Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.4) | 0.32% | — | Quickheal Total Security | 30/11/2020 | 17/6/2026 | Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify sensitive anti virus settings via a brute-attack on the settings password. | |
| En análisis | Alta (7.8) | 0.61% | — | 360totalsecurity 360 Total Security | 21/7/2020 | 17/6/2026 | In the version 12.1.0.1005 and below of 360 Total Security, when the Gamefolde calls GameChrome.exe, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking to bypass the hips could execute arbitrary code on the Local system. | |
| En análisis | Alta (7.8) | 0.48% | — | 360totalsecurity 360 Total Security | 21/7/2020 | 17/6/2026 | In the version 12.1.0.1004 and below of 360 Total Security, when the main process of 360 Total Security calls GameChrome.exe, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking to bypass the hips could execute arbitrary code on the Local system. | |
| En análisis | Alta (7.8) | 0.43% | — | 360totalsecurity 360 Total Security | 21/7/2020 | 17/6/2026 | In version 12.1.0.1004 and below of 360 Total Security,when TPI calls the browser process, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking could execute arbitrary code on the Local system. | |
| Modificada | Alta (8.8) | 1.1% | — | Bitdefender Total Security 2020 | 22/6/2020 | 17/6/2026 | Improper Input Validation vulnerability in the Safepay browser component of Bitdefender Total Security 2020 allows an external, specially crafted web page to run remote commands inside the Safepay Utility process. This issue affects Bitdefender Total Security 2020 versions prior to 24.0.20.116. | |
| Modificada | Alta (7.8) | 1.5% | — | Quickheal Antivirus FOR ServerQuickheal Antivirus PROQuickheal Home SecurityQuickheal Internet Security+2 | 24/2/2020 | 17/6/2026 | The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive. This affects Total Security, Home Security, Total Security Multi-Device, Internet Security, Total Security for Mac, AntiVirus Pro, AntiVirus for Server, and Total Security for Android. | |
| Modificada | Media (5.5) | 0.47% | — | Bitdefender Total Security 2020 | 30/1/2020 | 17/6/2026 | A vulnerability in the improper handling of junctions before deletion in Bitdefender Total Security 2020 can allow an attacker to to trigger a denial of service on the affected device. | |
| Modificada | Media (6.5) | 0.34% | — | Bitdefender Total Security 2020 | 27/1/2020 | 17/6/2026 | An Untrusted Search Path vulnerability in bdserviceshost.exe as used in Bitdefender Total Security 2020 allows an attacker to execute arbitrary code. This issue does not affect: Bitdefender Total Security versions prior to 24.0.12.69. | |
| Modificada | Media (6.7) | 0.77% | — | Kaspersky Internet SecurityKaspersky Secure ConnectionKaspersky Security CloudKaspersky Total Security | 2/12/2019 | 17/6/2026 | Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud prior to version 2020 patch E have bug that allows a local user to execute arbitrary code via execution compromised file placed by an attacker with administrator rights. No privilege escalation. Possible… | |
| Modificada | Media (6.1) | 2.1% | — | Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+1 | 26/11/2019 | 17/6/2026 | Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component did not adequately inform the user about the threat of redirecting to an untrusted site. Bypass. | |
| Modificada | Media (6.5) | 1.6% | — | Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+1 | 26/11/2019 | 17/6/2026 | Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component was vulnerable to remote disclosure of various information about the user's system (like Windows version and version… | |
| Modificada | Media (4.3) | 0.77% | — | Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+1 | 26/11/2019 | 17/6/2026 | Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attacker remotely disable various anti-virus protection features. DoS, Bypass. | |
| Modificada | Media (4.3) | 0.84% | — | Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+1 | 26/11/2019 | 17/6/2026 | Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attacker remotely disable such product's security features as private browsing and anti-banner. Bypass. | |
| Modificada | Crítica (9.8) | 1.6% | — | K7computing K7 Antivirus PremiumK7computing K7 Total SecurityK7computing K7 Ultimate Security | 28/10/2019 | 17/6/2026 | In K7 Antivirus Premium 16.0.xxx through 16.0.0120; K7 Total Security 16.0.xxx through 16.0.0120; and K7 Ultimate Security 16.0.xxx through 16.0.0120, the module K7TSHlpr.dll improperly validates the administrative privileges of the user, allowing arbitrary registry writes in the K7AVOptn.dll module to facilitate… | |
| Modificada | Media (5.3) | 1.1% | — | Fabrix Total Security | 21/8/2019 | 17/6/2026 | The total-security plugin before 3.4.1 for WordPress has a settings-change vulnerability. | |
| Modificada | Media (6.1) | 0.91% | — | Fabrix Total Security | 21/8/2019 | 17/6/2026 | The total-security plugin before 3.4.1 for WordPress has XSS. | |
| Modificada | Media (6.7) | 0.57% | — | Bitdefender Antivirus PlusBitdefender Endpoint Security ToolBitdefender Internet SecurityBitdefender Total Security | 30/7/2019 | 17/6/2026 | An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions prior to 6.6.8.115; and Bitdefender Antivirus Plus, Bitdefender Internet Security, and Bitdefender Total Security versions prior to 23.0.24.120) that can lead to local code injection. A local attacker with… | |
| Modificada | Media (4.3) | 2.2% | — | Kaspersky Anti-virusKaspersky Free Anti-virusKaspersky Internet SecurityKaspersky Small Office Security+1 | 18/7/2019 | 17/6/2026 | Information Disclosure in Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security versions up to 2019 could potentially disclose unique Product ID by forcing victim to visit a specially crafted webpage (for example, via clicking phishing link). Vulnerability has CVSS v3.0 base score 2.6 | |
| Modificada | Alta (7.5) | 1.4% | — | Gdata-software Total Security | 13/3/2019 | 17/6/2026 | gdwfpcd.sys in G Data Total Security before 2019-02-22 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEVICE_SECURE_OPEN and therefore files and directories "inside" the \\.\gdwfpcd device are not properly protected, leading to unintended impersonation or object creation. | |
| Modificada | Media (6.3) | 0.89% | — | 360totalsecurity 360 Total Security | 23/10/2018 | 17/6/2026 | 360 Total Security 3.5.0.1033 allows a Sandbox Escape via an "import os" statement, followed by os.system("CMD") or os.system("PowerShell"), within a .py file. NOTE: the vendor's position is that this cannot be categorized as a vulnerability, although it is a security-related issue | |
| Modificada | Alta (7.8) | 1.2% | — | Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security | 25/7/2018 | 17/6/2026 | Quick Heal Total Security 64 bit 17.00 (QHTS64.exe), (QHTSFT64.exe) - Version 10.0.1.38; Quick Heal Total Security 32 bit 17.00 (QHTS32.exe), (QHTSFT32.exe) - Version 10.0.1.38; Quick Heal Internet Security 64 bit 17.00 (QHIS64.exe), (QHISFT64.exe) - Version 10.0.0.37; Quick Heal Internet Security 32 bit 17.00… | |
| Modificada | Alta (8.8) | 6.2% | — | Gdata-software Total Security | 13/7/2018 | 17/6/2026 | The GDASPAMLib.AntiSpam ActiveX control ASK\GDASpam.dll in G DATA Total Security 25.4.0.3 has a buffer overflow via a long IsBlackListed argument. | |
| Modificada | Alta (7.8) | 0.29% | — | Bitdefender Total Security | 12/3/2018 | 17/6/2026 | BitDefender Total Security 2018 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of an "insecurely created named pipe". Ensures full access to Everyone users group. | |
| Modificada | Media (5.5) | 0.29% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | In K7 Antivirus Premium before 15.1.0.53, user-controlled input to the K7Sentry device is not sufficiently authenticated: a local user with a LOW integrity process can access a raw hard disk by sending a specific IOCTL. | |
| Modificada | Alta (7) | 0.27% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | K7 Antivirus Premium before 15.1.0.53 allows local users to gain privileges by sending a specific IOCTL after setting the memory in a particular way. |