Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.8% | — | Apache-airflow-providers-apache-hive | 3/7/2023 | 17/6/2026 | Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects Apache Airflow Apache Hive Provider: before 6.1.1. Before version 6.1.1 it was possible to bypass the security check to RCE via principal parameter. For this to be exploited it requires access to… | |
| Modificada | Alta (7.8) | 0.16% | — | IBM Spectrum Protect Backup-archive Client | 22/6/2023 | 17/6/2026 | IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access controls. | |
| Modificada | Media (5.3) | 0.19% | — | Libarchive | 29/5/2023 | 17/6/2026 | Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to… | |
| Modificada | Alta (7.1) | 0.30% | — | Opentext Archive Center Administration | 24/5/2023 | 17/6/2026 | The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administration client (Versions 16.2.3, 21.2, and older versions) could upload XML files to the application that it did not sufficiently validate. As a result, attackers could craft… | |
| Modificada | Media (6.1) | 0.38% | — | Wp-property-hive Propertyhive | 15/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.48 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Simple Yearly Archive Project Simple Yearly Archive | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Oliver Schlöbe Simple Yearly Archive plugin <= 2.1.8 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Archivist - Custom Archive Templates Project Archivist - Custom Archive Templates | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Wp-property-hive Propertyhive | 7/4/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.46 versions. | |
| Modificada | Crítica (9.8) | 2.8% | — | Apache Airflow Hive Provider | 7/4/2023 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 6.0.0. | |
| Modificada | Crítica (9.8) | 2.0% | — | Apache-airflow-providers-apache-hive | 24/2/2023 | 17/6/2026 | Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3. | |
| Modificada | Media (5.4) | 0.57% | — | Twinpictures Annual Archive | 6/2/2023 | 17/6/2026 | The Annual Archive WordPress plugin before 1.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (8.1) | 0.91% | — | Ziparchive Project Ziparchive | 3/1/2023 | 17/6/2026 | SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item. | |
| Modificada | Crítica (9.1) | 1.2% | — | Cloudfoundry Archiver | 27/12/2022 | 17/6/2026 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | |
| Modificada | Crítica (9.8) | 3.3% | — | Apache-airflow-providers-apache-hive | 20/12/2022 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0. | |
| Modificada | Alta (7.8) | 1.7% | — | Apache AirflowApache-airflow-providers-apache-hive | 22/11/2022 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airflow allows an attacker to execute arbtrary commands in the task execution context, without write access to DAG files. This issue affects Hive Provider versions prior to… | |
| Modificada | Crítica (9.8) | 2.4% | — | LibarchiveDebian LinuxFedoraproject FedoraSplunk Universal Forwarder | 22/11/2022 | 17/6/2026 | In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare… | |
| Modificada | Crítica (9.8) | 1.3% | — | Democritus D8s-archives | 11/10/2022 | 17/6/2026 | The d8s-archives package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0. | |
| Modificada | Crítica (9.8) | 1.7% | — | D8s-archives Project D8s-archives | 19/9/2022 | 17/6/2026 | The d8s-archives for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0. | |
| Modificada | Alta (7.8) | 0.39% | — | LibarchiveFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux EUS+10 | 23/8/2022 | 17/6/2026 | An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may… | |
| Modificada | Alta (7.8) | 0.39% | — | LibarchiveFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux EUS+9 | 23/8/2022 | 17/6/2026 | An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL… | |
| Modificada | Alta (7.8) | 0.43% | — | Git-archive Project Git-archive | 25/7/2022 | 17/6/2026 | All versions of package git-archive are vulnerable to Command Injection via the exports function. | |
| Modificada | Alta (7.5) | 1.9% | — | Apache Hive | 16/7/2022 | 17/6/2026 | Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized or underprivileged users to drop and… | |
| Modificada | Crítica (9.8) | 2.6% | — | GFI Archiver | 7/7/2022 | 17/6/2026 | File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which is affected by CVE-2014-2217, and CVE-2017-11317. | |
| Modificada | Alta (8.1) | 2.0% | 💥 PoC | Caphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+66 | 6/6/2022 | 9/7/2026 | Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected… | |
| Modificada | Media (6.5) | 1.9% | — | LibarchiveFedoraproject Fedora | 28/3/2022 | 17/6/2026 | Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init. |