Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

363 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.65%—K7computing AntivriusK7computing Enterprise SecurityK7computing Total SecurityK7computing Ultimate Security11/1/202117/6/2026
An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
ModificadaMedia (5.5)0.69%—K7computing AntivriusK7computing Enterprise SecurityK7computing Total SecurityK7computing Ultimate Security11/1/202117/6/2026
A Memory Leak issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
ModificadaMedia (5.5)0.69%—K7computing AntivriusK7computing Enterprise SecurityK7computing Total SecurityK7computing Ultimate Security11/1/202117/6/2026
An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
ModificadaMedia (5.5)0.69%—K7computing AntivriusK7computing Enterprise SecurityK7computing Total SecurityK7computing Ultimate Security11/1/202117/6/2026
A Memory Leak issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
ModificadaMedia (4.3)0.43%—Totalonlinesolutions Advanced Webhost Billing System8/1/202117/6/2026
Advanced Webhost Billing System 3.7.0 is affected by Cross Site Request Forgery (CSRF) attacks that can delete a contact from the My Additional Contact page.
ModificadaAlta (7.8)0.43%—Mcafee Total Protection1/12/202017/6/2026
Privilege Escalation vulnerability in Microsoft Windows client McAfee Total Protection (MTP) prior to 16.0.29 allows local users to gain elevated privileges via careful manipulation of a folder by creating a junction link. This exploits a lack of protection through a timing issue and is only exploitable in a small…
ModificadaMedia (6.7)0.36%—Quickheal Total Security30/11/202017/6/2026
Quick Heal Total Security before 19.0 allows attackers with local admin rights to obtain access to files in the File Vault via a brute-force attack on the password.
ModificadaMedia (5.9)0.70%—Quickheal Total Security30/11/202017/6/2026
Quick Heal Total Security before version 19.0 transmits quarantine and sysinfo files via clear text.
ModificadaMedia (4.4)0.32%—Quickheal Total Security30/11/202017/6/2026
Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify sensitive anti virus settings via a brute-attack on the settings password.
ModificadaAlta (7.3)0.39%—Ghisler Total Commander21/10/202017/6/2026
An issue was discovered in Ghisler Total Commander 9.51. Due to insufficient access restrictions in the default installation directory, an attacker can elevate privileges by replacing the %SYSTEMDRIVE%\totalcmd\TOTALCMD64.EXE binary.
ModificadaAlta (8.8)0.27%—Mcafee Total Protection14/10/202017/6/2026
Privilege Escalation vulnerability in McAfee Total Protection (MTP) trial prior to 4.0.176.1 allows local users to schedule tasks which call malicious software to execute with elevated privileges via editing of environment variables
ModificadaMedia (6.9)0.29%—Mcafee Total Protection21/8/202017/6/2026
Privilege Escalation vulnerability in the installer in McAfee McAfee Total Protection (MTP) trial prior to 4.0.161.1 allows local users to change files that are part of write protection rules via manipulating symbolic links to redirect a McAfee file operations to an unintended file.
ModificadaAlta (8.4)0.29%—Mcafee Total Protection5/8/202017/6/2026
Unexpected behavior violation in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to turn off real time scanning via a specially crafted object making a specific function call.
En análisisAlta (7.8)0.61%—360totalsecurity 360 Total Security21/7/202017/6/2026
In the version 12.1.0.1005 and below of 360 Total Security, when the Gamefolde calls GameChrome.exe, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking to bypass the hips could execute arbitrary code on the Local system.
En análisisAlta (7.8)0.48%—360totalsecurity 360 Total Security21/7/202017/6/2026
In the version 12.1.0.1004 and below of 360 Total Security, when the main process of 360 Total Security calls GameChrome.exe, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking to bypass the hips could execute arbitrary code on the Local system.
En análisisAlta (7.8)0.43%—360totalsecurity 360 Total Security21/7/202017/6/2026
In version 12.1.0.1004 and below of 360 Total Security,when TPI calls the browser process, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking could execute arbitrary code on the Local system.
ModificadaAlta (8.8)0.62%💥 PoCMcafee Total Protection3/7/202017/6/2026
Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to create and edit files via symbolic link manipulation in a location they would otherwise not have access to. This is achieved through running a malicious script or program on the target machine.
ModificadaMedia (6.3)0.32%—Mcafee Total Protection3/7/202017/6/2026
Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on…
ModificadaMedia (6.3)0.26%—Mcafee Total Protection3/7/202017/6/2026
Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program…
ModificadaAlta (8.8)1.1%—Bitdefender Total Security 202022/6/202017/6/2026
Improper Input Validation vulnerability in the Safepay browser component of Bitdefender Total Security 2020 allows an external, specially crafted web page to run remote commands inside the Safepay Utility process. This issue affects Bitdefender Total Security 2020 versions prior to 24.0.20.116.
ModificadaAlta (8.2)0.32%—Mcafee Total Protection10/6/202017/6/2026
Privilege escalation vulnerability in McAfee Total Protection (ToPS) for Mac OS prior to 4.6 allows local users to gain root privileges via incorrect protection of temporary files.
ModificadaCrítica (9.8)3.5%—Total-soft Responsive Poll13/4/202017/6/2026
An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clone, or view a hidden poll. This is due to the usage of the callback wp_ajax_nopriv function in Includes/Total-Soft-Poll-Ajax.php for sensitive operations.
ModificadaAlta (7.5)2.1%—Totaljs Total.js CMS24/2/202017/6/2026
controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/widgets/ URI. This can be exploited in conjunction with CVE-2019-15954.
ModificadaAlta (7.8)1.5%—Quickheal Antivirus FOR ServerQuickheal Antivirus PROQuickheal Home SecurityQuickheal Internet Security+224/2/202017/6/2026
The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive. This affects Total Security, Home Security, Total Security Multi-Device, Internet Security, Total Security for Mac, AntiVirus Pro, AntiVirus for Server, and Total Security for Android.
ModificadaCrítica (9.8)74%💥 ExploitAutomattic WP Super CacheBoldgrid W3 Total Cache12/2/202016/6/2026
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability