Vulnerability index

Browse CVEs

94 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.0 CVE-2026-6851 An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and… Internet Security 27.0.58.315+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-10046 Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the BIOS INT 0x15 / E820 memory map handler, implemented in… Napoca Mitigation only Fix from $1,9502026-06-02 HIGH 7.8 CVE-2026-10047 The Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the real-mode hook handler, implemented in napoca/kerne… Napoca Mitigation only Fix from $1,9502026-06-02 HIGH 7.8 CVE-2025-7073 A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privileged attackers to elevate pri… Antivirus 7.9.20.515 / 27.0.47.241+ Fix from $1,9502025-12-10 MEDIUM 5.5 CVE-2025-5317 An improper access restriction to a folder in Bitdefender Endpoint Security Tools for Mac (BEST) before 7.20.52.200087 allows local users with admini… Endpoint Security 7.20.52.200087+ Fix from $1,6002025-11-11 CRITICAL 9.8 CVE-2025-2244 A vulnerability in the sendMailFromRemoteSource method in Emails.php  as used in Bitdefender GravityZone Console unsafely uses php unserialize() on u… Gravityzone 6.41.2-1+ Fix from $2,3002025-04-04 HIGH 7.3 CVE-2025-2243 A server-side request forgery (SSRF) vulnerability in Bitdefender GravityZone Console allows an attacker to bypass input validation logic using leadi… Gravityzone 6.41.2-1+ Fix from $1,9502025-04-04 MEDIUM 5.3 CVE-2025-2245 A server-side request forgery (SSRF) vulnerability exists in the Bitdefender GravityZone Update Server when operating in Relay Mode. The HTTP proxy c… Gravityzone Update Server 3.5.2.689+ Fix from $1,6002025-04-04 HIGH 8.8 CVE-2024-13871 A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490). Th… Box Firmware Mitigation only Fix from $1,9502025-03-12 HIGH 7.5 CVE-2024-13872 Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart d… Box Firmware after 1.3.11.505 Fix from $1,9502025-03-12 MEDIUM 5.7 CVE-2024-13870 An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows an unauthenticated attacker … Box Firmware after 1.3.52.928 Fix from $1,6002025-03-12 HIGH 7.8 CVE-2020-8094 An untrusted search path vulnerability in testinitsigs.exe as used in Bitdefender Antivirus Free 2020 allows a low-privilege attacker to execute code… Antivirus 2020 1.0.16.152+ Fix from $1,9502025-01-15 HIGH 7.8 CVE-2024-11128 A vulnerability in the BitdefenderVirusScanner binary as used in Bitdefender Virus Scanner for MacOS may allow .dynamic library injection (DYLD injec… Virus Scanner 3.18+ Fix from $1,9502025-01-13 HIGH 7.4 CVE-2023-49570 A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software trusts a certificate issued by an e… Total Security 27.0.25.115+ Fix from $1,9502024-10-18 HIGH 7.4 CVE-2023-6055 A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software fails to properly validate website … Total Security 27.0.25.115+ Fix from $1,9502024-10-18 HIGH 7.4 CVE-2023-6056 A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of self-signed cert… Total Security 27.0.25.115+ Fix from $1,9502024-10-18 HIGH 7.4 CVE-2023-6057 A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of certificates iss… Total Security 27.0.25.115+ Fix from $1,9502024-10-18 MEDIUM 6.8 CVE-2023-49567 A vulnerability has been identified in the Bitdefender Total Security HTTPS scanning functionality where the product incorrectly checks the site's ce… Total Security 27.0.25.115+ Fix from $1,6002024-10-18 MEDIUM 6.8 CVE-2023-6058 A vulnerability has been identified in Bitdefender Safepay's handling of HTTPS connections. The issue arises when the product blocks a connection due… Total Security 27.0.25.115+ Fix from $1,6002024-10-18 CRITICAL 9.8 CVE-2024-6980 A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request fo… Gravityzone 6.38.1-5+ Fix from $2,3002024-07-31 CRITICAL 9.8 CVE-2024-4177 A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request for… Gravityzone 6.38.1-2+ Fix from $2,3002024-06-06 CRITICAL 9.8 CVE-2024-2223 An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and … Endpoint Security Mitigation only Fix from $2,3002024-04-09 CRITICAL 9.8 CVE-2024-2224 Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone… Endpoint Security Mitigation only Fix from $2,3002024-04-09 HIGH 7.8 CVE-2023-6154 A configuration setting issue in seccenter.exe as used in Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus Plus, Bitd… Antivirus Mitigation only Fix from $1,9502024-04-01 HIGH 7.5 CVE-2023-3633 An out-of-bounds write vulnerability in Bitdefender Engines on Windows causes the engine to crash. This issue affects Bitdefender Engines version 7.9… Engines 7.94792+ Fix from $1,9502023-07-14 HIGH 7.8 CVE-2022-0357 Unquoted Search Path or Element vulnerability in the Vulnerability Scan component of Bitdefender Total Security, Bitdefender Internet Security, and B… Antivirus Plus 26.0.10.45+ Fix from $1,9502023-05-24 MEDIUM 5.5 CVE-2022-3369 An Improper Access Control vulnerability in the bdservicehost.exe component, as used in Bitdefender Engines for Windows, allows an attacker to delete… Engines 7.92659+ Fix from $1,6002022-11-01 CRITICAL 9.8 CVE-2022-2830 Deserialization of Untrusted Data vulnerability in the message processing component of Bitdefender GravityZone Console allows an attacker to pass uns… Gravityzone 6.27.2-2 / 6.29.2-1+ Fix from $2,3002022-09-05 HIGH 7.5 CVE-2022-0677 Improper Handling of Length Parameter Inconsistency vulnerability in the Update Server component of Bitdefender Endpoint Security Tools (in relay rol… Endpoint Security Tools 3.4.0.276 / 6.2.21.171+ Fix from $1,9502022-04-07 HIGH 7.8 CVE-2021-4199 Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used in Bitdefender Total Securit… Antivirus Plus 7.4.3.146 / 26.0.3.29+ Fix from $1,9502022-03-07