Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
363 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.94% | — | Siemens Opcenter QualitySiemens Simatic PCS NEOSiemens Sinumerik Integrate Runmyhmi /automotiveSiemens Totally Integrated Automation Portal | 12/12/2023 | 17/6/2026 | A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal… | |
| Modificada | Crítica (9.8) | 0.55% | — | Total-soft Video Gallery | 6/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Video Gallery by Total-Soft Video Gallery – Best WordPress YouTube Gallery Plugin allows SQL Injection.This issue affects Video Gallery – Best WordPress YouTube Gallery Plugin: from n/a through 2.1.3. | |
| Modificada | Media (4.8) | 0.32% | — | Totalpress Custom Post Types | 26/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in TotalPress.Org Custom post types, Custom Fields & more plugin <= 4.0.12 versions. | |
| Modificada | Alta (8.8) | 1.1% | — | Virustotal Yara | 28/8/2023 | 17/6/2026 | Buffer Overflow vulnerability in VirusTotal yara v.4.3.2 allows a remote attacker to execute arbtirary code via the yr_execute_cod function in the exe.c component. | |
| Modificada | Alta (8.8) | 26% | — | Totalcms Total CMS | 3/8/2023 | 17/6/2026 | File Upload vulnerability in Total CMS v.1.7.4 allows a remote attacker to execute arbitrary code via a crafted PHP file to the edit page function. | |
| Modificada | Media (5.5) | 0.12% | — | Siemens Totally Integrated Automation Portal | 13/6/2023 | 17/6/2026 | A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All… | |
| Modificada | Alta (7.8) | 0.19% | — | Bitdefender Antivirus PlusBitdefender Internet SecurityBitdefender Total Security | 24/5/2023 | 17/6/2026 | Unquoted Search Path or Element vulnerability in the Vulnerability Scan component of Bitdefender Total Security, Bitdefender Internet Security, and Bitdefender Antivirus Plus allows an attacker to elevate privileges to SYSTEM. This issue affects: Bitdefender Total Security versions prior to 26.0.10.45. Bitdefender… | |
| Modificada | Media (5.4) | 0.67% | — | Totaljs Messenger | 4/5/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the private task field. | |
| Modificada | Media (5.4) | 0.67% | — | Totaljs Messenger | 4/5/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the user information field. | |
| Modificada | Media (5.4) | 0.67% | — | Totaljs Messenger | 4/5/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the channel description field. | |
| Modificada | Media (5.4) | 0.67% | — | Totaljs Flow | 4/5/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the platform name field in the settings module. | |
| Modificada | Media (4.8) | 0.37% | — | Total-soft Video Gallery | 3/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Video Gallery by Total-Soft Video Gallery plugin <= 1.7.6 versions. | |
| Modificada | Alta (7.8) | 0.42% | — | 360 Total Security | 19/4/2023 | 17/6/2026 | Qihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Total Security (http://www.360totalsecurity.com/) is affected by: Buffer Overflow. The impact is: execute arbitrary code (local). The component is: This is a set of vulnerabilities affecting popular software, "360… | |
| Modificada | Alta (8.8) | 1.0% | — | 360 Total Security | 19/4/2023 | 17/6/2026 | Qihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Chrome (https://browser.360.cn/ee/) is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: This is a set of vulnerabilities affecting popular software, and the installation packages… | |
| Modificada | Alta (7.8) | 0.40% | — | 360totalsecurity 360 Total Security | 19/4/2023 | 17/6/2026 | Buffer Overflow vulnerability in Qihoo 360 Safe guard v12.1.0.1004, v12.1.0.1005, v13.1.0.1001 allows attacker to escalate priveleges. | |
| Modificada | Media (6.7) | 0.26% | — | Mcafee Total Protection | 21/3/2023 | 17/6/2026 | McAfee Total Protection prior to 16.0.50 may allow an adversary (with full administrative access) to modify a McAfee specific Component Object Model (COM) in the Windows Registry. This can result in the loading of a malicious payload. | |
| Modificada | Media (5.4) | 0.52% | — | Totaljs Openplatform | 14/3/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the platform name field. | |
| Modificada | Media (5.4) | 0.52% | — | Totaljs Openplatform | 14/3/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the account name field. | |
| Modificada | Media (5.5) | 0.24% | — | Mcafee Total Protection | 13/3/2023 | 17/6/2026 | McAfee Total Protection prior to 16.0.51 allows attackers to trick a victim into uninstalling the application via the command prompt. | |
| Modificada | Media (5.5) | 0.25% | — | Mcafee Total Protection | 13/3/2023 | 17/6/2026 | McAfee Total Protection prior to 16.0.49 allows attackers to elevate user privileges due to DLL sideloading. This could enable a user with lower privileges to execute unauthorized tasks. | |
| Modificada | Media (5.5) | 0.28% | — | Mcafee Total Protection | 13/3/2023 | 17/6/2026 | McAfee Total Protection prior to 16.0.50 allows attackers to elevate user privileges due to Improper Link Resolution via registry keys. This could enable a user with lower privileges to execute unauthorized tasks. | |
| Modificada | Media (4.3) | 0.57% | — | Boldgrid Total Upkeep | 7/3/2023 | 17/6/2026 | The Total Upkeep plugin for WordPress is vulnerable to information disclosure in versions up to, and including 1.14.13. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated attackers, with subscriber-level permissions… | |
| Modificada | Alta (7.8) | 0.23% | — | Mcafee Total Protection | 23/11/2022 | 17/6/2026 | McAfee Total Protection prior to version 16.0.49 contains an uncontrolled search path element vulnerability due to the use of a variable pointing to a subdirectory that may be controllable by an unprivileged user. This may have allowed the unprivileged user to execute arbitrary code with system privileges. | |
| Modificada | Alta (7.8) | 0.17% | — | BD Totalys Multiprocessor Firmware | 4/11/2022 | 17/6/2026 | BD Totalys MultiProcessor, versions 1.70 and earlier, contain hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic protected health information (ePHI), protected health information (PHI) and personally identifiable information (PII).… | |
| Modificada | Media (5.4) | 0.45% | — | WP Total Hacks Project WP Total Hacks | 31/10/2022 | 17/6/2026 | The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's settings. This could allow users such as subscribers to perform Stored Cross-Site Scripting attacks against other users, like administrators, due to the lack of sanitisation and escaping as well. |