Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
754 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.77% | — | Online Thesis Archiving System Project Online Thesis Archiving System | 18/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Online Thesis Archiving System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/students/view_details.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 0.77% | — | Online Thesis Archiving System Project Online Thesis Archiving System | 18/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Online Thesis Archiving System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file classes/Master.php. The manipulation of the argument name leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.98% | — | Online Thesis Archiving System Project Online Thesis Archiving System | 18/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Online Thesis Archiving System 1.0. It has been classified as critical. Affected is an unknown function of the file projects_per_curriculum.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.98% | — | Online Thesis Archiving System Project Online Thesis Archiving System | 18/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Online Thesis Archiving System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/departments/view_department.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Alta (7.8) | 0.30% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+6 | 14/4/2023 | 17/6/2026 | A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | |
| Modificada | Alta (7.8) | 0.24% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+6 | 14/4/2023 | 17/6/2026 | A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | |
| Modificada | Alta (7.8) | 0.24% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+6 | 14/4/2023 | 17/6/2026 | A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can be used to write beyond the allocated buffer causing a Stack Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.24% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+6 | 14/4/2023 | 17/6/2026 | A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can be used to cause an Integer Overflow. A malicious actor can leverage this vulnerability to cause a crash or read sensitive data, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.24% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+6 | 14/4/2023 | 17/6/2026 | A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code in the context of the current process. | |
| Analizada | Baja (3.3) | 1.2% | ⚠ Explotación activa💥 PoC | ARM 5TH GEN GPU Architecture Kernel DriverARM Bifrost GPU Kernel DriverARM Midgard GPU Kernel DriverARM Valhall GPU Kernel Driver | 6/4/2023 | 17/6/2026 | Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user… | |
| Modificada | Alta (8.8) | 2.9% | — | Apache Unstructured Information Management Architecture | 30/3/2023 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache UIMA DUCC. When using the "Distributed UIMA Cluster Computing" (DUCC) module of Apache UIMA, an authenticated user that has the permissions to modify… | |
| Modificada | Media (5.4) | 1.2% | — | Apache Archiva | 29/3/2023 | 17/6/2026 | Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploited only by authenticated users which can create directory name to inject some XSS content and gain some privileges such admin user. | |
| Modificada | Media (5.4) | 0.57% | — | Twinpictures Annual Archive | 6/2/2023 | 17/6/2026 | The Annual Archive WordPress plugin before 1.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (7.5) | 0.52% | — | Oracle HCM Common Architecture | 18/1/2023 | 17/6/2026 | Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Auomated Test Suite). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HCM Common Architecture.… | |
| Modificada | Media (4.3) | 0.46% | — | Archibus WEB Central | 10/1/2023 | 17/6/2026 | An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application allows a basic user to access the profile information of all connected users. | |
| Modificada | Media (4.3) | 0.48% | — | Archibus WEB Central | 10/1/2023 | 17/6/2026 | An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a set of user-controlled parameters that are used to act on the data returned to the user. It allows a basic user to access data unrelated to their role. | |
| Modificada | Alta (8.8) | 0.64% | — | Archibus WEB Central | 10/1/2023 | 17/6/2026 | An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a user-controlled parameter that is used to create an SQL query. It causes this service to be prone to SQL injection. | |
| Modificada | Media (4.3) | 0.41% | — | Archibus WEB Central | 10/1/2023 | 17/6/2026 | An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application allows a basic user to cancel (delete) a booking, created by someone else - even if this basic user is not a member of the booking | |
| Modificada | Alta (8.1) | 0.91% | — | Ziparchive Project Ziparchive | 3/1/2023 | 17/6/2026 | SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item. | |
| Modificada | Crítica (9.1) | 1.2% | — | Cloudfoundry Archiver | 27/12/2022 | 17/6/2026 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | |
| Modificada | Crítica (9.8) | 2.4% | — | LibarchiveDebian LinuxFedoraproject FedoraSplunk Universal Forwarder | 22/11/2022 | 17/6/2026 | In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare… | |
| Modificada | Crítica (9.8) | 0.59% | — | Hostel Searching Project | 17/11/2022 | 17/6/2026 | A vulnerability has been found in Hostel Searching Project and classified as critical. This vulnerability affects unknown code of the file view-property.php. The manipulation of the argument property_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Media (4.3) | 1.4% | — | Apache Archiva | 15/11/2022 | 17/6/2026 | Users with write permissions to a repository can delete arbitrary directories. | |
| Modificada | Alta (7.5) | 1.3% | — | Apache Archiva | 15/11/2022 | 17/6/2026 | If anonymous read enabled, it's possible to read the database file directly without logging in. | |
| Modificada | Alta (7.8) | 0.40% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+7 | 21/10/2022 | 17/6/2026 | A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. |