Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.84%—Osisoft PI Data Archive24/7/202017/6/2026
An authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure. This can result in blocking queries to PI Data Archive (2018 SP2 and prior versions).
ModificadaAlta (7.5)1.3%—Compression AND Archive Extensions TZ Project23/6/202017/6/2026
In all versions of the package github.com/unknwon/cae/tz, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.
ModificadaAlta (7.5)1.4%—Compression AND Archive Extensions Project Compression AND Archive Extensions ZIP Project23/6/202017/6/2026
In all versions of the package github.com/unknwon/cae/zip, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.
ModificadaCrítica (9.8)8.3%—JoddApache Hive21/5/202017/6/2026
Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.
ModificadaMedia (6.1)0.84%—Hive Netius21/5/202017/6/2026
netius prior to 1.17.58 is vulnerable to HTTP Request Smuggling. HTTP pipelining issues and request smuggling attacks might be possible due to incorrect Transfer encoding header parsing which could allow for CL:TE or TE:TE attacks.
ModificadaAlta (8.8)2.3%—LibarchiveCanonical Ubuntu LinuxFedoraproject Fedora20/2/202017/6/2026
archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact.
ModificadaMedia (4.4)0.30%—IBM Spectrum Protect Backup-archive Client25/11/201917/6/2026
IBM Spectrum Protect Backup-Archive Client 7.1 and 8.1 may be vulnerable to a denial of service attack due to a timing issue between client and server TCP/IP communications. IBM X-Force ID: 162477.
ModificadaMedia (5.5)0.66%—LibarchiveDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux21/11/201917/6/2026
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
ModificadaAlta (8.1)0.92%—Archivemail Project ArchivemailDebian Linux6/11/201916/6/2026
archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition.
ModificadaMedia (5.5)6.4%💥 PoCArchiver Project Archiver29/10/201917/6/2026
All versions of archiver allow attacker to perform a Zip Slip attack via the "unarchive" functions. It is exploited using a specially crafted zip archive, that holds path traversal filenames. When exploited, a filename in a malicious archive is concatenated to the target extraction directory, which results in the…
ModificadaAlta (7.5)4.0%—LibarchiveDebian LinuxCanonical Ubuntu Linux24/10/201917/6/2026
archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.
ModificadaCrítica (9.8)2.3%—Archivesunleashed Graphpass15/7/201917/6/2026
borg-reducer c6d5240 is affected by: Buffer Overflow. The impact is: Possible code execution and denial of service. The component is: Output parameter within the executable.
ModificadaAlta (8.8)1.9%—Strangebee Thehive2/6/201917/6/2026
An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to escalate their privileges to the administrator's privileges. This affects app/controllers/UserCtrl.scala.
ModificadaMedia (6.1)2.3%💥 ExploitHeidelberg Prinect Archiver24/5/201917/6/2026
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0.
ModificadaAlta (7.7)5.1%💥 ExploitThehive-project Cortex-analyzers9/5/201917/6/2026
TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the vulnerability, an attacker must create a new analysis, select URL for Data Type, and provide an SSRF payload like "http://127.0.0.1:22" in the Data parameter. The result can be seen in the main…
ModificadaMedia (5.5)1.3%—Libarchive23/4/201917/6/2026
A memory leak in archive_read_format_zip_cleanup in archive_read_support_format_zip.c in libarchive 3.3.4-dev allows remote attackers to cause a denial of service via a crafted ZIP file because of a HAVE_LZMA_H typo. NOTE: this only affects users who downloaded the development code from GitHub. Users of the product's…
ModificadaMedia (4.7)0.22%—IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Virtual Environments8/4/201917/6/2026
In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be displayed in plain text in the IBM Spectrum Protect client trace file. IBM X-Force ID: 151968.
ModificadaMedia (6.1)1.2%—IBM Spectrum Protect Backup-archive Client8/4/201917/6/2026
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks…
ModificadaMedia (5.5)0.30%—IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Virtual Environments8/4/201917/6/2026
IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by insecure file permissions. IBM X-Force ID: 148872.
ModificadaMedia (6.1)1.4%—Hivewebstudios Font Organizer22/3/201917/6/2026
The font-organizer plugin 2.1.1 for WordPress has wp-admin/options-general.php manage_font_id XSS.
ModificadaMedia (6.5)3.2%—LibarchiveCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+44/2/201917/6/2026
libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) contains a CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ISO9660 parser, archive_read_support_format_iso9660.c, read_CE()/parse_rockridge() that can result in DoS by infinite loop.…
ModificadaMedia (6.5)3.4%—LibarchiveDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora+44/2/201917/6/2026
libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: Out-of-bounds Read vulnerability in 7zip decompression, archive_read_support_format_7zip.c, header_bytes() that can result in a crash (denial of service). This attack appears to be exploitable via…
ModificadaAlta (8.8)19%💥 ExploitPHP Pear Archive TARCanonical Ubuntu LinuxDebian Linux28/12/201817/6/2026
PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are several file operations with `$v_header['filename']` as parameter (such as file_exists, is_file, is_dir, etc). When extract is called without a specific prefix path, we can trigger unserialization…
ModificadaMedia (6.1)0.69%—Barracuda Message Archiver23/12/201817/6/2026
Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry.cgi module. The injection point of the issue is the Add_Update module.
ModificadaAlta (7.2)1.7%—Thehive-project Cortex21/12/201817/6/2026
An organization administrator can add a super administrator in THEHIVE PROJECT Cortex before 2.1.3 due to the lack of overriding the Role.toString method.