Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2683▼ 54 respecto a la semana anterior
Críticas / altas1442▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
363 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.42% | — | Boldgrid W3 Total CacheAI | 2/10/2026 | 2/10/2026 | The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Output-Buffer Regex Rewrite in all versions up to, and including, 2.10.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Pendiente de análisis | Media (5.5) | 0.17% | — | Virustotal YaraAI | 22/9/2026 | 24/9/2026 | A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can provide a malicious file with an invalid arena configuration (num_buffers=0) that triggers an assertion failure in yr_arena_get_ptr(), causing the application to terminate. | |
| Pendiente de análisis | Alta (7.6) | 0.25% | — | Virustotal YaraAI | 22/9/2026 | 25/9/2026 | An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnerability is caused by insufficient validation of external-variable pointers, which may lead to invalid free in yr_rules_destroy() or wild pointer access in yr_object_create(). An attacker can… | |
| Aplazada | Alta (7.5) | 0.39% | — | WP Fast Total SearchAI | 10/9/2026 | 10/9/2026 | Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions. | |
| Aplazada | Alta (7.2) | 0.50% | — | Boldgrid W3 Total CacheAI | 5/9/2026 | 8/9/2026 | The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Crítica (9.1) | 0.24% | — | Totalpaymentprocessing Total Processing Card PaymentsAI | 29/8/2026 | 31/8/2026 | The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unauthenticated attackers to redirect that request to an arbitrary host… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Calmar-webmedia Total DonationsAI | 19/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Calmar-webmedia Total DonationsAI | 19/8/2026 | 20/8/2026 | Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. | |
| Aplazada | Crítica (10) | 0.57% | — | Boldgrid W3 Total CacheAI | 19/8/2026 | 26/8/2026 | The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name. On Apache, the… | |
| Aplazada | Alta (7.2) | 0.43% | — | Boldgrid W3 Total CacheAI | 14/8/2026 | 14/8/2026 | The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Alta (7.5) | 0.43% | — | Boldgrid Total UpkeepAI | 12/8/2026 | 3/9/2026 | The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-restore functionality and exposes it to unauthenticated users, allowing them to disclose sensitive backup information and to force a full site restore that overwrites the live site's files and database.… | |
| Aplazada | Alta (8.2) | 0.37% | — | Boldgrid Total UpkeepAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions. | |
| Aplazada | Media (6.5) | 0.41% | — | W3 Total CacheAI | 6/8/2026 | 12/8/2026 | Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions. | |
| Pendiente de análisis | Alta (7.8) | 0.20% | — | Gdata Total SecurityAI | 29/7/2026 | 30/7/2026 | G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Aplazada | Alta (7.5) | 0.51% | — | WP Fast Total SearchAI | 28/7/2026 | 28/7/2026 | The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via the 'form_data[s]' parameter in all versions up to, and including, 1.80.280 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Aplazada | Media (5.3) | 0.29% | — | WP Fast Total SearchAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions. | |
| Analizada | Alta (7) | 0.15% | — | Bitdefender Internet SecurityBitdefender Total Security | 14/7/2026 | 12/8/2026 | An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and Internet Security on Windows allows a less-privileged local user to elevate rights by leveraging a race conditions via Symbolic Links. This issue affects Total Security:… | |
| Aplazada | Alta (7.5) | 2.9% | — | Boldgrid W3 Total CacheAI | 11/7/2026 | 14/7/2026 | The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation… | |
| Aplazada | Crítica (9.3) | 0.40% | — | WP Fast Total SearchAI | 2/7/2026 | 2/7/2026 | Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions. | |
| Aplazada | Crítica (9) | 0.53% | — | W3 Total CacheAI | 2/7/2026 | 2/7/2026 | Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions. | |
| Aplazada | Alta (7.5) | 0.68% | — | Clearsale TotalAI | 24/6/2026 | 25/6/2026 | The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of the `clearsale_total_push` AJAX action in all versions up to, and including, 3.4.2. The handler is registered for unauthenticated users (`wp_ajax_nopriv_clearsale_total_push`), and although a… | |
| Aplazada | Media (4.7) | 0.29% | — | Boldgrid W3 Total CacheAI | 17/6/2026 | 17/6/2026 | Author Broken Access Control in W3 Total Cache <= 2.9.1 versions. | |
| Aplazada | Alta (7.1) | 0.12% | — | Qihoo 360 Total SecurityAI | 15/6/2026 | 24/7/2026 | A security flaw has been discovered in Qihoo 360 Total Security 6.0. This vulnerability affects the function RpcStringBindingComposeW of the component Nucleus Engine Monitoring Logic. Performing a manipulation of the argument NetworkAddr results in protection mechanism failure. The attack requires a local approach.… | |
| Aplazada | Media (5.4) | 0.24% | — | TotalAI | 2/5/2026 | 17/6/2026 | The Total theme for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.2.1 due to insufficient output escaping when rendering the_title() inside HTML attribute context in the home blog section template. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.40% | — | Boldgrid Total UpkeepAI | 1/5/2026 | 17/6/2026 | The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_cli_cancel' function in all versions up to, and including, 1.17.1. This makes it possible for unauthenticated attackers… |