Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

363 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.3%—Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security4/5/201717/6/2026
Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Out of Bounds Write on a Heap Buffer due to improper validation of dwCompressionSize of Microsoft WIM Header WIMHEADER_V1_PACKED. This vulnerability can be exploited to gain Remote…
ModificadaAlta (7.5)3.1%—Virustotal Yara27/4/201717/6/2026
libyara/re.c in the regex component in YARA 3.5.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted rule that is mishandled in the yr_re_exec function.
ModificadaAlta (7.5)5.5%💥 ExploitQuickheal Total Security20/4/201717/6/2026
The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service.
ModificadaAlta (7.5)1.6%—Virustotal Yara3/4/201717/6/2026
libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule that is mishandled in the yr_compiler_destroy function.
ModificadaAlta (7.5)1.6%—Virustotal Yara3/4/201717/6/2026
libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted rule that is mishandled in the yara_yyparse function.
ModificadaAlta (7.5)1.6%—Virustotal Yara3/4/201717/6/2026
libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule that is mishandled in the yr_parser_lookup_loop_variable function.
ModificadaAlta (7.5)2.9%—Virustotal Yara3/4/201717/6/2026
libyara/lexer.l in YARA 3.5.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted rule that is mishandled in the yy_get_next_buffer function.
ModificadaMedia (6.7)0.94%—Avira Free Security SuiteAvira Internet Security SuiteAvira Optimization SuiteAvira Total Security Suite21/3/201717/6/2026
Code injection vulnerability in Avira Total Security Suite 15.0 (and earlier), Optimization Suite 15.0 (and earlier), Internet Security Suite 15.0 (and earlier), and Free Security Suite 15.0 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any…
ModificadaMedia (6.7)0.75%—Bitdefender Antivirus PlusBitdefender Internet SecurityBitdefender Total Security21/3/201717/6/2026
Code injection vulnerability in Bitdefender Total Security 12.0 (and earlier), Internet Security 12.0 (and earlier), and Antivirus Plus 12.0 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any Bitdefender process via a "DoubleAgent" attack.…
ModificadaMedia (5.5)0.57%—Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Total Security6/1/201717/6/2026
A local denial of service vulnerability exists in window broadcast message handling functionality of Kaspersky Anti-Virus software. Sending certain unhandled window messages, an attacker can cause application termination and in the same way bypass KAV self-protection mechanism.
ModificadaMedia (5.5)0.66%—Kaspersky Total Security6/1/201717/6/2026
Multiple information leaks exist in various IOCTL handlers of the Kaspersky Internet Security KLDISK driver. Specially crafted IOCTL requests can cause the driver to return out-of-bounds kernel memory, potentially leaking sensitive information such as privileged tokens or kernel memory addresses that may be useful in…
ModificadaCrítica (9.8)9.7%💥 PoCQuickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security2/1/201717/6/2026
Stack-based buffer overflow in Quick Heal Internet Security 10.1.0.316 and earlier, Total Security 10.1.0.316 and earlier, and AntiVirus Pro 10.1.0.316 and earlier on OS X allows remote attackers to execute arbitrary code via a crafted LC_UNIXTHREAD.cmdsize field in a Mach-O file that is mishandled during a Security…
ModificadaMedia (6.4)1.5%—Kaspersky Total Security 201516/12/201517/6/2026
Kaspersky Total Security 2015 15.0.2.361 allocates memory with Read, Write, Execute (RWX) permissions at predictable addresses when protecting user-mode processes, which allows attackers to bypass the DEP and ASLR protection mechanisms via unspecified vectors.
ModificadaMedia (5)2.9%—Dell Sonicwall Totalsecure TZ 100 Firmware6/11/201517/6/2026
Dell SonicWall TotalSecure TZ 100 devices with firmware before 5.9.1.0-22o allow remote attackers to cause a denial of service via a crafted packet.
ModificadaMedia (5)3.7%—Ghisler Total Commander21/7/201517/6/2026
The FileInfo plugin before 2.22 for Ghisler Total Commander allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via (1) a large Size value in the Archive Member Header of a COFF Archive Library file, (2) a large Number Of Symbols value in the 1st Linker Member of a COFF…
ModificadaAlta (7.2)1.0%💥 ExploitK7computing K7sentry.sysK7computing Anti-virus PlusK7computing Total SecurityK7computing Ultimate Security6/2/201517/6/2026
K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x95002570, 0x95002574, 0x95002580, 0x950025a8, 0x950025ac, or 0x950025c8 IOCTL call.
ModificadaMedia (6.8)1.4%—Boldgrid W3 Total Cache24/12/201417/6/2026
The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and hijack the authentication of administrators for requests that change the mobile site redirect URI via the mobile_groups[*][redirect]…
ModificadaMedia (4.3)2.1%—Boldgrid W3 Total Cache19/12/201417/6/2026
Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin before 0.9.4.1 for WordPress, when debug mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the "Cache key" in the HTML-Comments, as demonstrated by the PATH_INFO to the default URI.
ModificadaMedia (6.9)0.40%—Snowfoxsoft Snowfox Total Video Converter7/9/201216/6/2026
Untrusted search path vulnerability in SnowFox Total Video Converter 2.5.1 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .avi file. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.2)0.30%—Mcafee Total Protection 201025/8/201216/6/2026
Race condition in McAfee Total Protection 2010 10.0.580 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler…
ModificadaMedia (6.2)0.32%—Gdata Totalcare 201025/8/201216/6/2026
Race condition in G DATA TotalCare 2010 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an…
ModificadaMedia (6.2)0.30%—Bitdefender Total Security 201025/8/201216/6/2026
Race condition in BitDefender Total Security 2010 13.0.20.347 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler…
ModificadaMedia (4.3)1.6%💥 ExploitTotalshopuk Ecommerce20/8/201216/6/2026
Cross-site scripting (XSS) vulnerability in the refresh_page function in application/modules/_main/views/_top.php in Total Shop UK eCommerce Open Source before 2.1.2_p1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
ModificadaAlta (10)16%—Broadcom Total DefenseCA Gateway Security28/7/201116/6/2026
Icihttp.exe in CA Gateway Security for HTTP, as used in CA Gateway Security 8.1 before 8.1.0.69 and CA Total Defense r12, does not properly parse URLs, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and daemon crash) via a malformed request.
ModificadaAlta (7.5)12%—Broadcom Total Defense18/4/201116/6/2026
The management.asmx module in the Management Web Service in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 sends a cleartext response to unspecified getDBConfigSettings requests, which makes it easier for remote attackers to obtain database credentials, and subsequently execute…