Bitdefender

First CVE: Jan 27, 2020Active for: 6 years
106
CVEs Published
More CVEs Published than 70% of tracked CNAs
15.1
Avg CVEs / Year
More Avg CVEs / Year than 62% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Bitdefender as a CNA, 66.0% affect products that Bitdefender develops as a vendor.

66.0%
34.0%
Self-reported: 70Third-party: 36

Of all the CVEs published that affect products developed by Bitdefender, 66.0% are self-published by Bitdefender as a CNA.

66.0%
34.0%
Self-published: 70Published by other CNAs: 36

Trends Over Time

The number and severity of CVEs published by Bitdefender over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 27, 2020
6 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

Top CVEs

All CVEs published by Bitdefender as a CNA, regardless of affected vendor or product.

106 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and Internet Security on Windows a
Jul 14, 20267.033NONO
Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows an attacker to manipulate the
Nov 24, 202110.033NONO
Stack-based Buffer Overflow vulnerability in the EZVIZ Motion Detection component as used in camera models CS-CV248, CS-C6N-A0-1C2WFR, CS-DB1C-A0-1E2W2FR, CS-C6N-B0-1G2WF, CS-C3W-A
Sep 15, 20229.832NONO
The Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the real-mode hook handler, implemented in napoca/kernel/handler.c. The handler uses a
Jun 2, 20267.831NONO
Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the BIOS INT 0x15 / E820 memory map handler, implemented in napoca/guests/bios_handlers.c.
Jun 2, 20267.831NONO
Deserialization of Untrusted Data vulnerability in the message processing component of Bitdefender GravityZone Console allows an attacker to pass unsafe commands to the environment
Sep 5, 20229.831NONO
Stack-based Buffer Overflow vulnerability in Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to run arbitrary code on the affected device. This issue affects: Wyze Cam Pan v2 ve
Mar 30, 20229.831NONO
A vulnerability in the sendMailFromRemoteSource method in Emails.php  as used in Bitdefender GravityZone Console unsafely uses php unserialize() on user-supplied input without vali
Apr 4, 20259.830NONO
A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects
Jul 31, 20249.830NONO
A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects G
Jun 6, 20249.830NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA106 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local38 (35.8%)
Network56 (52.8%)
Unknown0 (0.0%)
Physical1 (0.9%)
Adjacent Network11 (10.4%)
Attack Complexity
Low96 (90.6%)
High10 (9.4%)
Unknown0 (0.0%)
User Interaction
None92 (86.8%)
Unknown0 (0.0%)
Required13 (12.3%)
Privileges Required
Low40 (37.7%)
High7 (6.6%)
None59 (55.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (106 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Bitdefender as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Bitdefender as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs