Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▲ 460 respecto a la semana anterior
Críticas / altas1445▲ 228 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 156 respecto a la semana anterior
296 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7) | 0.15% | — | Bitdefender Internet SecurityBitdefender Total Security | 14/7/2026 | 12/8/2026 | An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and Internet Security on Windows allows a less-privileged local user to elevate rights by leveraging a race conditions via Symbolic Links. This issue affects Total Security:… | |
| Aplazada | Alta (8.7) | 0.79% | — | Xcitium Client SecurityAIComodo Internet SecurityAI | 7/6/2026 | 23/7/2026 | Xcitium Client Security (XCS) before 13.8.2.10019 and Comodo Internet Security (CIS) through 12.3.4.8162 (fix expected by 2026 Q3) contain an integer underflow vulnerability in the firewall driver Inspect.sys that allows remote unauthenticated attackers to crash the system by sending a crafted IPv6 packet with a… | |
| Pendiente de análisis | Alta (7.8) | 0.18% | — | PC Tools Internet SecurityAIPC Tools Pctcore64AI | 1/6/2026 | 22/7/2026 | Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and invoke privileged IOCTL handlers. A local attacker with the ability to access or load the affected driver can exploit this vulnerability to… | |
| Modificada | Alta (7) | 0.13% | — | Avira Internet Security | 5/3/2026 | 17/6/2026 | Avira Internet Security contains a time-of-check time-of-use (TOCTOU) vulnerability in the Optimizer component. A privileged service running as SYSTEM identifies directories for cleanup during a scan phase and subsequently deletes them during a separate cleanup phase without revalidating the target path. A local… | |
| Modificada | Alta (7.8) | 0.69% | — | Avira Internet Security | 5/3/2026 | 17/6/2026 | Avira Internet Security contains a deserialization of untrusted data vulnerability in the System Speedup component. The Avira.SystemSpeedup.RealTimeOptimizer.exe process, which runs with SYSTEM privileges, deserializes data from a file located in C:\\ProgramData using .NET BinaryFormatter without implementing input… | |
| Modificada | Alta (7.1) | 0.19% | — | Avira Internet Security | 5/3/2026 | 17/6/2026 | Avira Internet Security contains an improper link resolution vulnerability in the Software Updater component. During the update process, a privileged service running as SYSTEM deletes a file under C:\\ProgramData without validating whether the path resolves through a symbolic link or reparse point. A local attacker… | |
| Analizada | Alta (8.8) | 0.17% | — | Bitdefender AntivirusBitdefender Antivirus PlusBitdefender Endpoint Security ToolsBitdefender Internet Security+1 | 10/12/2025 | 17/6/2026 | A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting files from a user-writable directory (C:\ProgramData\Atc\Feedback) without proper symbolic link validation,… | |
| Aplazada | Alta (8.5) | 0.54% | — | Agnitum Outpost Internet SecurityAI | 1/8/2025 | 16/6/2026 | A local privilege escalation vulnerability exists in Agnitum Outpost Internet Security 8.1 that allows an unprivileged user to execute arbitrary code with SYSTEM privileges. The flaw resides in the acs.exe component, which exposes a named pipe that accepts unauthenticated commands. By exploiting a directory traversal… | |
| Aplazada | Alta (8.5) | 0.34% | — | Pandasecurity Global ProtectionAIPandasecurity Antivirus PROAIPandasecurity Small Business ProtectionAIPandasecurity Internet SecurityAI | 15/7/2025 | 17/6/2026 | PSEvents.exe in multiple Panda Security products runs hourly with SYSTEM privileges and loads DLL files from a user-writable directory without proper validation. An attacker with low-privileged access who can write DLL files to the monitored directory can achieve arbitrary code execution with SYSTEM privileges.… | |
| Analizada | Baja (2.9) | 0.69% | — | Comodo Internet Security | 6/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Comodo Internet Security Premium 12.3.4.8162. Affected is an unknown function of the component File Name Handler. The manipulation of the argument name/folder leads to path traversal. It is possible to launch the attack remotely. The complexity of an… | |
| Analizada | Alta (8.2) | 4.2% | — | Comodo Internet Security | 6/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Comodo Internet Security Premium 12.3.4.8162. This issue affects some unknown processing of the file cis_update_x64.xml of the component Manifest File Handler. The manipulation of the argument binary/params leads to os command injection. The attack… | |
| Analizada | Alta (8.2) | 0.46% | — | Comodo Internet Security | 6/7/2025 | 17/6/2026 | A vulnerability classified as critical was found in Comodo Internet Security Premium 12.3.4.8162. This vulnerability affects unknown code of the file cis_update_x64.xml of the component Manifest File Handler. The manipulation leads to improper validation of integrity check value. The attack can be initiated remotely.… | |
| Analizada | Media (6.3) | 0.27% | — | Comodo Internet Security | 6/7/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Comodo Internet Security Premium 12.3.4.8162. This affects an unknown part of the component Update Handler. The manipulation leads to improper certificate validation. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The… | |
| Aplazada | Media (5.3) | 0.13% | — | Kaspersky Anti-virus SDK FOR WindowsAIKaspersky Security FOR Virtualization Light AgentAIKaspersky Endpoint Security FOR WindowsAIKaspersky Small Office SecurityAI+9 | 6/2/2025 | 17/6/2026 | Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small Office Security, Kaspersky for Windows (Standard, Plus, Premium), Kaspersky Free, Kaspersky Anti-Virus, Kaspersky Internet Security,… | |
| Analizada | Alta (7.8) | 0.12% | — | AVG Internet Security | 12/9/2024 | 17/6/2026 | Local Privilege Escalation in AVG Internet Security v24 on Windows allows a local unprivileged user to escalate privileges to SYSTEM via COM-Hijacking. | |
| Modificada | Alta (7.8) | 0.32% | — | Comodo Internet Security | 29/7/2024 | 17/6/2026 | Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Modificada | Alta (7.8) | 0.32% | — | Comodo Internet Security | 29/7/2024 | 17/6/2026 | Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Modificada | Alta (7.8) | 0.32% | — | Comodo Internet Security | 29/7/2024 | 17/6/2026 | Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Modificada | Alta (7.8) | 0.48% | — | Comodo Internet Security | 29/7/2024 | 17/6/2026 | Comodo Internet Security Pro Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order… | |
| Modificada | Media (5.5) | 0.20% | — | Eset Internet SecurityEset Nod32Eset SecurityEset Smart Security+4 | 16/7/2024 | 17/6/2026 | Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET’s security product inoperable, provided non-default preconditions were met. | |
| Analizada | Alta (7.8) | 0.20% | — | Bitdefender AntivirusBitdefender Antivirus PlusBitdefender Internet SecurityBitdefender Total Security | 1/4/2024 | 17/6/2026 | A configuration setting issue in seccenter.exe as used in Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus Plus, Bitdefender Antivirus Free allows an attacker to change the product's expected behavior and potentially load a third-party library upon execution. This issue affects Total… | |
| Modificada | Alta (7.8) | 0.55% | — | Eset Endpoint AntivirusEset Endpoint SecurityEset File SecurityEset Internet Security+5 | 15/2/2024 | 17/6/2026 | Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission. | |
| Modificada | Media (5.5) | 0.28% | — | Eset Endpoint AntivirusEset Endpoint SecurityEset Internet SecurityEset Mail Security+2 | 31/1/2024 | 17/6/2026 | Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with the NT AUTHORITY\NetworkService permissions. | |
| Modificada | Alta (7.8) | 0.64% | — | Trendmicro AIR SupportTrendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum Security+1 | 29/1/2024 | 17/6/2026 | Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable to a DLL hijacking/proxying vulnerability, which if exploited could allow an attacker to impersonate and modify a library to execute code on the system and ultimately escalate… | |
| Modificada | Alta (8.6) | 0.38% | — | Eset Endpoint AntivirusEset Endpoint SecurityEset File SecurityEset Internet Security+5 | 21/12/2023 | 17/6/2026 | Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted. |