Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

363 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.9%💥 ExploitBoldgrid W3 Total Cache19/7/202117/6/2026
The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the 'Anonymously track usage to improve product quality' setting is enabled, as the parameter is output in a JavaScript context without proper…
ModificadaMedia (6.1)1.9%💥 ExploitBoldgrid W3 Total Cache19/7/202117/6/2026
The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability within the "extension" parameter in the Extensions dashboard, which is output in an attribute without being escaped first. This could allow an attacker, who can convince an authenticated…
ModificadaMedia (4.8)0.62%—Boldgrid W3 Total Cache12/7/202117/6/2026
The W3 Total Cache WordPress plugin before 2.1.3 did not sanitise or escape some of its CDN settings, allowing high privilege users to use JavaScript in them, which will be output in the page, leading to an authenticated Stored Cross-Site Scripting issue
ModificadaCrítica (9.8)3.0%—Totaljs Total412/7/202117/6/2026
The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
ModificadaCrítica (9.8)3.6%—Totaljs Total.js12/7/202117/6/2026
The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
ModificadaAlta (7.5)0.54%—Bitdefender Antivirus PlusBitdefender Internet SecurityBitdefender Total Security22/6/202117/6/2026
Improper Certificate Validation vulnerability in the Online Threat Prevention module as used in Bitdefender Total Security allows an attacker to potentially bypass HTTP Strict Transport Security (HSTS) checks. This issue affects: Bitdefender Total Security versions prior to 25.0.7.29. Bitdefender Internet Security…
ModificadaCrítica (9.1)2.2%—Virustotal YaraFedoraproject Fedora14/5/202117/6/2026
An integer overflow and several buffer overflow reads in libyara/modules/macho/macho.c in YARA v4.0.3 and earlier could allow an attacker to either cause denial of service or information disclosure via a malicious Mach-O file. Affects all versions before libyara 4.0.4
ModificadaAlta (7.8)0.34%—Mcafee Total Protection12/5/202117/6/2026
Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated privileges by impersonating a client token which could lead to the bypassing of MTP self-defense.
ModificadaAlta (7.8)0.43%—Mcafee Total Protection12/5/202117/6/2026
Privilege Escalation vulnerability in the File Lock component of McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated privileges by manipulating a symbolic link in the IOCTL interface.
ModificadaCrítica (9.8)4.9%—Totaljs Total.js4/3/202117/6/2026
The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set.
ModificadaAlta (7.8)0.43%—Mcafee Total Protection10/2/202117/6/2026
Bypass Remote Procedure call in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and perform arbitrary file modification as the SYSTEM user potentially causing Denial of Service via executing carefully constructed malware.
AnalizadaAlta (7.8)1.0%⚠ Explotación activaMcafee Total Protection10/2/202117/6/2026
Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense.
ModificadaMedia (6.1)0.65%—Mcafee Total Protection10/2/202117/6/2026
Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and perform arbitrary file deletion as the SYSTEM user potentially causing Denial of Service via manipulating Junction link, after enumerating certain files, at a specific time.
ModificadaAlta (7.8)0.86%—Siemens Simatic Process Control System NEOSiemens Totally Integrated Automation Portal9/2/202117/6/2026
A vulnerability has been identified in PCS neo (Administration Console) (All versions < V3.1), TIA Portal (V15, V15.1 and V16). Manipulating certain files in specific folders could allow a local attacker to execute code with SYSTEM privileges. The security vulnerability could be exploited by an attacker with a valid…
ModificadaAlta (7.3)3.6%—Totaljs Total.js2/2/202117/6/2026
This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to the path. However the keys of the path being set are not properly sanitized, leading to a prototype pollution vulnerability. The impact depends on the application. In some cases it is possible to…
ModificadaAlta (8.6)1.7%—Totaljs Total.js2/2/202117/6/2026
This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type parameter is used to build the command that is then executed using child_process.spawn. The issue occurs because child_process.spawn is called with the option shell set to true and because the type…
ModificadaAlta (7.8)0.37%—K7computing AntivriusK7computing Enterprise SecurityK7computing Total SecurityK7computing Ultimate Security11/1/20219/7/2026
K7Computing Pvt Ltd K7AntiVirus Premium 15.1.0.53 is affected by: Buffer Overflow. The impact is: execute arbitrary code (local). The component is: K7TSMngr.exe.
ModificadaAlta (7.8)0.27%—K7computing AntivriusK7computing Enterprise SecurityK7computing Total SecurityK7computing Ultimate Security11/1/20219/7/2026
K7Computing Pvt Ltd K7AntiVirus Premium 15.01.00.53 is affected by: Incorrect Access Control. The impact is: gain privileges (local).
ModificadaAlta (7.8)0.42%—K7computing AntivriusK7computing Enterprise SecurityK7computing Total SecurityK7computing Ultimate Security11/1/20219/7/2026
K7Computing Pvt Ltd K7Antivirus Premium 15.1.0.53 is affected by: Buffer Overflow. The impact is: execute arbitrary code (local). The component is: K7TSMngr.exe.
ModificadaAlta (7.8)0.42%—K7computing AntivriusK7computing Enterprise SecurityK7computing Total SecurityK7computing Ultimate Security11/1/20219/7/2026
K7Computing Pvt Ltd K7AntiVirus Premium 15.01.00.53 is affected by: Buffer Overflow. The impact is: execute arbitrary code (local). The component is: K7TSMngr.exe.
ModificadaAlta (7.8)0.27%—K7computing AntivriusK7computing Enterprise SecurityK7computing Total SecurityK7computing Ultimate Security11/1/20219/7/2026
K7Computing Pvt Ltd K7AntiVirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: gain privileges (local). The component is: K7TSMngr.exe.
ModificadaAlta (7.8)0.33%—K7computing AntivriusK7computing Enterprise SecurityK7computing Total SecurityK7computing Ultimate Security11/1/20219/7/2026
K7Computing Pvt Ltd K7Antivirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: Local Process Execution (local). The component is: K7Sentry.sys.
ModificadaAlta (7.5)1.1%—K7computing AntivriusK7computing Enterprise SecurityK7computing Total SecurityK7computing Ultimate Security11/1/202117/6/2026
K7TSMngr.exe in K7Computing K7AntiVirus Premium 15.1.0.53 has a Memory Leak.
ModificadaAlta (7.8)0.85%—K7computing AntivriusK7computing Enterprise SecurityK7computing Total SecurityK7computing Ultimate Security11/1/202117/6/2026
A Buffer Overflow issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
ModificadaAlta (7.8)0.85%—K7computing AntivriusK7computing Enterprise SecurityK7computing Total SecurityK7computing Ultimate Security11/1/202117/6/2026
A Buffer Overflow issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
Orbitaley — Vulnerabilidades