Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Malwarebytes

First CVE: Dec 16, 2014Active for: 12 yearsTotal CVEs: 30
51.4
VTI Score
TOP TARGET

Malwarebytes develops security and system-maintenance software spanning endpoint protection, malware detection, and firewall control products that are widely deployed across consumer and enterprise environments. The vulnerability exposure recurs across its core products, including the Malwarebytes antimalware platform and complementary tools such as ADWCleaner and Windows Firewall Control, and clusters around input-validation and file-access weaknesses that reflect the complexity of threat detection and system-level integration work. A moderate share of the vendor's disclosures acquire public exploit code, presenting a tangible remediation priority for deployments of affected versions. Defenders should monitor this vendor's release cycles and prioritize patching for internet-accessible or high-value endpoint instances; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
30
Total CVEs
More Total CVEs than 97% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Malwarebytes over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 16, 2014
11 years ago
Most Recent CVE
Jun 19, 2026
35 days ago

Products(9 total)

Top CVEs

Signals from CVEs in this vendor scope (30 CVEs).

30 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-4936HIGH
The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE) consumer 1.04.1.1012 and earlier allow man-in-the-middle at
Dec 16, 20149.359NOYES
CVE-2022-50971HIGH
Malwarebytes 4.5 contains an unquoted service path vulnerability in the MBAMService executable that allows local attackers to escalate privileges by injecting malicious code into t
Jun 19, 20267.833NONO
CVE-2019-6739HIGH
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Malwarebytes Antimalware 3.6.1.2711. User interaction is required to exploit thi
Jun 3, 20198.833NONO
CVE-2022-25150HIGH
In Malwarebytes Binisoft Windows Firewall Control before 6.8.1.0, programs executed from the Tools tab can be used to escalate privileges.
Feb 14, 20227.825NONO
CVE-2020-11507HIGH
An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner 8.0.3 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded.
Apr 6, 20207.825NONO
CVE-2024-25089CRITICAL
Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes.
Feb 4, 20249.824NONO
CVE-2023-28892HIGH
Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs\AdwCleaner_Debug.log in which the target location is user-c
Mar 29, 20237.824NONO
CVE-2023-26088HIGH
In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine system. It can also lead to privilege escalati
Mar 23, 20237.824NONO
CVE-2020-25533HIGH
An issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged action within the Malwarebytes launch daemon. The privileged s
Jan 15, 20217.024NONO
CVE-2019-19929HIGH
An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner before 8.0.1 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded by
Dec 23, 20197.824NONO
View all 30 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products30 CVEs
83%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local26 (86.7%)
Network2 (6.7%)
Unknown2 (6.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (86.7%)
High2 (6.7%)
Unknown2 (6.7%)
User Interaction
None25 (83.3%)
Unknown2 (6.7%)
Required3 (10.0%)
Privileges Required
Low23 (76.7%)
High0 (0.0%)
None5 (16.7%)
Unknown2 (6.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (30 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.3% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
6.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Malwarebytes.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Malwarebytes — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Malwarebytes's Products

View all 3 CNAs →

Top CWEs