Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

avira

About This Vendor

avira is a technology vendor producing software and infrastructure products. As a software provider, avira's broad product portfolio across multiple domains—including operating systems, cloud infrastructure, enterprise applications, databases, networking, and security tools—creates a large attack surface. Additionally, long support cycles, widespread deployment, and continuous feature development contribute to the accumulation of discovered vulnerabilities over time. Major vendors typically report higher CVE counts not necessarily due to inferior security, but because of greater exposure to security research, responsible disclosure practices, and the sheer complexity of maintaining multiple product lines and legacy systems. Regular security assessments and patching of avira's products are critical for organizations running their software in production environments.

Vulnerability Trends for This Vendor

SecUtils has indexed 41 known vulnerabilities from avira. This includes 1 critical-severity issue and 24 high-severity issues that represent significant risk. These vulnerabilities affect 82 distinct products across avira's portfolio, demonstrating the breadth of the vendor's product ecosystem and the importance of comprehensive patch management strategies. Disclosure dates span from 2005 through 2026, indicating decades of continuous security attention and research. Organizations deploying avira products should maintain active vulnerability monitoring, prioritize critical patches, and implement compensating controls where patches cannot be applied immediately.

ID Date Published Last Modified Severity (CVSSv3) Severity (CVSSv2) Exploit Available
CVE-2005-2957 2005-09-16 2025-04-03 - 7.5 Likely
CVE-2005-3219 2005-10-14 2025-04-03 - 5.1 Unknown
CVE-2005-3224 2005-10-14 2025-04-03 - 5.1 Unknown
CVE-2006-1274 2006-03-19 2025-04-03 - 7.2 Unknown
CVE-2006-4619 2006-09-07 2025-04-03 - 4.6 Unknown
CVE-2007-1671 2007-05-09 2025-04-09 - 7.8 Likely
CVE-2007-1673 2007-05-09 2025-04-09 - 7.8 Likely
CVE-2007-2972 2007-06-01 2025-04-09 - 7.8 Likely
CVE-2007-2973 2007-06-01 2025-04-09 - 7.8 Likely
CVE-2007-2974 2007-06-01 2025-04-09 - 10.0 Likely
CVE-2008-6962 2009-08-13 2025-04-09 - 7.2 Unknown
CVE-2009-2761 2009-08-13 2025-04-09 - 7.2 Unknown
CVE-2012-1425 2012-03-21 2025-04-11 - 4.3 Likely
CVE-2012-1443 2012-03-21 2025-04-11 - 4.3 Likely
CVE-2012-1457 2012-03-21 2025-04-11 - 4.3 Likely
CVE-2012-1459 2012-03-21 2025-04-11 - 4.3 Likely
CVE-2010-5153 2012-08-25 2025-04-11 5.3 6.2 Unknown
CVE-2014-5576 2014-09-09 2025-04-12 - 5.4 Unknown
CVE-2015-7303 2015-09-21 2025-04-12 - 10.0 Likely
CVE-2017-6417 2017-03-21 2025-04-20 6.7 7.2 Unknown
CVE-2015-7732 2017-06-15 2025-04-20 7.5 5.0 Likely
CVE-2016-10402 2017-07-27 2025-04-20 7.8 9.3 Likely
CVE-2019-11396 2019-08-29 2024-11-21 7.8 7.2 Unknown
CVE-2019-17449 2019-10-10 2024-11-21 6.7 4.6 Unknown
CVE-2019-18568 2019-12-31 2024-11-21 8.8 7.2 Unknown
CVE-2013-4602 2020-02-12 2024-11-21 5.5 7.1 Likely
CVE-2020-9320 2020-02-20 2024-11-21 5.5 4.3 Likely
CVE-2020-8961 2020-04-09 2024-11-21 9.8 7.5 Likely
CVE-2020-12254 2020-04-26 2024-11-21 7.8 4.6 Unknown
CVE-2020-12463 2020-05-05 2024-11-21 7.8 4.6 Unknown
CVE-2020-12680 2020-05-08 2024-11-21 5.5 2.1 Unknown
CVE-2022-28795 2022-04-12 2024-11-21 6.5 4.3 Likely
CVE-2022-3368 2022-10-17 2025-05-10 7.3 - -
CVE-2022-4294 2023-01-10 2024-11-21 7.1 - -
CVE-2022-4429 2023-01-10 2024-11-21 5.3 - -
CVE-2023-1900 2023-04-19 2025-02-05 7.8 - -
CVE-2023-36673 2023-08-09 2024-11-21 7.3 - -
CVE-2023-51636 2024-05-22 2025-08-14 7.8 - -
CVE-2026-27748 2026-03-05 2026-03-13 7.8 - -
CVE-2026-27749 2026-03-05 2026-03-13 7.8 - -
CVE-2026-27750 2026-03-05 2026-03-13 7.8 - -

How SecUtils Normalizes Vendor Data

SecUtils aggregates National Vulnerability Database (NVD) and MITRE records for avira by normalizing vendor identifiers across diverse data sources, mapping vendor names to their associated product lines, and collecting all known vulnerabilities under a unified vendor context. For every CVE associated with avira's products, we extract and structure Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) categories, CVSS severity metrics, and reference links to enable rapid vulnerability identification and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and vendor vulnerability tracking.