Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

363 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)2.3%💥 ExploitBoldgrid W3 Total Cache14/1/202517/6/2026
The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it possible for unauthenticated attackers to view potentially sensitive information in the exposed log file. For example, the log file may…
AnalizadaMedia (5.3)0.51%—Boldgrid W3 Total Cache14/1/202517/6/2026
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to deactivate the plugin as well as activate and deactivate plugin…
AplazadaMedia (4.3)0.17%—Epsiloncool WP Fast Total SearchAI2/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search fulltext-search.This issue affects WP Fast Total Search: from n/a through <= 1.69.234.
AplazadaCrítica (9.8)1.9%💥 PoCSaiful.total Wp-nssuser-registerAI16/12/202417/6/2026
Incorrect Privilege Assignment vulnerability in saiful.total Wp NssUser Register wp-nssuser-register allows Privilege Escalation.This issue affects Wp NssUser Register: from n/a through <= 1.0.0.
AplazadaCrítica (9.3)1.5%—Siemens Opcenter Execution FoundationAISiemens Opcenter IntelligenceAISiemens Opcenter QualityAISiemens Opcenter RdnlAI+316/12/202417/6/2026
A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2501.0001), Opcenter Intelligence (All versions < V2501.0001), Opcenter Quality (All versions < V2512), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3),…
AplazadaAlta (7.5)0.83%—Total-soft Portfolio Gallery Responsive Image GalleryAI13/12/202417/6/2026
Missing Authorization vulnerability in Total-Soft Portfolio Gallery – Responsive Image Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Portfolio Gallery – Responsive Image Gallery: from n/a through 1.4.6.
AplazadaMedia (4.3)0.47%—Hashthemes TotalAI13/12/202417/6/2026
Missing Authorization vulnerability in HashThemes Total allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Total: from n/a through 2.1.19.
AplazadaAlta (7.5)0.84%—Total-soft Video Gallery Youtube GalleryAI13/12/202417/6/2026
Missing Authorization vulnerability in Video Gallery by Total-Soft Video Gallery – YouTube Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Video Gallery – YouTube Gallery: from n/a through 1.7.6.
AplazadaMedia (6.3)0.40%—Totalsuite Total Poll LiteAI9/12/202417/6/2026
Missing Authorization vulnerability in TotalSuite Total Poll Lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Total Poll Lite: from n/a through 4.8.6.
AplazadaMedia (5.3)0.53%—Tungstenautomation TotalagilityAI6/12/202417/6/2026
Tungsten Automation (Kofax) TotalAgility in versions all through 7.9.0.25.0.954 is vulnerable to a Reflected XSS attacks through mfpScreenResolutionWidth parameter manipulation in a form sent to an endpoint /TotalAgility/Kofax/BrowserDevice/ScanFront.aspx This allows for injection of a malicious JavaScript code,…
AplazadaMedia (5.3)0.53%—Kofax TotalagilityAITungstenautomation TotalagilityAI6/12/202417/6/2026
Tungsten Automation (Kofax) TotalAgility in versions all through 7.9.0.25.0.954 is vulnerable to a Reflected XSS attacks through mfpConnectionId parameter manipulation in a form sent to endpoints "/TotalAgility/Kofax/BrowserDevice/ScanFront.aspx" and "/TotalAgility/Kofax/BrowserDevice/ScanFrontDebug.aspx" This allows…
AnalizadaMedia (4.8)0.31%—Total-soft Video Gallery6/12/202417/6/2026
The Video Gallery – Best WordPress YouTube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
AnalizadaMedia (4.9)0.53%—Total-soft Video Gallery6/12/202417/6/2026
The Video Gallery – Best WordPress YouTube Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the orderby parameter in all versions up to, and including, 2.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
AnalizadaAlta (7.2)1.0%—Boldgrid Total Upkeep26/11/202417/6/2026
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.6 via the cron_interval parameter. This is due to missing input validation and sanitization. This makes it possible for authenticated…
AnalizadaAlta (7.8)0.38%—F-secure Total22/11/202417/6/2026
F-Secure Total Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of F-Secure Total. User interaction on the part of an administrator is required to exploit this vulnerability. The specific flaw exists within the…
AnalizadaAlta (7.8)0.22%—Gdata-software Total Security22/11/202417/6/2026
G DATA Total Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…
AnalizadaAlta (7.8)0.40%—Gdata-software Total Security22/11/202417/6/2026
G DATA Total Security Scan Server Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…
AnalizadaAlta (7.8)0.40%—Gdata-software Total Security22/11/202417/6/2026
G DATA Total Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
AnalizadaAlta (7.8)0.40%—Gdata-software Total Security22/11/202417/6/2026
G DATA Total Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
AplazadaAlta (8.8)0.38%—Quickheal Antivirus PROAIQuickheal Total SecurityAI18/11/202417/6/2026
An issue in the wssrvc.exe service of QuickHeal Antivirus Pro Version v24.0 and Quick Heal Total Security v24.0 allows authenticated attackers to escalate privileges.
AplazadaMedia (6.7)0.20%—Mcafee Total ProtectionAI15/11/202417/6/2026
Trial installer for McAfee Total Protection (legacy trial installer software) 16.0.53 allows local privilege escalation because of an Uncontrolled Search Path Element. The attacker could be "an adversary or knowledgeable user" and the type of attack could be called "DLL-squatting." The issue only affects execution of…
AplazadaMedia (4.3)0.37%—Epsiloncool WP Fast Total SearchAI1/11/202417/6/2026
Missing Authorization vulnerability in Epsiloncool WP Fast Total Search fulltext-search.This issue affects WP Fast Total Search: from n/a through <= 1.68.232.
AnalizadaAlta (8.8)1.0%—Totaljs Total.js25/10/202417/6/2026
An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.
AnalizadaAlta (7.2)2.3%💥 ExploitTotal-soft TS Poll21/10/202417/6/2026
The TS Poll WordPress plugin before 2.4.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
AnalizadaAlta (8.6)0.21%—Bitdefender Total Security18/10/202417/6/2026
A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software trusts a certificate issued by an entity that isn't authorized to issue certificates. This occurs when the "Basic Constraints" extension in the certificate indicates that it is meant to be an "End Entity”.…
Orbitaley — Vulnerabilidades