Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
363 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.2% | — | Totaljs Total.js | 30/10/2022 | 17/6/2026 | In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter. | |
| Modificada | Alta (7.5) | 0.79% | — | Jenkins Compuware Topaz FOR Total Test | 19/10/2022 | 17/6/2026 | Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Alta (7.5) | 0.66% | — | Jenkins Compuware Topaz FOR Total Test | 19/10/2022 | 17/6/2026 | Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to read arbitrary files on the Jenkins controller file system. | |
| Modificada | Media (5.3) | 0.71% | — | Jenkins Compuware Topaz FOR Total Test | 19/10/2022 | 17/6/2026 | Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process. | |
| Modificada | Media (4.3) | 0.51% | — | Jenkins Compuware Topaz FOR Total Test | 19/10/2022 | 17/6/2026 | Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Media (5.4) | 0.85% | — | Totaljs Total.js | 7/10/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website name text field under Main Settings. | |
| Modificada | Media (5.4) | 0.55% | — | Total-soft Event Calendar | 21/9/2022 | 17/6/2026 | Authenticated (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress. | |
| Modificada | Media (5.3) | 0.66% | — | Total-soft Event Calendar | 9/9/2022 | 17/6/2026 | Unauthenticated Event Deletion vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress. | |
| Modificada | Alta (7.3) | 0.29% | — | Quickheal Total Security | 23/5/2022 | 17/6/2026 | A DLL hijacking vulnerability in the installed for Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, leading to execution of arbitrary code, via the installer not restricting the search path for required DLLs and then not verifying the signature of the DLLs it tries… | |
| Modificada | Alta (7) | 0.16% | — | Quickheal Total Security | 23/5/2022 | 17/6/2026 | Time of Check - Time of Use (TOCTOU) vulnerability in Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, potentially leading to deletion of system files. This is achieved through exploiting the time between detecting a file as malicious and when the action of… | |
| Modificada | Media (5.4) | 0.62% | — | Totaljs Total.js | 16/5/2022 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execute arbitrary web scripts via a JavaScript embedded PDF file. | |
| Modificada | Alta (7.5) | 1.4% | — | Siemens Simatic PCS NEOSiemens SinetplanSiemens Totally Integrated Automation Portal | 12/4/2022 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo (Administration Console) (All versions < V3.1 SP1), SINETPLAN (All versions), TIA Portal (V15, V15.1, V16 and V17). The affected system cannot properly process specially crafted packets sent to port 8888/tcp. A remote attacker could exploit this vulnerability to… | |
| Modificada | Crítica (9.8) | 3.1% | — | Kaspersky Anti-virusKaspersky Endpoint SecurityKaspersky Internet SecurityKaspersky Security Cloud+2 | 1/4/2022 | 17/6/2026 | Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data parsing module that potentially allowed an attacker to execute arbitrary code. The fix was delivered automatically. Credits: Georgy Zaytsev (Positive Technologies). | |
| Modificada | Media (5.5) | 0.20% | — | Kaspersky Anti-virusKaspersky Endpoint SecurityKaspersky Internet SecurityKaspersky Security Cloud+2 | 1/4/2022 | 17/6/2026 | A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security. A local user could cause Windows crash by running a specially crafted binary module. The fix was delivered automatically. Credits: (Straghkov Denis, Kurmangaleev Shamil,… | |
| Modificada | Media (4.8) | 0.54% | — | Totaljs Content Management System | 1/4/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Name text field when creating a new page. | |
| Modificada | Alta (7.8) | 0.76% | — | Bitdefender Antivirus PlusBitdefender Endpoint Security ToolsBitdefender Internet SecurityBitdefender Total Security | 7/3/2022 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools for Windows allows a remote attacker to escalate local privileges to SYSTEM. This issue affects: Bitdefender… | |
| Modificada | Media (6.1) | 0.55% | — | Bitdefender Antivirus PlusBitdefender Endpoint Security ToolsBitdefender Internet SecurityBitdefender Total Security+1 | 7/3/2022 | 17/6/2026 | A NULL Pointer Dereference vulnerability in the messaging_ipc.dll component as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools, VPN Standalone allows an attacker to arbitrarily crash product processes and generate crashdump files. This issue affects: Bitdefender Total… | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Alta (7.8) | 0.32% | — | Bitdefender Antivirus PlusBitdefender Internet SecurityBitdefender Total Security | 18/2/2022 | 17/6/2026 | A Process Control vulnerability in ProductAgentUI.exe as used in Bitdefender Antivirus Plus allows an attacker to tamper with product settings via a specially crafted DLL file. This issue affects: Bitdefender Antivirus Plus versions prior to 24.0.26.136. Bitdefender Internet Security versions prior to 24.0.26.136.… | |
| Analizada | Media (5.5) | 0.83% | — | Virustotal Yara | 4/2/2022 | 17/6/2026 | A Buffer Overflow vulnerablity exists in VirusTotal YARA git commit: 605b2edf07ed8eb9a2c61ba22eb2e7c362f47ba7 via yr_set_configuration in yara/libyara/libyara.c, which could cause a Denial of Service. | |
| Modificada | Alta (7.5) | 1.3% | — | Unifiedoffice Total Connect NOW | 3/2/2022 | 17/6/2026 | SQL Injection vulnerability discovered in Unified Office Total Connect Now that would allow an attacker to extract sensitive information through a cookie parameter. | |
| Modificada | Alta (7.8) | 0.69% | — | Bitdefender Endpoint Security ToolsBitdefender Total Security | 28/10/2021 | 17/6/2026 | Incorrect Default Permissions vulnerability in the bdservicehost.exe and Vulnerability.Scan.exe components as used in Bitdefender Endpoint Security Tools for Windows, Total Security allows a local attacker to elevate privileges to NT AUTHORITY\SYSTEM This issue affects: Bitdefender Endpoint Security Tools for Windows… | |
| Modificada | Alta (7.8) | 0.96% | — | Bitdefender Endpoint Security ToolsBitdefender Total Security | 28/10/2021 | 17/6/2026 | Execution with Unnecessary Privileges vulnerability in Bitdefender Endpoint Security Tools, Total Security allows a local attacker to elevate to 'NT AUTHORITY\System. Impersonation enables the server thread to perform actions on behalf of the client but within the limits of the client's security context. This issue… | |
| Modificada | Alta (7.8) | 0.37% | — | Mcafee Total Protection | 26/10/2021 | 17/6/2026 | Privilege escalation vulnerability in the Windows trial installer of McAfee Total Protection (MTP) prior to 16.0.34_x may allow a local user to run arbitrary code as the admin user by replacing a specific temporary file created during the installation of the trial version of MTP. | |
| Modificada | Alta (7.2) | 1.5% | — | Totaljs Total.js | 30/8/2021 | 17/6/2026 | Total.js framework (npm package total.js) is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django or ASP.NET MVC. In total.js framework before version 3.4.9, calling the utils.set function with user-controlled values leads to code-injection. This can cause a variety… |