Vulnerability index

Browse CVEs

94 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Internet Security HIGH 7.0
CVE-2026-6851

An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and…

Fix: 27.0.58.315+
Fix from $1,950 2026-07-14
Napoca HIGH 7.8
CVE-2026-10046

Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the BIOS INT 0x15 / E820 memory map handler, implemented in…

Mitigation only
Fix from $1,950 2026-06-02
Napoca HIGH 7.8
CVE-2026-10047

The Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the real-mode hook handler, implemented in napoca/kerne…

Mitigation only
Fix from $1,950 2026-06-02
Antivirus HIGH 7.8
CVE-2025-7073

A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privileged attackers to elevate pri…

Fix: 7.9.20.515 / 27.0.47.241+
Fix from $1,950 2025-12-10
Endpoint Security MEDIUM 5.5
CVE-2025-5317

An improper access restriction to a folder in Bitdefender Endpoint Security Tools for Mac (BEST) before 7.20.52.200087 allows local users with admini…

Fix: 7.20.52.200087+
Fix from $1,600 2025-11-11
Gravityzone CRITICAL 9.8
CVE-2025-2244

A vulnerability in the sendMailFromRemoteSource method in Emails.php  as used in Bitdefender GravityZone Console unsafely uses php unserialize() on u…

Fix: 6.41.2-1+
Fix from $2,300 2025-04-04
Gravityzone HIGH 7.3
CVE-2025-2243

A server-side request forgery (SSRF) vulnerability in Bitdefender GravityZone Console allows an attacker to bypass input validation logic using leadi…

Fix: 6.41.2-1+
Fix from $1,950 2025-04-04
Gravityzone Update Server MEDIUM 5.3
CVE-2025-2245

A server-side request forgery (SSRF) vulnerability exists in the Bitdefender GravityZone Update Server when operating in Relay Mode. The HTTP proxy c…

Fix: 3.5.2.689+
Fix from $1,600 2025-04-04
Box Firmware HIGH 8.8
CVE-2024-13871

A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490). Th…

Mitigation only
Fix from $1,950 2025-03-12
Box Firmware HIGH 7.5
CVE-2024-13872

Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart d…

Fix: after 1.3.11.505
Fix from $1,950 2025-03-12
Box Firmware MEDIUM 5.7
CVE-2024-13870

An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows an unauthenticated attacker …

Fix: after 1.3.52.928
Fix from $1,600 2025-03-12
Antivirus 2020 HIGH 7.8
CVE-2020-8094

An untrusted search path vulnerability in testinitsigs.exe as used in Bitdefender Antivirus Free 2020 allows a low-privilege attacker to execute code…

Fix: 1.0.16.152+
Fix from $1,950 2025-01-15
Virus Scanner HIGH 7.8
CVE-2024-11128

A vulnerability in the BitdefenderVirusScanner binary as used in Bitdefender Virus Scanner for MacOS may allow .dynamic library injection (DYLD injec…

Fix: 3.18+
Fix from $1,950 2025-01-13
Total Security HIGH 7.4
CVE-2023-49570

A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software trusts a certificate issued by an e…

Fix: 27.0.25.115+
Fix from $1,950 2024-10-18
Total Security HIGH 7.4
CVE-2023-6055

A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software fails to properly validate website …

Fix: 27.0.25.115+
Fix from $1,950 2024-10-18
Total Security HIGH 7.4
CVE-2023-6056

A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of self-signed cert…

Fix: 27.0.25.115+
Fix from $1,950 2024-10-18
Total Security HIGH 7.4
CVE-2023-6057

A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of certificates iss…

Fix: 27.0.25.115+
Fix from $1,950 2024-10-18
Total Security MEDIUM 6.8
CVE-2023-49567

A vulnerability has been identified in the Bitdefender Total Security HTTPS scanning functionality where the product incorrectly checks the site's ce…

Fix: 27.0.25.115+
Fix from $1,600 2024-10-18
Total Security MEDIUM 6.8
CVE-2023-6058

A vulnerability has been identified in Bitdefender Safepay's handling of HTTPS connections. The issue arises when the product blocks a connection due…

Fix: 27.0.25.115+
Fix from $1,600 2024-10-18
Gravityzone CRITICAL 9.8
CVE-2024-6980

A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request fo…

Fix: 6.38.1-5+
Fix from $2,300 2024-07-31
Gravityzone CRITICAL 9.8
CVE-2024-4177

A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request for…

Fix: 6.38.1-2+
Fix from $2,300 2024-06-06
Endpoint Security CRITICAL 9.8
CVE-2024-2223

An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and …

Mitigation only
Fix from $2,300 2024-04-09
Endpoint Security CRITICAL 9.8
CVE-2024-2224

Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone…

Mitigation only
Fix from $2,300 2024-04-09
Antivirus HIGH 7.8
CVE-2023-6154

A configuration setting issue in seccenter.exe as used in Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus Plus, Bitd…

Mitigation only
Fix from $1,950 2024-04-01
Engines HIGH 7.5
CVE-2023-3633

An out-of-bounds write vulnerability in Bitdefender Engines on Windows causes the engine to crash. This issue affects Bitdefender Engines version 7.9…

Fix: 7.94792+
Fix from $1,950 2023-07-14
Antivirus Plus HIGH 7.8
CVE-2022-0357

Unquoted Search Path or Element vulnerability in the Vulnerability Scan component of Bitdefender Total Security, Bitdefender Internet Security, and B…

Fix: 26.0.10.45+
Fix from $1,950 2023-05-24
Engines MEDIUM 5.5
CVE-2022-3369

An Improper Access Control vulnerability in the bdservicehost.exe component, as used in Bitdefender Engines for Windows, allows an attacker to delete…

Fix: 7.92659+
Fix from $1,600 2022-11-01
Gravityzone CRITICAL 9.8
CVE-2022-2830

Deserialization of Untrusted Data vulnerability in the message processing component of Bitdefender GravityZone Console allows an attacker to pass uns…

Fix: 6.27.2-2 / 6.29.2-1+
Fix from $2,300 2022-09-05
Endpoint Security Tools HIGH 7.5
CVE-2022-0677

Improper Handling of Length Parameter Inconsistency vulnerability in the Update Server component of Bitdefender Endpoint Security Tools (in relay rol…

Fix: 3.4.0.276 / 6.2.21.171+
Fix from $1,950 2022-04-07
Antivirus Plus HIGH 7.8
CVE-2021-4199

Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used in Bitdefender Total Securit…

Fix: 7.4.3.146 / 26.0.3.29+
Fix from $1,950 2022-03-07