 4GB. This leads to an integer wrap-around if the data is larger than the maximum unsigned integer value (32-bit). Attackers could create a colliding hash value for…
AplazadaAlta (8.7)0.14%—Malwarebytes AdwcleanerAI17/2/202617/6/2026
Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link, a related issue to CVE-2023-28892. To exploit this, an attacker must create…
AnalizadaBaja (3.3)0.21%—Malwarebytes12/12/202517/6/2026
Malwarebytes 1.0.14 for Linux doesn't properly compute signatures in some scenarios. This allows a bypass of detection.
AplazadaMedia (5.3)0.25%—Malwarebytes FOR TeamsAI24/10/202517/6/2026
In Malwarebytes For Teams v.1.0.990 and before and fixed in v.1.0.1003 and later a privilege escalation can occur via the COM interface running in mbamservice.exe.
AplazadaMedia (6.5)0.24%—MalwarebytesAIMalwarebytes NebulaAI14/8/202517/6/2026
An issue was discovered in Malwarebytes before 4.6.14.326 and before 5.1.5.116 (and Nebula 2020-10-21 and later). There is a Race condition that leads to code execution because of a lack of locks between file verification and execution.
AplazadaAlta (7.5)0.41%—MalwarebytesAIMalwarebytes NebulaAI14/8/202517/6/2026
An issue was discovered in Malwarebytes before 4.6.14.326 and before 5.1.5.116 (and Nebula 2020-10-21 and later). Out-of-bound reads in strings detection utilities lead to system crashes.
AplazadaMedia (6.5)0.35%—MalwarebytesAIMalwarebytes NebulaAI14/8/202517/6/2026
An issue was discovered in Malwarebytes 4.6.14.326 and before 5.1.5.116 (and Nebula 2020-10-21 and later). A Stack buffer out-of-bounds access exists because of an integer underflow when handling newline characters.
AplazadaMedia (5.2)0.12%—MalwarebytesAIMalwarebytes NebulaAI14/8/202517/6/2026
An issue was discovered in Malwarebytes 4.6.14.326 and before and 5.1.5.116 and before (and Nebula 2020-10-21 and later). An Out of bounds read in several disassembling utilities causes stability issues and denial of service.
AplazadaMedia (4.5)0.11%—Malwarebytes Binisoft Windows Firewall ControlAI28/7/202517/6/2026
In Malwarebytes Binisoft Windows Firewall Control before 6.16.0.0, the installer is vulnerable to local privilege escalation.
AnalizadaAlta (7.8)0.29%—Malwarebytes Antimalware22/11/202417/6/2026
Malwarebytes Antimalware Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Malwarebytes Antimalware. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit…
AplazadaMedia (5.7)0.38%—Malwarebytes Premium SecurityAI1/10/202417/6/2026
An issue in Malwarebytes Premium Security v5.0.0.883 allows attackers to execute arbitrary code via placing crafted binaries into unspecified directories. NOTE: Malwarebytes argues that this issue requires admin privileges and that the contents cannot be altered by non-admin users.
ModificadaCrítica (9.8)1.8%—Malwarebytes Binisoft Windows Firewall Control4/2/202417/6/2026
Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes.
ModificadaMedia (5.5)0.28%—Malwarebytes Endpoint Detection AND ResponseMalwarebytes30/6/202317/6/2026
In Malwarebytes EDR 1.0.11 for Linux, it is possible to bypass the detection layers that depend on inode identifiers, because an identifier may be reused when a file is replaced, and because two files on different filesystems can have the same identifier.
ModificadaAlta (7.8)0.31%—Malwarebytes Endpoint Detection AND ResponseMalwarebytes30/6/202317/6/2026
The Malwarebytes EDR 1.0.11 for Linux driver doesn't properly ensure whitelisting of executable libraries loaded by executable files, allowing arbitrary code execution. The attacker can set LD_LIBRARY_PATH, set LD_PRELOAD, or run an executable file in a debugger.
ModificadaAlta (7.1)0.40%—Malwarebytes Anti-exploit30/6/202317/6/2026
Malwarebytes Anti-Exploit 4.4.0.220 is vulnerable to arbitrary file deletion and denial of service via an ALPC message in which FullFileNamePath lacks a '\0' character.
ModificadaAlta (7.8)0.68%—Malwarebytes Binisoft Windows Firewall Control26/6/202317/6/2026
Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0 allows local unprivileged users to bypass Windows Firewall restrictions via the user interface's rules tab. NOTE: the vendor's perspective is "this is intended behavior as the application can be locked using a password."
ModificadaAlta (7.8)0.49%—Malwarebytes Adwcleaner29/3/202317/6/2026
Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs\AdwCleaner_Debug.log in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link.
ModificadaAlta (7.8)0.47%—Malwarebytes23/3/202317/6/2026
In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine system. It can also lead to privilege escalation in certain scenarios.
ModificadaAlta (7.8)0.45%—Malwarebytes Binisoft Windows Firewall Control14/2/202217/6/2026
In Malwarebytes Binisoft Windows Firewall Control before 6.8.1.0, programs executed from the Tools tab can be used to escalate privileges.
ModificadaAlta (7)0.27%—Malwarebytes15/1/202117/6/2026
An issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged action within the Malwarebytes launch daemon. The privileged service improperly validated XPC connections by relying on the PID instead of the audit token. An attacker can construct a situation where…
ModificadaAlta (7.1)0.77%—Malwarebytes Endpoint ProtectionMalwarebytes22/12/202017/6/2026
In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system.
ModificadaAlta (7.8)0.88%—Malwarebytes Adwcleaner6/4/202017/6/2026
An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner 8.0.3 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded.