Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
754 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.1% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+6 | 23/11/2023 | 17/6/2026 | A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Modificada | Media (6.1) | 0.29% | — | Ericteubert Archivist - Custom Archive Templates | 27/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.5 versions. | |
| Modificada | Media (5.4) | 0.41% | — | Osmansorkar Ajax Archive Calendar | 25/10/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Osmansorkar Ajax Archive Calendar plugin <= 2.6.7 versions. | |
| Modificada | Media (5.4) | 0.68% | — | Archivebox | 19/10/2023 | 7/7/2026 | ArchiveBox is an open source self-hosted web archiving system. Any users who are using the `wget` extractor and view the content it outputs. The impact is potentially severe if you are logged in to the ArchiveBox admin site in the same browser session and view an archived malicious page designed to target your… | |
| Analizada | Media (5.5) | 1.1% | ⚠ Explotación activa | ARM 5TH GEN GPU Architecture Kernel DriverARM Bifrost GPU Kernel DriverARM Midgard GPU Kernel DriverARM Valhall GPU Kernel Driver | 1/10/2023 | 17/6/2026 | A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory. | |
| Modificada | Media (6.1) | 1.0% | 💥 Exploit | Ajaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+42 | 4/9/2023 | 17/6/2026 | All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite… | |
| Modificada | Alta (7.8) | 0.37% | — | Archive Project Archive | 30/8/2023 | 17/6/2026 | An issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file. | |
| Modificada | Alta (7.8) | 0.35% | — | Archive Project Archive | 30/8/2023 | 17/6/2026 | An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing. | |
| Modificada | Media (5.5) | 0.37% | — | Ziparchive Project Ziparchive | 30/8/2023 | 17/6/2026 | An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file. | |
| Modificada | Media (6.1) | 0.46% | — | Perfopsone Mailarchiver | 30/8/2023 | 17/6/2026 | The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Media (6.5) | 0.84% | — | Opengroup Archi | 10/8/2023 | 17/6/2026 | An NTLM Hash Disclosure was discovered in ArchiMate Archi before 5.1.0. When parsing the XMLNS value of an ArchiMate project file, if the namespace does not match the expected ArchiMate URL, the parser will access the provided resource. If the provided resource is a UNC path pointing to a share server that does not… | |
| Modificada | Alta (8.8) | 0.34% | — | Lw-systems Benno Mailarchiv | 9/8/2023 | 17/6/2026 | A CSRF issue was discovered in LWsystems Benno MailArchiv 2.10.1. | |
| Modificada | Media (6.1) | 0.44% | — | Lw-systems Benno Mailarchiv | 9/8/2023 | 17/6/2026 | An issue was discovered in LWsystems Benno MailArchiv 2.10.1. Attackers can cause XSS via JavaScript content to a mailbox. | |
| Modificada | Crítica (9.8) | 2.5% | 💥 PoC | Codehaus-plexus Plexus-archiver | 25/7/2023 | 17/6/2026 | Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified `Archiver`/`UnArchiver` API. Prior to version 4.8.0, using AbstractUnArchiver for extracting an archive might lead to an arbitrary file creation and possibly remote code execution. When extracting… | |
| Modificada | Alta (7.8) | 0.24% | — | Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+13 | 27/6/2023 | 17/6/2026 | A maliciously crafted file consumed through pskernel.dll file could lead to memory corruption vulnerabilities. These vulnerabilities in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | |
| Modificada | Alta (7.8) | 0.24% | — | Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+13 | 27/6/2023 | 17/6/2026 | A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploitation of these vulnerabilities may lead to code execution. | |
| Modificada | Alta (7.8) | 0.25% | — | Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+13 | 23/6/2023 | 17/6/2026 | A maliciously crafted pskernel.dll file in Autodesk AutoCAD 2023 and Maya 2022 may be used to trigger out-of-bound read write / read vulnerabilities. Exploitation of this vulnerability may lead to code execution. | |
| Modificada | Alta (7.8) | 0.16% | — | IBM Spectrum Protect Backup-archive Client | 22/6/2023 | 17/6/2026 | IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access controls. | |
| Modificada | Media (5.3) | 0.19% | — | Libarchive | 29/5/2023 | 17/6/2026 | Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to… | |
| Modificada | Alta (7.1) | 0.30% | — | Opentext Archive Center Administration | 24/5/2023 | 17/6/2026 | The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administration client (Versions 16.2.3, 21.2, and older versions) could upload XML files to the application that it did not sufficiently validate. As a result, attackers could craft… | |
| Modificada | Alta (8.8) | 0.25% | — | Archivist Project Archivist | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Simple Yearly Archive Project Simple Yearly Archive | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Oliver Schlöbe Simple Yearly Archive plugin <= 2.1.8 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Archivist - Custom Archive Templates Project Archivist - Custom Archive Templates | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 versions. | |
| Modificada | Crítica (9.8) | 0.77% | — | Online Thesis Archiving System Project Online Thesis Archiving System | 18/4/2023 | 17/6/2026 | A vulnerability classified as critical was found in Campcodes Online Thesis Archiving System 1.0. This vulnerability affects unknown code of the file /admin/user/manage_user.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 0.77% | — | Online Thesis Archiving System Project Online Thesis Archiving System | 18/4/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Campcodes Online Thesis Archiving System 1.0. This affects an unknown part of the file /admin/curriculum/view_curriculum.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… |