Products: 37
    Vulnerabilities: 41
    Known Exploited: 0
    3
    Critical Level Threats
    22
    High Level Threats
    16
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-27748

    Avira Internet Security Arbitrary File Deletion via Improper Link Resolution

    Last Modified: Apr 15, 2026
    Published: Mar 05, 2026

    CVE-2026-27749

    Avira Internet Security System Speedup Insecure Deserialization

    Last Modified: Apr 16, 2026
    Published: Mar 05, 2026

    CVE-2026-27750

    Avira Internet Security Optimizer TOCTOU

    Last Modified: Apr 16, 2026
    Published: Mar 05, 2026

    CVE-2023-51636

    Avira Prime Link Following Local Privilege Escalation Vulnerability

    Last Modified: Aug 14, 2025
    Published: May 22, 2024

    CVE-2023-36673

    An issue was discovered in Avira Phantom VPN through 2.23.1 for macOS. The VPN client insecurely configures the operating system such that all IP traffic to the VPN server's IP address is sent in plaintext outside the VPN tunnel, even if this traffic is not generated by the VPN client, while simultaneously using plaintext DNS to look up the VPN server's IP address. This allows an adversary to trick the victim into sending traffic to arbitrary IP addresses in plaintext outside the VPN tunnel. NOTE: the tunnelcrack.mathyvanhoef.com website uses this CVE ID to refer more generally to "ServerIP attack, combined with DNS spoofing, that can leak traffic to an arbitrary IP address" rather than to only Avira Phantom VPN.

    Last Modified: Nov 21, 2024
    Published: Aug 09, 2023
    Items Per Page