Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

286 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)6.4%💥 ExploitInfireal Mxcamarchive12/8/200916/6/2026
mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain configuration details and passwords via a direct request for archive/config.ini.
ModificadaBaja (3.5)1.5%—Barracuda Networks Barracuda IM FirewallBarracuda Networks Barracuda Load BalancerBarracuda Networks Barracuda Message ArchiverBarracuda Networks Barracuda Spam Firewall+119/12/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in Barracuda Spam Firewall (BSF) before 3.5.12.007, Message Archiver before 1.2.1.002, Web Filter before 3.3.0.052, IM Firewall before 3.1.01.017, and Load Balancer before 2.3.024 allow remote attackers to inject arbitrary web script or HTML via (1) the…
ModificadaMedia (4.3)1.1%—Drupal Archive ModuleDrupal25/1/200816/6/2026
Cross-site scripting (XSS) vulnerability in the Archive 5.x before 5.x-1.8 module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)4.3%—Archive\ \Canonical Ubuntu Linux2/11/200716/6/2026
Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files via a TAR archive that contains a file whose name is an absolute path or has ".." sequences.
ModificadaAlta (9.3)4.8%—Conexware Powerarchiver9/10/200716/6/2026
Heap-based buffer overflow in ConeXware PowerArchiver before 10.20.21 might allow remote attackers to execute arbitrary code via a long filename in a BlackHole archive.
ModificadaMedia (4.3)3.4%—Freebsd Libarchive15/7/200716/6/2026
archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (crash) via (1) an end-of-file condition within a tar header that follows a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive, which results in a…
ModificadaMedia (4.3)3.9%—Freebsd Libarchive14/7/200716/6/2026
archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (infinite loop) via (1) an end-of-file condition within a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive.
ModificadaAlta (9.3)7.4%—Freebsd Libarchive14/7/200716/6/2026
archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly compute the length of a certain buffer when processing a malformed pax extension header, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PAX or (2) TAR…
ModificadaAlta (9.3)4.6%—Wakwak Lhaca File Archiver3/7/200716/6/2026
Stack-based buffer overflow in Lhaca File Archiver before 1.22 allows user-assisted remote attackers to execute arbitrary code via a large LHA "Extended Header Size" value in an LZH archive, a different issue than CVE-2007-3375.
ModificadaMedia (6.8)4.7%—Lhaca File Archiver25/6/200716/6/2026
Stack-based buffer overflow in Lhaca File Archiver before 1.21 allows user-assisted remote attackers to execute arbitrary code via a crafted LZH archive, as exploited by malware such as Trojan.Lhdropper.
ModificadaAlta (7.5)1.5%—Archivexpert11/4/200716/6/2026
Multiple directory traversal vulnerabilities in ArchiveXpert 2.02 build 80 allow remote attackers to create files in arbitrary directories via a .. (dot dot) in a (1) .gz, (2) .jar, (3) .rar, (4) .tar.gz, (5) .zip, or (6) .tar file.
ModificadaMedia (6.8)1.2%—Darrens 5-dollar Script Archive Flashchat7/2/200716/6/2026
Cross-site scripting (XSS) vulnerability in FlashChat 4.7.8 allows remote attackers to inject arbitrary web script or HTML via the user name field when the user joins a chat room, a different vulnerability than CVE-2007-0807. NOTE: the provenance of this information is unknown; the details are obtained solely from…
ModificadaMedia (6.8)1.4%—Darrens 5-dollar Script Archive Flashchat7/2/200716/6/2026
Cross-site scripting (XSS) vulnerability in info.php in flashChat 4.7.8 allows remote attackers to inject arbitrary web script or HTML via a channel title (aka room name) that is not properly handled by the "who's online" feature.
ModificadaAlta (9.3)3.5%—Conexware Powerarchiver 20065/1/200716/6/2026
Multiple stack-based buffer overflows in the (1) LoadTree and (2) ReadHeader functions in PAISO.DLL 1.7.3.0 (1.7.3 beta) in ConeXware PowerArchiver 2006 9.64.02 allow user-assisted attackers to execute arbitrary code via a crafted ISO file containing a file within several nested directories.
ModificadaMedia (5)1.2%—Apple BomarchivehelperApple MAC OS XApple MAC OS X Server7/12/200616/6/2026
Multiple unspecified vulnerabilities in BOMArchiveHelper in Mac OS X allow user-assisted remote attackers to cause a denial of service (application crash) via unspecified vectors related to (1) certain KERN_PROTECTION_FAILURE thread crashes and (2) certain KERN_INVALID_ADDRESS thread crashes, as discovered with the…
ModificadaAlta (7.5)3.8%💥 ExploitDarrens 5-dollar Script Archive Flashchat6/9/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in FlashChat before 4.6.2 allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter in (1) inc/cmses/aedatingCMS.php, (2) inc/cmses/aedatingCMS2.php, or (3) inc/cmses/aedating4CMS.php.
ModificadaAlta (9.3)4.6%—Conexware Powerarchiver5/8/200616/6/2026
Stack-based buffer overflow in DZIPS32.DLL 6.0.0.4 in ConeXware PowerArchiver 9.62.03 allows user-assisted attackers to execute arbitrary code by adding a new file to a crafted ZIP archive that already contains a file with a long name.
ModificadaMedia (5)1.2%—Darrens 5-dollar Script Archive Osdate21/7/200616/6/2026
Darren's $5 Script Archive osDate 1.1.7 and earlier allows users to boost their own ratings via a txtrating parameter with a score greater than the intended maximum of 10.
ModificadaMedia (6.8)1.7%—Darrens 5-dollar Script Archive Osdate21/7/200616/6/2026
Cross-site scripting (XSS) vulnerability in showprofile.php in Darren's $5 Script Archive osDate 1.1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the onerror attribute in an HTML IMG tag with a non-existent source file in txtcomment parameter, which is used when posting a comment.
ModificadaBaja (2.6)1.3%—Anton Belev MP3 Search Archive19/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in MP3 Search/Archive 1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter, as used by the "search box", and (2) res parameter.
ModificadaMedia (5)1.6%—KGB Archiver4/4/200616/6/2026
Directory traversal vulnerability in KGB Archiver before 1.1.5.22 allows remote attackers to overwrite arbitrary files wile decompressing an archive, possibly due to directory traversal sequences in a filename.
ModificadaMedia (5)2.4%—Pear Archive TAR28/2/200616/6/2026
Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a TAR archive.
ModificadaMedia (5)1.9%—Pear Archive ZIP28/2/200616/6/2026
Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a ZIP archive.
ModificadaMedia (4.3)1.2%—Quicksquare Development Honeycomb Archive Enterprise20/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in Honeycomb Archive Enterprise 3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keyword parameter in search.cfm.
ModificadaAlta (7.5)1.2%💥 ExploitQuicksquare Development Honeycomb ArchiveQuicksquare Development Honeycomb Archive Enterprise20/12/200516/6/2026
Multiple SQL injection vulnerabilities in CategoryResults.cfm in Honeycomb Archive and Honeycomb Archive Enterprise 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) series, (2) cat_parent, (3) cat, and (4) div parameters.