Skip to main content

Vendor archive

bitdefender CVEs

Beta · best-effort

106 CVEs tagged to vendor bitdefender13 Critical, 48 High, 42 Medium, 3 Low, 0 Unrated.

CVE-2026-10047

Published Jun 2, 2026

The Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the real-mode hook handler, implemented in napoca/kernel/handler.c. The handler uses…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-10046

Published Jun 2, 2026

Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the BIOS INT 0x15 / E820 memory map handler, implemented in napoca/guests/bios_handlers.c…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-5317

Published Nov 11, 2025

An improper access restriction to a folder in Bitdefender Endpoint Security Tools for Mac (BEST) before 7.20.52.200087 allows local users with administrative privileges to bypass…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1987

Published Jun 21, 2025

A Cross-Site Scripting (XSS) vulnerability has been identified in Psono-Client’s handling of vault entries of type website_password and bookmark, as used in Bitdefender SecurePass…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-2245

Published Apr 4, 2025

A server-side request forgery (SSRF) vulnerability exists in the Bitdefender GravityZone Update Server when operating in Relay Mode. The HTTP proxy component on port 7074 uses a d…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-2244

Published Apr 4, 2025

A vulnerability in the sendMailFromRemoteSource method in Emails.php  as used in Bitdefender GravityZone Console unsafely uses php unserialize() on user-supplied input without val…

CVSS 9.5 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-2243

Published Apr 4, 2025

A server-side request forgery (SSRF) vulnerability in Bitdefender GravityZone Console allows an attacker to bypass input validation logic using leading characters in DNS requests.…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-13872

Published Mar 12, 2025

Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules on…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-13871

Published Mar 12, 2025

A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490). This flaw allows an unauthentica…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-8094

Published Jan 15, 2025

An untrusted search path vulnerability in testinitsigs.exe as used in Bitdefender Antivirus Free 2020 allows a low-privilege attacker to execute code as SYSTEM via a specially cra…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11128

Published Jan 13, 2025

A vulnerability in the BitdefenderVirusScanner binary as used in Bitdefender Virus Scanner for MacOS may allow .dynamic library injection (DYLD injection) without being blocked by…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49570

Published Oct 18, 2024

A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software trusts a certificate issued by an entity that isn't authorized to…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6058

Published Oct 18, 2024

A vulnerability has been identified in Bitdefender Safepay's handling of HTTPS connections. The issue arises when the product blocks a connection due to an untrusted server certif…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6057

Published Oct 18, 2024

A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of certificates issued using the DSA signature al…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6056

Published Oct 18, 2024

A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of self-signed certificates. The product is found…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6055

Published Oct 18, 2024

A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software fails to properly validate website certificates. Specifically, if…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49567

Published Oct 18, 2024

A vulnerability has been identified in the Bitdefender Total Security HTTPS scanning functionality where the product incorrectly checks the site's certificate, which allows an att…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6980

Published Jul 31, 2024

A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects…

CVSS 9.2 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-4177

Published Jun 6, 2024

A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3633

Published Jul 14, 2023

An out-of-bounds write vulnerability in Bitdefender Engines on Windows causes the engine to crash. This issue affects Bitdefender Engines version 7.94791 and lower.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 106 CVEsPage 1 of 5