Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bitdefender

First CVE: Jan 19, 2007Active for: 20 yearsTotal CVEs: 106
45.1
VTI Score
High

Bitdefender maintains a focused portfolio of endpoint protection, threat management, and consumer security products—including Total Security, GravityZone, and Endpoint Security Tools—that operate across enterprise and consumer deployments and handle sensitive system and network traffic. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the privileged access and trust these products command within protected systems. The exposure recurs through weakness classes including server-side request forgery, improper certificate validation, and input-validation flaws that are characteristic of security software's deep integration with operating systems and its role in parsing untrusted security-relevant data. Defenders should treat Bitdefender advisories with priority, since vulnerabilities in endpoint protection tools directly undermine the systems they are meant to defend. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
106
Total CVEs
More Total CVEs than 99% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Bitdefender over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 19, 2007
19 years ago
Most Recent CVE
Jun 2, 2026
52 days ago

Self-Reporting Analysis

Of all the CVEs published by Bitdefender as a CNA, 66.0% affect products that Bitdefender develops as a vendor.

66.0%
34.0%
Self-reported: 70 (66.0%)
Third-party: 36 (34.0%)

Of all the CVEs published that affect products developed by Bitdefender, 66.0% are self-published by Bitdefender as a CNA.

66.0%
34.0%
Self-published: 70 (66.0%)
Other CNAs: 36 (34.0%)

Products(34 total)

Top CVEs

Signals from CVEs in this vendor scope (106 CVEs).

106 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-1459MEDIUM
The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10
Mar 21, 20124.371NONO
CVE-2012-1457MEDIUM
The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka
Mar 21, 20124.370NONO
CVE-2012-1443MEDIUM
The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protectio
Mar 21, 20124.369NONO
CVE-2012-1430MEDIUM
The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (form
Mar 21, 20124.367NONO
CVE-2012-1461MEDIUM
The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus
Mar 21, 20124.366NONO
CVE-2012-1463MEDIUM
The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.
Mar 21, 20124.365NONO
CVE-2012-1431MEDIUM
The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, McAfee Gatew
Mar 21, 20124.365NONO
CVE-2014-5350MEDIUM
Multiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the id parameter
Aug 19, 20145.064NOYES
CVE-2007-5775CRITICAL
Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024. NOTE: as of 20071029, the only disclosure is a vag
Nov 1, 20079.855NOYES
CVE-2008-5409HIGH
Unspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGuard Internet Security 8.5, and (3) Software602 Groupware Ser
Dec 10, 20089.338NOYES
View all 106 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products106 CVEs
36%
49%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local40 (37.7%)
Network46 (43.4%)
Unknown16 (15.1%)
Physical1 (0.9%)
Adjacent Network3 (2.8%)
Attack Complexity
Low76 (71.7%)
High14 (13.2%)
Unknown16 (15.1%)
User Interaction
None67 (63.2%)
Unknown16 (15.1%)
Required23 (21.7%)
Privileges Required
Low31 (29.2%)
High5 (4.7%)
None54 (50.9%)
Unknown16 (15.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (106 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
4.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bitdefender.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bitdefender — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bitdefender's Products

View all 3 CNAs →

Top CWEs