Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
363 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 5.1% | — | Totaljs Total.js CMS | 5/9/2019 | 17/6/2026 | An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the Pages privilege can conduct a path traversal attack (../) to include .html files that are outside the permitted directory. Also, if a page contains a template directive, then the directive will be server side processed. Thus, if a user can… | |
| Modificada | Media (5.3) | 1.1% | — | Fabrix Total Security | 21/8/2019 | 17/6/2026 | The total-security plugin before 3.4.1 for WordPress has a settings-change vulnerability. | |
| Modificada | Media (6.1) | 0.91% | — | Fabrix Total Security | 21/8/2019 | 17/6/2026 | The total-security plugin before 3.4.1 for WordPress has XSS. | |
| Modificada | Media (5.5) | 1.1% | — | Virustotal Yara | 31/7/2019 | 17/6/2026 | An exploitable denial of service vulnerability exists in the object lookup functionality of Yara 3.8.1. A specially crafted binary file can cause a negative value to be read to satisfy an assert, resulting in Denial of Service. An attacker can create a malicious binary to trigger this vulnerability. | |
| Modificada | Media (6.7) | 0.57% | — | Bitdefender Antivirus PlusBitdefender Endpoint Security ToolBitdefender Internet SecurityBitdefender Total Security | 30/7/2019 | 17/6/2026 | An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions prior to 6.6.8.115; and Bitdefender Antivirus Plus, Bitdefender Internet Security, and Bitdefender Total Security versions prior to 23.0.24.120) that can lead to local code injection. A local attacker with… | |
| Modificada | Media (4.3) | 2.2% | — | Kaspersky Anti-virusKaspersky Free Anti-virusKaspersky Internet SecurityKaspersky Small Office Security+1 | 18/7/2019 | 17/6/2026 | Information Disclosure in Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security versions up to 2019 could potentially disclose unique Product ID by forcing victim to visit a specially crafted webpage (for example, via clicking phishing link). Vulnerability has CVSS v3.0 base score 2.6 | |
| Modificada | Alta (7.5) | 19% | 💥 Exploit | Boldgrid W3 Total Cache | 1/4/2019 | 17/6/2026 | pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data. | |
| Modificada | Media (6.1) | 0.91% | — | Totaljs Total.js CMS | 28/3/2019 | 17/6/2026 | Total.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (column.format). | |
| Modificada | Alta (7.5) | 1.4% | — | Gdata-software Total Security | 13/3/2019 | 17/6/2026 | gdwfpcd.sys in G Data Total Security before 2019-02-22 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEVICE_SECURE_OPEN and therefore files and directories "inside" the \\.\gdwfpcd device are not properly protected, leading to unintended impersonation or object creation. | |
| Modificada | Alta (7.5) | 72% | 💥 Exploit | Totaljs Total.js | 18/2/2019 | 17/6/2026 | index.js in Total.js Platform before 3.2.3 allows path traversal. | |
| Modificada | Alta (7.1) | 0.35% | — | Mcafee Total Protection | 28/1/2019 | 17/6/2026 | Exploitation of Privilege/Trust vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.R18 allows local users to bypass product self-protection, tamper with policies and product files, and uninstall McAfee software without permission via specially crafted malware. | |
| Modificada | Crítica (9.8) | 26% | 💥 Exploit | Calmar-webmedia Total Donations | 27/1/2019 | 17/6/2026 | Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated attackers to update arbitrary WordPress option values, leading to site takeover. These attackers can send requests to wp-admin/admin-ajax.php to call the… | |
| Modificada | Media (6.5) | 1.4% | — | Mcafee Total Protection | 23/1/2019 | 17/6/2026 | DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.18 allows local users to execute arbitrary code via execution from a compromised folder. | |
| Modificada | Media (5.5) | 1.3% | — | Virustotal Yara | 17/12/2018 | 17/6/2026 | In YARA 3.8.1, bytecode in a specially crafted compiled rule is exposed to information about its environment, in libyara/exec.c. This is a consequence of the design of the YARA virtual machine. | |
| Modificada | Media (5.5) | 1.4% | — | Virustotal Yara | 17/12/2018 | 17/6/2026 | In YARA 3.8.1, bytecode in a specially crafted compiled rule can read data from any arbitrary address in memory, in libyara/exec.c. Specifically, OP_COUNT can read a DWORD. | |
| Modificada | Media (5.5) | 1.3% | — | Virustotal Yara | 17/12/2018 | 17/6/2026 | In YARA 3.8.1, bytecode in a specially crafted compiled rule can read uninitialized data from VM scratch memory in libyara/exec.c. This can allow attackers to discover addresses in the real stack (not the YARA virtual stack). | |
| Modificada | Media (6.3) | 0.89% | — | 360totalsecurity 360 Total Security | 23/10/2018 | 17/6/2026 | 360 Total Security 3.5.0.1033 allows a Sandbox Escape via an "import os" statement, followed by os.system("CMD") or os.system("PowerShell"), within a .py file. NOTE: the vendor's position is that this cannot be categorized as a vulnerability, although it is a security-related issue | |
| Modificada | Alta (7.8) | 1.2% | 💥 PoC | Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security | 25/7/2018 | 17/6/2026 | Quick Heal Total Security 64 bit 17.00 (QHTS64.exe), (QHTSFT64.exe) - Version 10.0.1.38; Quick Heal Total Security 32 bit 17.00 (QHTS32.exe), (QHTSFT32.exe) - Version 10.0.1.38; Quick Heal Internet Security 64 bit 17.00 (QHIS64.exe), (QHISFT64.exe) - Version 10.0.0.37; Quick Heal Internet Security 32 bit 17.00… | |
| Modificada | Alta (7.8) | 0.28% | — | Totalav | 13/7/2018 | 17/6/2026 | An issue was discovered in TotalAV v4.1.7. An unprivileged user could modify or overwrite all of the product's files because of weak permissions (Everyone:F) under %PROGRAMFILES%, which allows local users to gain privileges or obtain maximum control over the product. | |
| Modificada | Alta (8.8) | 6.2% | 💥 Exploit | Gdata-software Total Security | 13/7/2018 | 17/6/2026 | The GDASPAMLib.AntiSpam ActiveX control ASK\GDASpam.dll in G DATA Total Security 25.4.0.3 has a buffer overflow via a long IsBlackListed argument. | |
| Modificada | Alta (7.5) | 0.99% | — | Bitotal | 4/7/2018 | 17/6/2026 | Bitotal (TFUND) is a smart contract running on Ethereum. The mintTokens function has an integer overflow that allows minted tokens to be arbitrarily retrieved by the contract owner. | |
| Modificada | Alta (7.8) | 1.3% | — | Virustotal Yara | 15/6/2018 | 17/6/2026 | In YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds write vulnerability in yr_execute_code in libyara/exec.c. | |
| Modificada | Alta (7.8) | 1.3% | — | Virustotal Yara | 15/6/2018 | 17/6/2026 | In YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds read vulnerability in yr_execute_code in libyara/exec.c. | |
| Modificada | Alta (7.8) | 0.86% | — | Virustotal | 13/6/2018 | 17/6/2026 | An issue was discovered in VirusTotal. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the malicious unsigned code will execute. | |
| Modificada | Media (4.4) | 0.53% | — | Mcafee Anti-virus PlusMcafee Endpoint SecurityMcafee Host Intrusion PreventionMcafee Internet Security+2 | 3/4/2018 | 17/6/2026 | Maliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee process via manipulation of registry parameters. |