Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

754 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.1%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+623/11/202317/6/2026
A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
ModificadaMedia (6.1)0.29%—Ericteubert Archivist - Custom Archive Templates27/10/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.5 versions.
ModificadaMedia (5.4)0.41%—Osmansorkar Ajax Archive Calendar25/10/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Osmansorkar Ajax Archive Calendar plugin <= 2.6.7 versions.
ModificadaMedia (5.4)0.68%—Archivebox19/10/20237/7/2026
ArchiveBox is an open source self-hosted web archiving system. Any users who are using the `wget` extractor and view the content it outputs. The impact is potentially severe if you are logged in to the ArchiveBox admin site in the same browser session and view an archived malicious page designed to target your…
AnalizadaMedia (5.5)1.1%⚠ Explotación activaARM 5TH GEN GPU Architecture Kernel DriverARM Bifrost GPU Kernel DriverARM Midgard GPU Kernel DriverARM Valhall GPU Kernel Driver1/10/202317/6/2026
A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.
ModificadaMedia (6.1)1.0%💥 ExploitAjaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+424/9/202317/6/2026
All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite…
ModificadaAlta (7.8)0.37%—Archive Project Archive30/8/202317/6/2026
An issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file.
ModificadaAlta (7.8)0.35%—Archive Project Archive30/8/202317/6/2026
An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.
ModificadaMedia (5.5)0.37%—Ziparchive Project Ziparchive30/8/202317/6/2026
An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file.
ModificadaMedia (6.1)0.46%—Perfopsone Mailarchiver30/8/202317/6/2026
The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute…
ModificadaMedia (6.5)0.84%—Opengroup Archi10/8/202317/6/2026
An NTLM Hash Disclosure was discovered in ArchiMate Archi before 5.1.0. When parsing the XMLNS value of an ArchiMate project file, if the namespace does not match the expected ArchiMate URL, the parser will access the provided resource. If the provided resource is a UNC path pointing to a share server that does not…
ModificadaAlta (8.8)0.34%—Lw-systems Benno Mailarchiv9/8/202317/6/2026
A CSRF issue was discovered in LWsystems Benno MailArchiv 2.10.1.
ModificadaMedia (6.1)0.44%—Lw-systems Benno Mailarchiv9/8/202317/6/2026
An issue was discovered in LWsystems Benno MailArchiv 2.10.1. Attackers can cause XSS via JavaScript content to a mailbox.
ModificadaCrítica (9.8)2.5%💥 PoCCodehaus-plexus Plexus-archiver25/7/202317/6/2026
Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified `Archiver`/`UnArchiver` API. Prior to version 4.8.0, using AbstractUnArchiver for extracting an archive might lead to an arbitrary file creation and possibly remote code execution. When extracting…
ModificadaAlta (7.8)0.24%—Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+1327/6/202317/6/2026
A maliciously crafted file consumed through pskernel.dll file could lead to memory corruption vulnerabilities. These vulnerabilities in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
ModificadaAlta (7.8)0.24%—Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+1327/6/202317/6/2026
A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploitation of these vulnerabilities may lead to code execution.
ModificadaAlta (7.8)0.25%—Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+1323/6/202317/6/2026
A maliciously crafted pskernel.dll file in Autodesk AutoCAD 2023 and Maya 2022 may be used to trigger out-of-bound read write / read vulnerabilities. Exploitation of this vulnerability may lead to code execution.
ModificadaAlta (7.8)0.16%—IBM Spectrum Protect Backup-archive Client22/6/202317/6/2026
IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access controls.
ModificadaMedia (5.3)0.19%—Libarchive29/5/202317/6/2026
Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to…
ModificadaAlta (7.1)0.30%—Opentext Archive Center Administration24/5/202317/6/2026
The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administration client (Versions 16.2.3, 21.2, and older versions) could upload XML files to the application that it did not sufficiently validate. As a result, attackers could craft…
ModificadaAlta (8.8)0.25%—Archivist Project Archivist22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 versions.
ModificadaMedia (4.8)0.37%—Simple Yearly Archive Project Simple Yearly Archive25/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Oliver Schlöbe Simple Yearly Archive plugin <= 2.1.8 versions.
ModificadaMedia (4.8)0.37%—Archivist - Custom Archive Templates Project Archivist - Custom Archive Templates25/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 versions.
ModificadaCrítica (9.8)0.77%—Online Thesis Archiving System Project Online Thesis Archiving System18/4/202317/6/2026
A vulnerability classified as critical was found in Campcodes Online Thesis Archiving System 1.0. This vulnerability affects unknown code of the file /admin/user/manage_user.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…
ModificadaCrítica (9.8)0.77%—Online Thesis Archiving System Project Online Thesis Archiving System18/4/202317/6/2026
A vulnerability classified as critical has been found in Campcodes Online Thesis Archiving System 1.0. This affects an unknown part of the file /admin/curriculum/view_curriculum.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…