Bitdefender records
107 published records for vendor bitdefender.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 21
- With a fix record
- 2.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls9
- CWE-295 Improper Certificate Validation7
- CWE-59 Improper Link Resolution Before File Access ('Link Following')6
- CWE-918 Server-Side Request Forgery (SSRF)6
- CWE-426 Untrusted Search Path5
- CWE-787 Out-of-bounds Write5
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
107 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
47Plan | CVE-2012-1459No exploit | The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8ahnlab · v3 internet security · CWE-264 | Medium4.3 | — | 99.8% | Mar 21, 2012 |
47Plan | CVE-2012-1443No exploit | The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 2010cat · quick heal · CWE-264 | Medium4.3 | — | 99.6% | Mar 21, 2012 |
47Plan | CVE-2007-5775Proof of concept | Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024.bitdefender · antivirus · CWE-94 | Critical9.8 | — | 26.9% | Nov 1, 2007 |
46Plan | CVE-2012-1457No exploit | The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.anti-virus · vba32 · CWE-264 | Medium4.3 | — | 98.3% | Mar 21, 2012 |
46Plan | CVE-2012-1430No exploit | The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Ebitdefender · bitdefender · CWE-264 | Medium4.3 | — | 96.0% | Mar 21, 2012 |
46Plan | CVE-2012-1431No exploit | The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secbitdefender · bitdefender · CWE-264 | Medium4.3 | — | 96.0% | Mar 21, 2012 |
45Plan | CVE-2012-1463No exploit | The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5ahnlab · v3 internet security · CWE-264 | Medium4.3 | — | 94.2% | Mar 21, 2012 |
45Plan | CVE-2012-1461No exploit | The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Antanti-virus · vba32 · CWE-264 | Medium4.3 | — | 91.7% | Mar 21, 2012 |
41Plan | CVE-2021-3554No exploit | Improper Access Control vulnerability in the patchesUpdate APIbitdefender · endpoint security tools · CWE-284 | Critical10.0 | — | 2.6% | Nov 24, 2021 |
40Plan | CVE-2008-5409Proof of concept | Unspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGuard Internet Securitbitdefender · antivirus · CWE-119 | Critical9.3 | — | 11.1% | Dec 10, 2008 |
40Plan | CVE-2018-8955No exploit | The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which albitdefender · gravityzone · CWE-347 | Critical9.8 | — | 4.3% | Oct 24, 2018 |
40Plan | CVE-2019-17095No exploit | Bitdefender BOX 2 bootstrap download_image command injection vulnerabilitybitdefender · box 2 firmware · CWE-78 | Critical9.8 | — | 4.2% | Jan 27, 2020 |
40Plan | CVE-2019-17096No exploit | Bitdefender BOX 2 bootstrap get_image_size command injection vulnerabilitybitdefender · box 2 firmware · CWE-78 | Critical9.8 | — | 2.1% | Jan 27, 2020 |
39Monitor | CVE-2014-5350Proof of concept | Multiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read arbitrary files viabitdefender · gravityzone · CWE-22 | Medium5.0 | — | 63.9% | Aug 19, 2014 |
39Monitor | CVE-2007-6189Proof of concept | A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to execbitdefender · online anti-virus scanner · CWE-119 | Critical9.3 | — | 8.1% | Nov 29, 2007 |
39Monitor | CVE-2017-8931No exploit | Bitdefender GravityZone VMware appliance before 6.2.1-35 might allow attackers to gain access with root privileges via unspecified vectors.bitdefender · gravityzone | Critical9.8 | — | 1.5% | Oct 30, 2018 |
39Monitor | CVE-2021-3823No exploit | Path traversal vulnerability in Bitdefender GravitZone Update Server in relay modebitdefender · gravityzone · CWE-22 | Critical9.8 | — | 1.1% | Oct 28, 2021 |
39Monitor | CVE-2022-2830No exploit | Deserialization of Untrusted Data in GravityZone Console On-Premise (VA-10573)bitdefender · gravityzone · CWE-502 | Critical9.8 | — | 0.9% | Sep 5, 2022 |
39Monitor | CVE-2024-2224No exploit | Privilege Escalation via the GravityZone productManager UpdateServer.KitsManager API (VA-11466)bitdefender · endpoint security · CWE-22 | Critical9.8 | — | 0.7% | Apr 9, 2024 |
39Monitor | CVE-2024-2223No exploit | Incorrect Regular Expression in GravityZone Update Server (VA-11465)bitdefender · endpoint security · CWE-185 | Critical9.8 | — | 0.5% | Apr 9, 2024 |
39Monitor | CVE-2024-4177No exploit | Host whitelist parser issue in GravityZone Console On-Premise (VA-11554)bitdefender · gravityzone · CWE-116 | Critical9.8 | — | 0.4% | Jun 6, 2024 |
38Monitor | CVE-2025-2244No exploit | Insecure PHP deserialization issue in GravityZone Console (VA-12634)bitdefender · gravityzone · CWE-502 | Critical9.5 | — | 1.1% | Apr 4, 2025 |
37Monitor | CVE-2017-17408No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender Internet Security 2018.bitdefender · internet security 2018 · CWE-190 | High8.8 | — | 6.5% | Dec 21, 2017 |
37Monitor | CVE-2024-13871No exploit | Unauthenticated Command Injection in Bitdefender BOX v1bitdefender · box firmware · CWE-77 | Critical9.4 | — | 0.8% | Mar 12, 2025 |
37Monitor | CVE-2025-1987No exploit | Stored XSS in Psono-Client via Malicious Vault Entry URLsesaqa · psono client · CWE-79 | Critical9.3 | — | 0.6% | Jun 21, 2025 |
- CVE-2012-145947Plan
The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8
MediumCVSS 4.3No exploitEPSS 100%ahnlab · v3 internet securityMar 21, 2012
- CVE-2012-144347Plan
The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 2010
MediumCVSS 4.3No exploitEPSS 100%cat · quick healMar 21, 2012
- CVE-2007-577547Plan
Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024.
CriticalCVSS 9.8Proof of conceptEPSS 27%bitdefender · antivirusNov 1, 2007
- CVE-2012-145746Plan
The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.
MediumCVSS 4.3No exploitEPSS 98%anti-virus · vba32Mar 21, 2012
- CVE-2012-143046Plan
The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning E
MediumCVSS 4.3No exploitEPSS 96%bitdefender · bitdefenderMar 21, 2012
- CVE-2012-143146Plan
The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Sec
MediumCVSS 4.3No exploitEPSS 96%bitdefender · bitdefenderMar 21, 2012
- CVE-2012-146345Plan
The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5
MediumCVSS 4.3No exploitEPSS 94%ahnlab · v3 internet securityMar 21, 2012
- CVE-2012-146145Plan
The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Ant
MediumCVSS 4.3No exploitEPSS 92%anti-virus · vba32Mar 21, 2012
- CVE-2021-355441Plan
Improper Access Control vulnerability in the patchesUpdate API
CriticalCVSS 10.0No exploitEPSS 3%bitdefender · endpoint security toolsNov 24, 2021
- CVE-2008-540940Plan
Unspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGuard Internet Securit
CriticalCVSS 9.3Proof of conceptEPSS 11%bitdefender · antivirusDec 10, 2008
- CVE-2018-895540Plan
The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which al
CriticalCVSS 9.8No exploitEPSS 4%bitdefender · gravityzoneOct 24, 2018
- CVE-2019-1709540Plan
Bitdefender BOX 2 bootstrap download_image command injection vulnerability
CriticalCVSS 9.8No exploitEPSS 4%bitdefender · box 2 firmwareJan 27, 2020
- CVE-2019-1709640Plan
Bitdefender BOX 2 bootstrap get_image_size command injection vulnerability
CriticalCVSS 9.8No exploitEPSS 2%bitdefender · box 2 firmwareJan 27, 2020
- CVE-2014-535039Monitor
Multiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read arbitrary files via
MediumCVSS 5.0Proof of conceptEPSS 64%bitdefender · gravityzoneAug 19, 2014
- CVE-2007-618939Monitor
A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to exec
CriticalCVSS 9.3Proof of conceptEPSS 8%bitdefender · online anti-virus scannerNov 29, 2007
- CVE-2017-893139Monitor
Bitdefender GravityZone VMware appliance before 6.2.1-35 might allow attackers to gain access with root privileges via unspecified vectors.
CriticalCVSS 9.8No exploitEPSS 2%bitdefender · gravityzoneOct 30, 2018
- CVE-2021-382339Monitor
Path traversal vulnerability in Bitdefender GravitZone Update Server in relay mode
CriticalCVSS 9.8No exploitEPSS 1%bitdefender · gravityzoneOct 28, 2021
- CVE-2022-283039Monitor
Deserialization of Untrusted Data in GravityZone Console On-Premise (VA-10573)
CriticalCVSS 9.8No exploitEPSS 1%bitdefender · gravityzoneSep 5, 2022
- CVE-2024-222439Monitor
Privilege Escalation via the GravityZone productManager UpdateServer.KitsManager API (VA-11466)
CriticalCVSS 9.8No exploitEPSS 1%bitdefender · endpoint securityApr 9, 2024
- CVE-2024-222339Monitor
Incorrect Regular Expression in GravityZone Update Server (VA-11465)
CriticalCVSS 9.8No exploitEPSS 1%bitdefender · endpoint securityApr 9, 2024
- CVE-2024-417739Monitor
Host whitelist parser issue in GravityZone Console On-Premise (VA-11554)
CriticalCVSS 9.8No exploitEPSS 0%bitdefender · gravityzoneJun 6, 2024
- CVE-2025-224438Monitor
Insecure PHP deserialization issue in GravityZone Console (VA-12634)
CriticalCVSS 9.5No exploitEPSS 1%bitdefender · gravityzoneApr 4, 2025
- CVE-2017-1740837Monitor
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender Internet Security 2018.
HighCVSS 8.8No exploitEPSS 6%bitdefender · internet security 2018Dec 21, 2017
- CVE-2024-1387137Monitor
Unauthenticated Command Injection in Bitdefender BOX v1
CriticalCVSS 9.4No exploitEPSS 1%bitdefender · box firmwareMar 12, 2025
- CVE-2025-198737Monitor
Stored XSS in Psono-Client via Malicious Vault Entry URLs
CriticalCVSS 9.3No exploitEPSS 1%esaqa · psono clientJun 21, 2025