Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
363 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.47% | — | Bitdefender Total Security 2020 | 30/1/2020 | 17/6/2026 | A vulnerability in the improper handling of junctions before deletion in Bitdefender Total Security 2020 can allow an attacker to to trigger a denial of service on the affected device. | |
| Modificada | Media (6.5) | 0.34% | — | Bitdefender Total Security 2020 | 27/1/2020 | 17/6/2026 | An Untrusted Search Path vulnerability in bdserviceshost.exe as used in Bitdefender Total Security 2020 allows an attacker to execute arbitrary code. This issue does not affect: Bitdefender Total Security versions prior to 24.0.12.69. | |
| Modificada | Alta (7.8) | 0.43% | — | Siemens Totally Integrated Automation Portal | 16/1/2020 | 17/6/2026 | A vulnerability has been identified in TIA Portal V14 (All versions), TIA Portal V15 (All versions < V15.1 Update 7), TIA Portal V16 (All versions < V16 Update 6), TIA Portal V17 (All versions < V17 Update 4). Changing the contents of a configuration file could allow an attacker to execute arbitrary code with SYSTEM… | |
| Modificada | Alta (7.8) | 2.2% | 💥 Exploit | Totalav 2020 | 10/1/2020 | 17/6/2026 | TotalAV 2020 4.14.31 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junction to restore a malicious DLL from quarantine into the system32 folder. | |
| Modificada | Alta (7.8) | 1.5% | — | Virustotal YaraFedoraproject Fedora | 9/12/2019 | 17/6/2026 | In the macho_parse_file functionality in macho/macho.c of YARA 3.11.0, command_size may be inconsistent with the real size. A specially crafted MachO file can cause an out-of-bounds memory access, resulting in Denial of Service (application crash) or potential code execution. | |
| Modificada | Media (6.7) | 0.77% | — | Kaspersky Internet SecurityKaspersky Secure ConnectionKaspersky Security CloudKaspersky Total Security | 2/12/2019 | 17/6/2026 | Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud prior to version 2020 patch E have bug that allows a local user to execute arbitrary code via execution compromised file placed by an attacker with administrator rights. No privilege escalation. Possible… | |
| Modificada | Media (6.1) | 2.1% | — | Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+1 | 26/11/2019 | 17/6/2026 | Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component did not adequately inform the user about the threat of redirecting to an untrusted site. Bypass. | |
| Modificada | Media (6.5) | 1.6% | — | Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+1 | 26/11/2019 | 17/6/2026 | Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component was vulnerable to remote disclosure of various information about the user's system (like Windows version and version… | |
| Modificada | Media (4.3) | 0.77% | — | Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+1 | 26/11/2019 | 17/6/2026 | Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attacker remotely disable various anti-virus protection features. DoS, Bypass. | |
| Modificada | Media (4.3) | 0.84% | — | Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+1 | 26/11/2019 | 17/6/2026 | Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attacker remotely disable such product's security features as private browsing and anti-banner. Bypass. | |
| Modificada | Alta (7.5) | 2.1% | — | Boldgrid W3 Total Cache | 22/11/2019 | 16/6/2026 | W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via their hash keys. | |
| Modificada | Alta (7.5) | 2.3% | — | Boldgrid W3 Total Cache | 22/11/2019 | 16/6/2026 | W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes. | |
| Modificada | Alta (7.5) | 5.4% | — | Boldgrid W3 Total Cache | 22/11/2019 | 16/6/2026 | W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files. | |
| Modificada | Media (6.7) | 0.66% | — | Mcafee Anti-virus PlusMcafee Internet SecurityMcafee Total Protection | 13/11/2019 | 17/6/2026 | A Privilege Escalation vulnerability in the Microsoft Windows client in McAfee Total Protection 16.0.R22 and earlier allows administrators to execute arbitrary code via carefully placing malicious files in specific locations protected by administrator permission. | |
| Modificada | Media (5.5) | 0.38% | — | Totaldefense Anti-virus | 31/10/2019 | 17/6/2026 | The quarantine restoration function in Total Defense Anti-virus 11.5.2.28 is vulnerable to symbolic link attacks, allowing files to be written to privileged directories. | |
| Modificada | Media (5.9) | 0.56% | — | Totaldefense Anti-virus | 31/10/2019 | 17/6/2026 | The malware scan function in Total Defense Anti-virus 11.5.2.28 is vulnerable to a TOCTOU bug; consequently, symbolic link attacks allow privileged files to be deleted. | |
| Modificada | Alta (7.8) | 0.22% | — | Mcafee Total Protection | 28/10/2019 | 17/6/2026 | A File Masquerade vulnerability in McAfee Total Protection (MTP) version 16.0.R21 and earlier in Windows client allowed an attacker to read the plaintext list of AV-Scan exclusion files from the Windows registry, and to possibly replace excluded files with potential malware without being detected. | |
| Modificada | Crítica (9.8) | 1.6% | — | K7computing K7 Antivirus PremiumK7computing K7 Total SecurityK7computing K7 Ultimate Security | 28/10/2019 | 17/6/2026 | In K7 Antivirus Premium 16.0.xxx through 16.0.0120; K7 Total Security 16.0.xxx through 16.0.0120; and K7 Ultimate Security 16.0.xxx through 16.0.0120, the module K7TSHlpr.dll improperly validates the administrative privileges of the user, allowing arbitrary registry writes in the K7AVOptn.dll module to facilitate… | |
| Modificada | Alta (7.8) | 0.59% | — | Totaldefense Anti-virus | 24/9/2019 | 17/6/2026 | In Total Defense Anti-virus 9.0.0.773, resource acquisition from the untrusted search path C:\ used by caschelp.exe allows local attackers to hijack ccGUIFrm.dll, which leads to code execution. SYSTEM-level code execution can be achieved when the ccSchedulerSVC service runs the affected executable. | |
| Modificada | Alta (7.8) | 0.38% | — | Totaldefense Anti-virus | 24/9/2019 | 17/6/2026 | In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS\9\bd\TDUpdate2\ used by AMRT.exe allows local attackers to hijack bdcore.dll, which leads to privilege escalation when the AMRT service loads the DLL. | |
| Modificada | Alta (7.8) | 0.36% | — | Totaldefense Anti-virus | 24/9/2019 | 17/6/2026 | In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS\9\ used by ccschedulersvc.exe allows local attackers to hijack dotnetproxy.exe, which leads to privilege escalation when the ccSchedulerSVC service runs the executable. | |
| Modificada | Media (6.5) | 1.5% | — | Mcafee Total Protection | 13/9/2019 | 17/6/2026 | DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Free Antivirus Trial 16.0.R18 and earlier allows local users to execute arbitrary code via execution from a compromised folder placed by an attacker with administrator rights. | |
| Modificada | Media (6.5) | 0.87% | — | Totaljs Total.js CMS | 5/9/2019 | 17/6/2026 | An issue was discovered in Total.js CMS 12.0.0. A low privilege user can perform a simple transformation of a cookie to obtain the random values inside it. If an attacker can discover a session cookie owned by an admin, then it is possible to brute force it with O(n)=2n instead of O(n)=n^x complexity, and steal the… | |
| Modificada | Crítica (9.9) | 79% | 💥 Exploit | Totaljs Total.js CMS | 5/9/2019 | 17/6/2026 | An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag containing JavaScript code that will be evaluated server side. In the process of evaluating the tag by… | |
| Modificada | Alta (8.8) | 1.5% | — | Totaljs Total.js CMS | 5/9/2019 | 17/6/2026 | An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resource that they do not own by calling the associated API. The product correctly manages privileges only for the front-end resource path, not for API requests. This leads to vertical and horizontal… |