Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 0.84% | — | Osisoft PI Data Archive | 24/7/2020 | 17/6/2026 | An authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure. This can result in blocking queries to PI Data Archive (2018 SP2 and prior versions). | |
| Modificada | Alta (7.5) | 1.3% | — | Compression AND Archive Extensions TZ Project | 23/6/2020 | 17/6/2026 | In all versions of the package github.com/unknwon/cae/tz, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide. | |
| Modificada | Alta (7.5) | 1.4% | — | Compression AND Archive Extensions Project Compression AND Archive Extensions ZIP Project | 23/6/2020 | 17/6/2026 | In all versions of the package github.com/unknwon/cae/zip, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide. | |
| Modificada | Crítica (9.8) | 8.3% | — | JoddApache Hive | 21/5/2020 | 17/6/2026 | Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set. | |
| Modificada | Media (6.1) | 0.84% | — | Hive Netius | 21/5/2020 | 17/6/2026 | netius prior to 1.17.58 is vulnerable to HTTP Request Smuggling. HTTP pipelining issues and request smuggling attacks might be possible due to incorrect Transfer encoding header parsing which could allow for CL:TE or TE:TE attacks. | |
| Modificada | Alta (8.8) | 2.3% | — | LibarchiveCanonical Ubuntu LinuxFedoraproject Fedora | 20/2/2020 | 17/6/2026 | archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact. | |
| Modificada | Media (4.4) | 0.30% | — | IBM Spectrum Protect Backup-archive Client | 25/11/2019 | 17/6/2026 | IBM Spectrum Protect Backup-Archive Client 7.1 and 8.1 may be vulnerable to a denial of service attack due to a timing issue between client and server TCP/IP communications. IBM X-Force ID: 162477. | |
| Modificada | Media (5.5) | 0.66% | — | LibarchiveDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux | 21/11/2019 | 17/6/2026 | In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive. | |
| Modificada | Alta (8.1) | 0.92% | — | Archivemail Project ArchivemailDebian Linux | 6/11/2019 | 16/6/2026 | archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition. | |
| Modificada | Media (5.5) | 6.4% | 💥 PoC | Archiver Project Archiver | 29/10/2019 | 17/6/2026 | All versions of archiver allow attacker to perform a Zip Slip attack via the "unarchive" functions. It is exploited using a specially crafted zip archive, that holds path traversal filenames. When exploited, a filename in a malicious archive is concatenated to the target extraction directory, which results in the… | |
| Modificada | Alta (7.5) | 4.0% | — | LibarchiveDebian LinuxCanonical Ubuntu Linux | 24/10/2019 | 17/6/2026 | archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol. | |
| Modificada | Crítica (9.8) | 2.3% | — | Archivesunleashed Graphpass | 15/7/2019 | 17/6/2026 | borg-reducer c6d5240 is affected by: Buffer Overflow. The impact is: Possible code execution and denial of service. The component is: Output parameter within the executable. | |
| Modificada | Alta (8.8) | 1.9% | — | Strangebee Thehive | 2/6/2019 | 17/6/2026 | An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to escalate their privileges to the administrator's privileges. This affects app/controllers/UserCtrl.scala. | |
| Modificada | Media (6.1) | 2.3% | 💥 Exploit | Heidelberg Prinect Archiver | 24/5/2019 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0. | |
| Modificada | Alta (7.7) | 5.1% | 💥 Exploit | Thehive-project Cortex-analyzers | 9/5/2019 | 17/6/2026 | TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the vulnerability, an attacker must create a new analysis, select URL for Data Type, and provide an SSRF payload like "http://127.0.0.1:22" in the Data parameter. The result can be seen in the main… | |
| Modificada | Media (5.5) | 1.3% | — | Libarchive | 23/4/2019 | 17/6/2026 | A memory leak in archive_read_format_zip_cleanup in archive_read_support_format_zip.c in libarchive 3.3.4-dev allows remote attackers to cause a denial of service via a crafted ZIP file because of a HAVE_LZMA_H typo. NOTE: this only affects users who downloaded the development code from GitHub. Users of the product's… | |
| Modificada | Media (4.7) | 0.22% | — | IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Virtual Environments | 8/4/2019 | 17/6/2026 | In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be displayed in plain text in the IBM Spectrum Protect client trace file. IBM X-Force ID: 151968. | |
| Modificada | Media (6.1) | 1.2% | — | IBM Spectrum Protect Backup-archive Client | 8/4/2019 | 17/6/2026 | IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks… | |
| Modificada | Media (5.5) | 0.30% | — | IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Virtual Environments | 8/4/2019 | 17/6/2026 | IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by insecure file permissions. IBM X-Force ID: 148872. | |
| Modificada | Media (6.1) | 1.4% | — | Hivewebstudios Font Organizer | 22/3/2019 | 17/6/2026 | The font-organizer plugin 2.1.1 for WordPress has wp-admin/options-general.php manage_font_id XSS. | |
| Modificada | Media (6.5) | 3.2% | — | LibarchiveCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+4 | 4/2/2019 | 17/6/2026 | libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) contains a CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ISO9660 parser, archive_read_support_format_iso9660.c, read_CE()/parse_rockridge() that can result in DoS by infinite loop.… | |
| Modificada | Media (6.5) | 3.4% | — | LibarchiveDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora+4 | 4/2/2019 | 17/6/2026 | libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: Out-of-bounds Read vulnerability in 7zip decompression, archive_read_support_format_7zip.c, header_bytes() that can result in a crash (denial of service). This attack appears to be exploitable via… | |
| Modificada | Alta (8.8) | 19% | 💥 Exploit | PHP Pear Archive TARCanonical Ubuntu LinuxDebian Linux | 28/12/2018 | 17/6/2026 | PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are several file operations with `$v_header['filename']` as parameter (such as file_exists, is_file, is_dir, etc). When extract is called without a specific prefix path, we can trigger unserialization… | |
| Modificada | Media (6.1) | 0.69% | — | Barracuda Message Archiver | 23/12/2018 | 17/6/2026 | Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry.cgi module. The injection point of the issue is the Add_Update module. | |
| Modificada | Alta (7.2) | 1.7% | — | Thehive-project Cortex | 21/12/2018 | 17/6/2026 | An organization administrator can add a super administrator in THEHIVE PROJECT Cortex before 2.1.3 due to the lack of overriding the Role.toString method. |