Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Avast

First CVE: May 9, 2007Active for: 19 yearsTotal CVEs: 79
39.2
VTI Score
Medium

Avast's vulnerability footprint centers on a modestly sized but widely deployed consumer and professional antivirus product portfolio. The vendor's disclosures span a meaningful range of serious outcomes, and vulnerabilities affecting its products have a moderate tendency toward public exploit availability. The exposure recurs across its antivirus product line through weakness classes including improper link resolution before file access, memory-safety violations such as buffer overflows and out-of-bounds writes, and improper input validation—issues endemic to security software that must parse and process untrusted samples. Defenders should treat Avast advisories as relevant to endpoint security posture broadly, since the antivirus layer's security directly affects the hosts it protects; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
79
Total CVEs
More Total CVEs than 99% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Avast over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 9, 2007
19 years ago
Most Recent CVE
Dec 1, 2025
235 days ago

Products(36 total)

Top CVEs

Signals from CVEs in this vendor scope (79 CVEs).

79 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2010-3126HIGH
Untrusted search path vulnerability in avast! Free Antivirus version 5.0.594 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DL
Aug 26, 20109.340NOYES
CVE-2016-3986HIGH
Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a crafted PE file, related to authenticode parsing.
Apr 12, 20167.839NOYES
CVE-2025-3500CRITICAL
Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3.
Dec 1, 20259.832NONO
CVE-2022-4291CRITICAL
The aswjsflt.dll library from Avast Antivirus windows contained a potentially exploitable heap corruption vulnerability that could enable an attacker to bypass the sandbox of the a
Dec 8, 202210.031NONO
CVE-2017-8307CRITICAL
In Avast Antivirus before v17, using the LPC interface API exposed by the AvastSVC.exe Windows service, it is possible to launch predefined binaries, or replace or delete arbitrary
Apr 27, 20179.831NONO
CVE-2020-10867CRITICAL
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to bypass intended access
Apr 1, 20209.830NONO
CVE-2020-23907CRITICAL
An issue was discovered in retdec v3.3. In function canSplitFunctionOn() of ir_modifications.cpp, there is a possible out of bounds read due to a heap buffer overflow. The impact i
Apr 21, 20219.829NONO
CVE-2010-0705HIGH
Aavmker4.sys in avast! 4.8 through 4.8.1368.0 and 5.0 before 5.0.418.0 running on Windows 2000 and XP does not properly validate input to IOCTL 0xb2d60030, which allows local users
Feb 25, 20107.229NOYES
CVE-2009-4049HIGH
Heap-based buffer overflow in aswRdr.sys (aka the TDI RDR driver) in avast! Home and Professional 4.8.1356.0 allows local users to cause a denial of service (memory corruption) or
Nov 23, 20097.229NOYES
CVE-2009-3522HIGH
Stack-based buffer overflow in aswMon2.sys in avast! Home and Professional for Windows 4.8.1351, and possibly other versions before 4.8.1356, allows local users to cause a denial o
Oct 1, 20097.229NOYES
View all 79 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products79 CVEs
35%
56%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local44 (55.7%)
Network17 (21.5%)
Unknown18 (22.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low56 (70.9%)
High5 (6.3%)
Unknown18 (22.8%)
User Interaction
None52 (65.8%)
Unknown18 (22.8%)
Required9 (11.4%)
Privileges Required
Low36 (45.6%)
High4 (5.1%)
None21 (26.6%)
Unknown18 (22.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (79 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
10.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Avast.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Avast — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Avast's Products

View all 4 CNAs →

Top CWEs