| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-7073 | Local Privilege Escalation via Arbitrary File Operation in Bitdefender Total Security | Bitdefender | Total Security | - | - | 2025-12-10 09:46:40 | Deep Dive |
| CVE-2025-5317 | Improper access restriction to critical folder in Bitdefender Endpoint Security Tools for Mac | Bitdefender | Endpoint Security Tools for Mac | 中危 | - | 2025-11-11 08:02:23 | Deep Dive |
| CVE-2025-1987 | Stored XSS in Psono-Client via Malicious Vault Entry URLs | Psono | Psono-client | - | - | 2025-06-21 21:35:07 | Deep Dive |
| CVE-2025-2245 | Server Side Request Forgery in GravityZone Update Server Using Null Bytes (VA-12646) | Bitdefender | GravityZone Update Server | - | - | 2025-04-04 09:54:04 | Deep Dive |
| CVE-2025-2243 | SSRF in GravityZone Console via DNS Truncation (VA-12634) | Bitdefender | GravityZone Console | - | - | 2025-04-04 09:53:25 | Deep Dive |
| CVE-2025-2244 | Insecure PHP deserialization issue in GravityZone Console (VA-12634) | Bitdefender | GravityZone Console | - | - | 2025-04-04 09:52:49 | Deep Dive |
| CVE-2024-13870 | Unauthenticated Firmware Downgrade in Bitdefender Box v1 | Bitdefender | BOX v1 | 中危 | - | 2025-03-12 11:48:36 | Deep Dive |
| CVE-2024-13871 | Unauthenticated Command Injection in Bitdefender BOX v1 | Bitdefender | BOX v1 | 中危 | - | 2025-03-12 11:48:21 | Deep Dive |
| CVE-2024-13872 | Bitdefender Box Insecure Update Mechanism Vulnerability in libboxhermes.so | Bitdefender | BOX v1 | 中危 | - | 2025-03-12 11:47:46 | Deep Dive |
| CVE-2020-8094 | Untrusted Search Path Vulnerability in Bitdefender Antivirus Free 2020 (VA-8422) | Bitdefender | Antivirus Free 2020 | 中危 | - | 2025-01-15 16:12:35 | Deep Dive |
| CVE-2024-11128 | Insufficient Hardened Runtime or Library Validation signing in Bitdefender Virus Scanner for macOS | Bitdefender | Virus Scanner | 中危 | - | 2025-01-13 21:49:31 | Deep Dive |
| CVE-2023-49570 | Insecure Trust of Basic Constraints certificate in Bitdefender Total Security HTTPS Scanning (VA-11210) | Bitdefender | Total Security | 中危 | - | 2024-10-18 08:07:19 | Deep Dive |
| CVE-2023-49567 | Insecure Trust of certificates using collision hash functions in Bitdefender Total Security HTTPS Scanning (VA-11239) | Bitdefender | Total Security | 中危 | - | 2024-10-18 07:59:02 | Deep Dive |
| CVE-2023-6058 | HTTPS Certificate Validation Issue in Bitdefender Safepay (VA-11167) | Bitdefender | Total Security | 中危 | - | 2024-10-18 07:52:09 | Deep Dive |
| CVE-2023-6057 | Insecure Trust of DSA-Signed Certificates in Bitdefender Total Security HTTPS Scanning (VA-11166) | Bitdefender | Total Security | 中危 | - | 2024-10-18 07:38:24 | Deep Dive |
| CVE-2023-6056 | Insecure Trust of Self-Signed Certificates in Bitdefender Total Security HTTPS Scanning (VA-11164) | BItdefender | Total Security | 中危 | - | 2024-10-18 07:31:23 | Deep Dive |
| CVE-2023-6055 | Improper Certificate Validation in Bitdefender Total Security HTTPS Scanning (VA-11158) | Bitdefender | Total Security | 中危 | - | 2024-10-18 07:17:03 | Deep Dive |
| CVE-2024-6980 | Verbose error handling issue in GravityZone Update Server proxy service | Bitdefender | GravityZone Update Server | - | - | 2024-07-31 06:58:45 | Deep Dive |
| CVE-2024-4177 | Host whitelist parser issue in GravityZone Console On-Premise (VA-11554) | Bitdefender | GravityZone Console On-Premise | High | 8.1 | 2024-06-06 07:59:23 | Deep Dive |
| CVE-2024-2224 | Privilege Escalation via the GravityZone productManager UpdateServer.KitsManager API (VA-11466) | Bitdefender | GravityZone Control Center (On Premises) | High | 8.1 | 2024-04-09 13:01:47 | Deep Dive |