Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.0
CVE-2026-6851
An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and…
Internet Security
27.0.58.315+
HIGH 7.8
CVE-2026-10046
Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the BIOS INT 0x15 / E820 memory map handler, implemented in…
Napoca
Mitigation only
HIGH 7.8
CVE-2026-10047
The Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the real-mode hook handler, implemented in napoca/kerne…
Napoca
Mitigation only
HIGH 7.8
CVE-2025-7073
A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privileged attackers to elevate pri…
Antivirus
7.9.20.515 / 27.0.47.241+
MEDIUM 5.5
CVE-2025-5317
An improper access restriction to a folder in Bitdefender Endpoint Security Tools for Mac (BEST) before 7.20.52.200087 allows local users with admini…
Endpoint Security
7.20.52.200087+
CRITICAL 9.8
CVE-2025-2244
A vulnerability in the sendMailFromRemoteSource method in Emails.php as used in Bitdefender GravityZone Console unsafely uses php unserialize() on u…
Gravityzone
6.41.2-1+
HIGH 7.3
CVE-2025-2243
A server-side request forgery (SSRF) vulnerability in Bitdefender GravityZone Console allows an attacker to bypass input validation logic using leadi…
Gravityzone
6.41.2-1+
MEDIUM 5.3
CVE-2025-2245
A server-side request forgery (SSRF) vulnerability exists in the Bitdefender GravityZone Update Server when operating in Relay Mode. The HTTP proxy c…
Gravityzone Update Server
3.5.2.689+
HIGH 8.8
CVE-2024-13871
A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490). Th…
Box Firmware
Mitigation only
HIGH 7.5
CVE-2024-13872
Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart d…
Box Firmware
after 1.3.11.505
MEDIUM 5.7
CVE-2024-13870
An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows an unauthenticated attacker …
Box Firmware
after 1.3.52.928
HIGH 7.8
CVE-2020-8094
An untrusted search path vulnerability in testinitsigs.exe as used in Bitdefender Antivirus Free 2020 allows a low-privilege attacker to execute code…
Antivirus 2020
1.0.16.152+
HIGH 7.8
CVE-2024-11128
A vulnerability in the BitdefenderVirusScanner binary as used in Bitdefender Virus Scanner for MacOS may allow .dynamic library injection (DYLD injec…
Virus Scanner
3.18+
HIGH 7.4
CVE-2023-49570
A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software trusts a certificate issued by an e…
Total Security
27.0.25.115+
HIGH 7.4
CVE-2023-6055
A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software fails to properly validate website …
Total Security
27.0.25.115+
HIGH 7.4
CVE-2023-6056
A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of self-signed cert…
Total Security
27.0.25.115+
HIGH 7.4
CVE-2023-6057
A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of certificates iss…
Total Security
27.0.25.115+
MEDIUM 6.8
CVE-2023-49567
A vulnerability has been identified in the Bitdefender Total Security HTTPS scanning functionality where the product incorrectly checks the site's ce…
Total Security
27.0.25.115+
MEDIUM 6.8
CVE-2023-6058
A vulnerability has been identified in Bitdefender Safepay's handling of HTTPS connections. The issue arises when the product blocks a connection due…
Total Security
27.0.25.115+
CRITICAL 9.8
CVE-2024-6980
A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request fo…
Gravityzone
6.38.1-5+
CRITICAL 9.8
CVE-2024-4177
A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request for…
Gravityzone
6.38.1-2+
CRITICAL 9.8
CVE-2024-2223
An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and …
Endpoint Security
Mitigation only
CRITICAL 9.8
CVE-2024-2224
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone…
Endpoint Security
Mitigation only
HIGH 7.8
CVE-2023-6154
A configuration setting issue in seccenter.exe as used in Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus Plus, Bitd…
Antivirus
Mitigation only
HIGH 7.5
CVE-2023-3633
An out-of-bounds write vulnerability in Bitdefender Engines on Windows causes the engine to crash. This issue affects Bitdefender Engines version 7.9…
Engines
7.94792+
HIGH 7.8
CVE-2022-0357
Unquoted Search Path or Element vulnerability in the Vulnerability Scan component of Bitdefender Total Security, Bitdefender Internet Security, and B…
Antivirus Plus
26.0.10.45+
MEDIUM 5.5
CVE-2022-3369
An Improper Access Control vulnerability in the bdservicehost.exe component, as used in Bitdefender Engines for Windows, allows an attacker to delete…
Engines
7.92659+
CRITICAL 9.8
CVE-2022-2830
Deserialization of Untrusted Data vulnerability in the message processing component of Bitdefender GravityZone Console allows an attacker to pass uns…
Gravityzone
6.27.2-2 / 6.29.2-1+
HIGH 7.5
CVE-2022-0677
Improper Handling of Length Parameter Inconsistency vulnerability in the Update Server component of Bitdefender Endpoint Security Tools (in relay rol…
Endpoint Security Tools
3.4.0.276 / 6.2.21.171+
HIGH 7.8
CVE-2021-4199
Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used in Bitdefender Total Securit…
Antivirus Plus
7.4.3.146 / 26.0.3.29+