Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

286 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)1.8%—Libarchive20/9/201617/6/2026
bsdcpio in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read and crash) via crafted cpio file.
ModificadaMedia (5.8)1.0%💥 ExploitSapcar Archive Tool13/8/201617/6/2026
SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard link attack on files extracted from an archive, possibly related to SAP Security Note 2327384.
ModificadaAlta (7.5)4.4%—Canonical Ubuntu LinuxKDE Karchives2/8/201617/6/2026
Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.
ModificadaAlta (8.8)10%—Libarchive7/5/201617/6/2026
Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to execute arbitrary code via crafted entry-size values in a ZIP archive.
ModificadaAlta (10)1.6%—Gehealthcare Centricity Clinical Archive Audit Trail Repository4/8/201517/6/2026
GE Healthcare Centricity Clinical Archive Audit Trail Repository has a default password of initinit for the (1) SSL key manager and (2) server keystore; (3) keystore_password for the server truststore; and atna for the (4) primary storage database and (5) archive storage database, which has unspecified impact and…
ModificadaAlta (7.5)5.8%—Debian LinuxFedoraproject FedoraARJ Software ARJ Archiver8/4/201517/6/2026
Buffer overflow in Open-source ARJ archiver 3.10.22 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ARJ archive.
ModificadaMedia (5.8)3.3%—ARJ Software ARJ ArchiverFedoraproject Fedora8/4/201517/6/2026
Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive.
ModificadaMedia (5.8)3.8%—ARJ Software ARJ ArchiverFedoraproject Fedora8/4/201517/6/2026
Open-source ARJ archiver 3.10.22 allows remote attackers to conduct directory traversal attacks via a symlink attack in an ARJ archive.
ModificadaMedia (6.4)4.9%—LibarchiveCanonical Ubuntu LinuxOpensuse15/3/201517/6/2026
Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.
ModificadaMedia (6.9)0.64%—Hamstersoft Hamster Free ZIP Archiver23/10/201417/6/2026
Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the current working directory.
ModificadaAlta (9.3)11%💥 ExploitPowersoftware Winarchiver25/4/201416/6/2026
Buffer overflow in Power Software WinArchiver 3.2 allows remote attackers to execute arbitrary code via a crafted .zip file.
ModificadaMedia (5)1.2%—SAP Guided Procedures Archive Monitor10/4/201417/6/2026
Unspecified vulnerability in SAP Guided Procedures Archive Monitor allows remote attackers to obtain usernames, roles, profiles, and possibly other identity information via unknown vectors.
ModificadaMedia (5)0.76%—Powerarchiver14/3/201417/6/2026
The Encrypt Files feature in ConeXware PowerArchiver before 14.02.05 uses legacy ZIP encryption even if the AES 256-bit selection is chosen, which makes it easier for context-dependent attackers to obtain sensitive information via a known-plaintext attack.
ModificadaMedia (5)3.9%—LibarchiveCanonical Ubuntu LinuxOpensuseFedoraproject Fedora+130/9/201316/6/2026
Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecified vectors, which triggers an improper conversion between unsigned and…
ModificadaMedia (5.8)1.2%—Earl Dunovant Monthly Archive BY Node Type31/10/201216/6/2026
The Monthly Archive by Node Type module 6.x for Drupal does not properly check permissions defined by node_access modules, which allows remote attackers to access restricted nodes via unspecified vectors.
ModificadaMedia (6)1.5%—Efstechnology Autoform PDM Archive13/6/201216/6/2026
AutoFORM PDM Archive before 7.0 implements user accounts in a way that allows for JMX Console authentication, which allows remote authenticated users to bypass intended access restrictions via the /jmx-console URI, and then upload and execute arbitrary JSP code via a JBoss remote-deployment mechanism, a different…
ModificadaBaja (3.5)1.1%—Efstechnology Autoform PDM Archive13/6/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in AutoFORM PDM Archive before 6.920 allow remote authenticated users to inject arbitrary web script or HTML via unspecified fields.
ModificadaMedia (6.5)1.6%—Efstechnology Autoform PDM Archive13/6/201216/6/2026
The administrative functions in AutoFORM PDM Archive before 7.1 do not have authorization requirements, which allows remote authenticated users to perform administrative actions by leveraging knowledge of a hidden function, as demonstrated by the password-change function.
ModificadaMedia (6.5)1.6%—Efstechnology Autoform PDM Archive13/6/201216/6/2026
The web service in AutoFORM PDM Archive before 7.1 does not have authorization requirements, which allows remote authenticated users to perform database operations via a SOAP request, as demonstrated by the initializeQueryDatabase2 request.
ModificadaAlta (7.5)1.4%—Freebsd Libarchive13/4/201216/6/2026
Multiple use-after-free vulnerabilities in libarchive 2.8.4 and 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted (1) TAR archive or (2) ISO9660 image.
ModificadaMedia (6.8)4.2%—Freebsd Libarchive13/4/201216/6/2026
Buffer overflow in libarchive through 2.8.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TAR archive.
ModificadaMedia (6.8)4.2%—Freebsd Libarchive13/4/201216/6/2026
Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660.c in libarchive through 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ISO9660 image.
ModificadaAlta (7.5)2.1%—Freebsd Libarchive13/4/201216/6/2026
Buffer overflow in libarchive 3.0 pre-release code allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CAB file, which is not properly handled during the reading of Huffman code data within LZX compressed data.
ModificadaMedia (6.9)0.28%—Ponsoftware Archive Decoder25/10/201016/6/2026
Untrusted search path vulnerability in Archive Decoder 1.23 and earlier allows local users to gain privileges via a Trojan horse executable file in the current working directory.
ModificadaMedia (6.5)4.8%💥 ExploitInfireal Mxcamarchive12/8/200916/6/2026
Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to inject arbitrary PHP code into an unspecified program via the description parameter, which is executed by invocation of index.php. NOTE: some of these details are obtained from third party…
Orbitaley — Vulnerabilidades