Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
74 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.3) | 0.14% | — | GNU LibextractorAI | 25/9/2026 | 30/9/2026 | GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX to a directory containing a malicious plugin that executes arbitrary code with elevated… | |
| Pendiente de análisis | Alta (8.7) | 0.74% | — | GNU LibextractorAI | 14/9/2026 | 24/9/2026 | GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data. Attackers can craft malicious StarOffice documents that allocate up to 4 MB on the stack, causing stack overflow and… | |
| Aplazada | Alta (8.1) | 0.28% | — | Max-mapper Extract-zipAI | 17/8/2026 | 9/9/2026 | extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and… | |
| Analizada | Alta (8.6) | 0.53% | 💥 PoC | Max-mapper Extract-zip | 26/6/2026 | 6/7/2026 | extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how… | |
| Pendiente de análisis | Media (5.6) | 0.14% | — | Gnome Tracker-extract-mp3AIGnome Tracker-minersAI | 16/6/2026 | 17/6/2026 | A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Denial of Service (DoS)… | |
| Aplazada | Media (5.5) | 0.29% | — | Sourcecodester SEO Meta TAG ExtractorAI | 1/6/2026 | 22/7/2026 | A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get_headers of the file /index.php. This manipulation of the argument url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and… | |
| Analizada | Crítica (9.8) | 3.6% | 💥 PoC | Dbashford Textract | 25/3/2026 | 17/6/2026 | textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious filenames, the filePath is passed directly to child_process.exec() in lib/extractors/doc.js, rtf.js, dxf.js, images.js, and lib/util.js with inadequate sanitization | |
| Analizada | Baja (2.1) | 0.43% | — | Remyandrade Website Link Extractor | 25/2/2026 | 17/6/2026 | A vulnerability has been found in SourceCodester Website Link Extractor 1.0. This vulnerability affects the function file_get_contents of the component URL Handler. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Baja (1.9) | 0.17% | — | CcextractorAI | 21/2/2026 | 17/6/2026 | A vulnerability was detected in CCExtractor up to 0.96.5. Affected is the function processmp4 in the library src/lib_ccx/mp4.c. Performing a manipulation results in use after free. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version 0.96.6 is able to address… | |
| Aplazada | Baja (1.9) | 0.15% | — | CcextractorAI | 9/2/2026 | 17/6/2026 | A vulnerability was identified in CCExtractor up to 183. This affects the function parse_PAT/parse_PMT in the library src/lib_ccx/ts_tables.c of the component MPEG-TS File Parser. Such manipulation leads to out-of-bounds read. The attack can only be performed from a local environment. The exploit is publicly available… | |
| Aplazada | Media (5.3) | 0.34% | — | Magic Import Document ExtractorAI | 4/2/2026 | 17/6/2026 | The Magic Import Document Extractor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.4 via the get_frontend_settings() function. This makes it possible for unauthenticated attackers to extract the site's magicimport.ai license key from the page source on… | |
| Aplazada | Media (5.3) | 0.34% | — | Magic Import Document ExtractorAI | 4/2/2026 | 17/6/2026 | The Magic Import Document Extractor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_sync_usage() function in all versions up to, and including, 1.0.5. This makes it possible for unauthenticated attackers to modify the plugin's license status and… | |
| Analizada | Media (4.3) | 0.44% | — | Articentgroup ZIP RAR Extractor Tool | 3/2/2026 | 17/6/2026 | Articentgroup Zip Rar Extractor Tool 1.345.93.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file processing component, specifically in the functionality responsible for extracting and handling ZIP archive contents. | |
| Aplazada | Baja (2.7) | 0.39% | — | Wikimedia TextextractsAI | 3/2/2026 | 17/6/2026 | Vulnerability in Wikimedia Foundation TextExtracts. This vulnerability is associated with program files includes/ApiQueryExtracts.Php. This issue affects TextExtracts: from * before 1.39.14, 1.43.4, 1.44.1. | |
| Analizada | Media (5.5) | 0.43% | — | Simsong Bulk Extractor | 28/1/2026 | 17/6/2026 | `bulk_extractor` is a digital forensics exploitation tool. Starting in version 1.4, `bulk_extractor`’s embedded unrar code has a heap‑buffer‑overflow in the RAR PPM LZ decoding path. A crafted RAR inside a disk image causes an out‑of‑bounds write in `Unpack::CopyString`, leading to a crash under ASAN (and likely a… | |
| Aplazada | Alta (8.4) | 0.55% | — | Kingdia CD ExtractorAI | 15/1/2026 | 17/6/2026 | Kingdia CD Extractor 3.0.2 contains a buffer overflow vulnerability in the registration name field that allows attackers to execute arbitrary code. Attackers can craft a malicious payload exceeding 256 bytes to overwrite Structured Exception Handler and gain remote code execution through a bind shell. | |
| Aplazada | Media (6.9) | 0.36% | — | Piextract Soop-clmAI | 13/10/2025 | 17/6/2026 | SOOP-CLM developed by PiExtract has a Server-Side Request Forgery vulnerability, allowing privileged remote attackers to read server files or probe internal network information. | |
| Aplazada | Alta (8.6) | 0.58% | — | Piextract Soop-clmAI | 13/10/2025 | 17/6/2026 | SOOP-CLM developed by PiExtract has a Hidden Functionality vulnerability, allowing privileged remote attackers to exploit a hidden functionality to execute arbitrary code on the server. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Piextract Soop-clmAI | 31/3/2025 | 17/6/2026 | SOOP-CLM from PiExtract has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Aplazada | Media (5.5) | 0.56% | 💥 PoC | Rarlab RAR Extractor - UnarchiverAIRarlab RAR Extractor - Unarchiver PROAI | 21/1/2025 | 17/6/2026 | An issue in RAR Extractor - Unarchiver Free and Pro v.6.4.0 allows local attackers to inject arbitrary code potentially leading to remote control and unauthorized access to sensitive user data via the exploit_combined.dylib component on MacOS. | |
| Analizada | Media (6.9) | 0.55% | — | Codeclysm Extract | 11/10/2024 | 17/6/2026 | Extract is aA Go library to extract archives in zip, tar.gz or tar.bz2 formats. A maliciously crafted archive may allow an attacker to create a symlink outside the extraction target directory. This vulnerability is fixed in 4.0.0. If you're using the Extractor.FS interface, then upgrading to /v4 will require to… | |
| Modificada | Alta (7.5) | 1.1% | — | Markdown-link-extractor Project Markdown-link-extractor | 2/6/2022 | 17/6/2026 | An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package, when an attacker is able to supply arbitrary input to the module's exported function | |
| Analizada | Media (5.5) | 0.73% | — | Metadata-extractor Project Metadata-extractor | 24/2/2022 | 17/6/2026 | When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of memory that finally leads to an out-of-memory error even for very small inputs. This could be used to mount a denial of service attack against services that use metadata-extractor library. | |
| Analizada | Media (5.5) | 0.78% | — | Metadata-extractor Project Metadata-extractor | 24/2/2022 | 17/6/2026 | metadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which could result in an application crash. This could be used to mount a denial of service attack against services that use metadata-extractor library. | |
| Modificada | Media (6.5) | 12% | — | Apache Xerces-jOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Banking Deposits AND Lines OF Credit Servicing+25 | 24/1/2022 | 25/8/2026 | There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version… |