Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.8%—Apache-airflow-providers-apache-hive3/7/202317/6/2026
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects Apache Airflow Apache Hive Provider: before 6.1.1. Before version 6.1.1 it was possible to bypass the security check to RCE via principal parameter. For this to be exploited it requires access to…
ModificadaAlta (7.8)0.16%—IBM Spectrum Protect Backup-archive Client22/6/202317/6/2026
IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access controls.
ModificadaMedia (5.3)0.19%—Libarchive29/5/202317/6/2026
Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to…
ModificadaAlta (7.1)0.30%—Opentext Archive Center Administration24/5/202317/6/2026
The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administration client (Versions 16.2.3, 21.2, and older versions) could upload XML files to the application that it did not sufficiently validate. As a result, attackers could craft…
ModificadaMedia (6.1)0.38%—Wp-property-hive Propertyhive15/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.48 versions.
ModificadaMedia (4.8)0.37%—Simple Yearly Archive Project Simple Yearly Archive25/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Oliver Schlöbe Simple Yearly Archive plugin <= 2.1.8 versions.
ModificadaMedia (4.8)0.37%—Archivist - Custom Archive Templates Project Archivist - Custom Archive Templates25/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 versions.
ModificadaMedia (6.1)0.38%—Wp-property-hive Propertyhive7/4/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.46 versions.
ModificadaCrítica (9.8)2.8%—Apache Airflow Hive Provider7/4/202317/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 6.0.0.
ModificadaCrítica (9.8)2.0%—Apache-airflow-providers-apache-hive24/2/202317/6/2026
Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3.
ModificadaMedia (5.4)0.57%—Twinpictures Annual Archive6/2/202317/6/2026
The Annual Archive WordPress plugin before 1.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaAlta (8.1)0.91%—Ziparchive Project Ziparchive3/1/202317/6/2026
SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item.
ModificadaCrítica (9.1)1.2%—Cloudfoundry Archiver27/12/202217/6/2026
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
ModificadaCrítica (9.8)3.3%—Apache-airflow-providers-apache-hive20/12/202217/6/2026
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0.
ModificadaAlta (7.8)1.7%—Apache AirflowApache-airflow-providers-apache-hive22/11/202217/6/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airflow allows an attacker to execute arbtrary commands in the task execution context, without write access to DAG files. This issue affects Hive Provider versions prior to…
ModificadaCrítica (9.8)2.4%—LibarchiveDebian LinuxFedoraproject FedoraSplunk Universal Forwarder22/11/202217/6/2026
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare…
ModificadaCrítica (9.8)1.3%—Democritus D8s-archives11/10/202217/6/2026
The d8s-archives package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.
ModificadaCrítica (9.8)1.7%—D8s-archives Project D8s-archives19/9/202217/6/2026
The d8s-archives for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
ModificadaAlta (7.8)0.39%—LibarchiveFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux EUS+1023/8/202217/6/2026
An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may…
ModificadaAlta (7.8)0.39%—LibarchiveFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux EUS+923/8/202217/6/2026
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL…
ModificadaAlta (7.8)0.43%—Git-archive Project Git-archive25/7/202217/6/2026
All versions of package git-archive are vulnerable to Command Injection via the exports function.
ModificadaAlta (7.5)1.9%—Apache Hive16/7/202217/6/2026
Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized or underprivileged users to drop and…
ModificadaCrítica (9.8)2.6%—GFI Archiver7/7/202217/6/2026
File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which is affected by CVE-2014-2217, and CVE-2017-11317.
ModificadaAlta (8.1)2.0%💥 PoCCaphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+666/6/20229/7/2026
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected…
ModificadaMedia (6.5)1.9%—LibarchiveFedoraproject Fedora28/3/202217/6/2026
Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.
Orbitaley — Vulnerabilidades