Totalav develops antivirus and threat-protection software with a focused product line; observed vulnerabilities cluster around privilege-escalation and access-control weaknesses, including incorrect default permissions, improper privilege assignment, and unquoted search-path issues common to Windows security contexts. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Totalav over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-18194HIGH TotalAV 2020 4.14.31 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junction to restore a malicious DLL from quarantine into the system | Jan 10, 2020 | 7.8 | 34 | NO | YES |
CVE-2021-47787HIGH TotalAV 5.15.69 contains an unquoted service path vulnerability in multiple system services running with LocalSystem privileges. Attackers can place malicious executables in specif | Jan 16, 2026 | 7.8 | 25 | NO | NO |
CVE-2018-7535HIGH An issue was discovered in TotalAV v4.1.7. An unprivileged user could modify or overwrite all of the product's files because of weak permissions (Everyone:F) under %PROGRAMFILES%, | Jul 13, 2018 | 7.8 | 24 | NO | NO |
CVE-2024-31771HIGH Insecure Permission vulnerability in TotalAV v.6.0.740 allows a local attacker to escalate privileges via a crafted file | May 14, 2024 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Totalav.
Media articles that mention a CVE ID that affects a product developed by Totalav — matched by CVE ID, not by vendor name.