Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
363 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.54% | — | IBM Total Storage Service ConsoleIBM Ts4500 IMC | 23/4/2026 | 17/6/2026 | IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input. | |
| Aplazada | Media (6.5) | 0.25% | — | Totalsuite Total Poll LiteAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in TotalSuite Total Poll Lite totalpoll-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Total Poll Lite: from n/a through <= 4.12.0. | |
| Aplazada | Alta (7.5) | 2.7% | — | Boldgrid W3 Total CacheAI | 2/4/2026 | 17/6/2026 | The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.3. This is due to the plugin bypassing its entire output buffering and processing pipeline when the request's User-Agent header contains "W3 Total Cache", which causes raw mfunc/mclude dynamic… | |
| Aplazada | Crítica (9.9) | 0.52% | — | Totalsuite Total Poll LiteAI | 25/3/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in TotalSuite Total Poll Lite totalpoll-lite allows Remote Code Inclusion.This issue affects Total Poll Lite: from n/a through <= 4.12.0. | |
| Aplazada | Media (6.3) | 0.23% | — | Totalsuite Totalcontest LiteAI | 20/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in TotalSuite TotalContest Lite totalcontest-lite allows Object Injection.This issue affects TotalContest Lite: from n/a through <= 2.9.1. | |
| Aplazada | Crítica (9) | 0.45% | — | Boldgrid W3 Total CacheAI | 5/3/2026 | 17/6/2026 | Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects W3 Total Cache: from n/a through <= 2.9.1. | |
| Aplazada | Alta (7.1) | 0.19% | — | Totalbounty Widget Logic VisualAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in totalbounty Widget Logic Visual widget-logic-visual allows Reflected XSS.This issue affects Widget Logic Visual: from n/a through <= 1.52. | |
| Aplazada | Media (4.4) | 0.22% | — | Total-soft TS PollAI | 19/2/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in totalsoft TS Poll poll-wp allows Server Side Request Forgery.This issue affects TS Poll: from n/a through <= 2.5.5. | |
| Aplazada | Alta (7.3) | 0.17% | — | Total VPNAI | 16/2/2026 | 17/6/2026 | A weakness has been identified in Total VPN 0.5.29.0 on Windows. Affected by this vulnerability is an unknown functionality of the file C:\Program Files\Total VPN\win-service.exe. Executing a manipulation can lead to unquoted search path. It is possible to launch the attack on the local host. This attack is… | |
| Analizada | Alta (7.8) | 0.12% | — | Quickheal Total Security | 3/2/2026 | 17/6/2026 | A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and improper permission handling allow a low-privileged local user to restore quarantined files into protected system directories. This behavior can be abused by a local… | |
| Analizada | Alta (8.5) | 0.26% | — | Totalav | 15/1/2026 | 6/10/2026 | TotalAV 5.15.69 contains an unquoted service path vulnerability in multiple system services running with LocalSystem privileges. Attackers can place malicious executables in specific unquoted path segments to potentially gain SYSTEM-level access by exploiting the service path configuration. | |
| Aplazada | Media (4.3) | 0.22% | — | Total-soft TS PollAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in totalsoft TS Poll poll-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TS Poll: from n/a through <= 2.5.5. | |
| Modificada | Alta (8.5) | 0.25% | — | Zillya Total Security | 22/12/2025 | 17/6/2026 | Zillya Total Security 3.0.2367.0 contains a privilege escalation vulnerability that allows low-privileged users to copy files to unauthorized system locations using the quarantine module. Attackers can leverage symbolic link techniques to restore quarantined files to restricted directories, potentially enabling… | |
| Analizada | Alta (8.8) | 0.17% | — | Bitdefender AntivirusBitdefender Antivirus PlusBitdefender Endpoint Security ToolsBitdefender Internet Security+1 | 10/12/2025 | 17/6/2026 | A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting files from a user-writable directory (C:\ProgramData\Atc\Feedback) without proper symbolic link validation,… | |
| Aplazada | Crítica (9) | 23% | — | Boldgrid W3 Total CacheAI | 17/11/2025 | 17/6/2026 | The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post. | |
| Aplazada | Media (5.4) | 0.20% | — | Total Book ProjectAI | 11/11/2025 | 17/6/2026 | The The Total Book Project plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0 via several functions due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform… | |
| Analizada | Alta (7.1) | 0.38% | — | Tesigandia Gandia Integra Total | 23/10/2025 | 30/9/2026 | Path Traversal vulnerability in version 4.4.2236.1 of TESI Gandia Integra Total. This issue allows an authenticated attacker to download a ZIP file containing files from the server, including those located in parent directories (e.g., ..\..\..), by exploiting the “direstudio” parameter in… | |
| Aplazada | Baja (2) | 0.28% | — | Totaljs FlowAI | 13/10/2025 | 17/6/2026 | A security flaw has been discovered in Total.js Flow up to 673ef9144dd25d4f4fd4fdfda5af27f230198924. The impacted element is an unknown function of the component SVG File Handler. Performing manipulation results in unrestricted upload. The attack can be initiated remotely. The exploit has been released to the public… | |
| Analizada | Baja (1.9) | 0.24% | — | Totaljs Total.js | 26/9/2025 | 17/6/2026 | A vulnerability has been found in Total.js CMS up to 19.9.0. This impacts an unknown function of the component Files Menu. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (1.9) | 0.26% | — | Totaljs Total.js | 25/9/2025 | 30/9/2026 | A vulnerability was found in Total.js CMS 1.0.0. Affected by this vulnerability is the function layouts_save of the file /admin/ of the component Layout Page. Performing manipulation of the argument HTML results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public… | |
| Aplazada | Media (4.3) | 0.14% | — | Epsiloncool WP Fast Total SearchAI | 22/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search fulltext-search allows Cross Site Request Forgery.This issue affects WP Fast Total Search: from n/a through <= 1.79.270. | |
| Analizada | Baja (1.3) | 0.48% | — | Totalwebshield Total Webshield | 9/8/2025 | 17/6/2026 | A vulnerability was found in Protected Total WebShield Extension up to 3.2.0 on Chrome. It has been classified as problematic. This affects an unknown part of the component Block Page. The manipulation of the argument Category leads to cross site scripting. It is possible to initiate the attack remotely. The… | |
| Analizada | Alta (8.7) | 0.59% | — | Tesigandia Gandia Integra Total | 1/8/2025 | 17/6/2026 | A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in… | |
| Analizada | Alta (8.7) | 1.1% | — | Tesigandia Gandia Integra Total | 1/8/2025 | 17/6/2026 | A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in… | |
| Analizada | Alta (8.7) | 0.59% | — | Tesigandia Gandia Integra Total | 1/8/2025 | 17/6/2026 | A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in… |