Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

754 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.77%—Online Thesis Archiving System Project Online Thesis Archiving System18/4/202317/6/2026
A vulnerability was found in Campcodes Online Thesis Archiving System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/students/view_details.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has…
ModificadaCrítica (9.8)0.77%—Online Thesis Archiving System Project Online Thesis Archiving System18/4/202317/6/2026
A vulnerability was found in Campcodes Online Thesis Archiving System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file classes/Master.php. The manipulation of the argument name leads to sql injection. The attack can be launched remotely. The exploit has been…
ModificadaCrítica (9.8)0.98%—Online Thesis Archiving System Project Online Thesis Archiving System18/4/202317/6/2026
A vulnerability was found in Campcodes Online Thesis Archiving System 1.0. It has been classified as critical. Affected is an unknown function of the file projects_per_curriculum.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been…
ModificadaCrítica (9.8)0.98%—Online Thesis Archiving System Project Online Thesis Archiving System18/4/202317/6/2026
A vulnerability was found in Campcodes Online Thesis Archiving System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/departments/view_department.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been…
ModificadaAlta (7.8)0.30%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+614/4/202317/6/2026
A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
ModificadaAlta (7.8)0.24%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+614/4/202317/6/2026
A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
ModificadaAlta (7.8)0.24%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+614/4/202317/6/2026
A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can be used to write beyond the allocated buffer causing a Stack Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code in the context of the current process.
ModificadaAlta (7.8)0.24%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+614/4/202317/6/2026
A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can be used to cause an Integer Overflow. A malicious actor can leverage this vulnerability to cause a crash or read sensitive data, or execute arbitrary code in the context of the current process.
ModificadaAlta (7.8)0.24%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+614/4/202317/6/2026
A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code in the context of the current process.
AnalizadaBaja (3.3)1.2%⚠ Explotación activa💥 PoCARM 5TH GEN GPU Architecture Kernel DriverARM Bifrost GPU Kernel DriverARM Midgard GPU Kernel DriverARM Valhall GPU Kernel Driver6/4/202317/6/2026
Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user…
ModificadaAlta (8.8)2.9%—Apache Unstructured Information Management Architecture30/3/202317/6/2026
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache UIMA DUCC. When using the "Distributed UIMA Cluster Computing" (DUCC) module of Apache UIMA, an authenticated user that has the permissions to modify…
ModificadaMedia (5.4)1.2%—Apache Archiva29/3/202317/6/2026
Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploited only by authenticated users which can create directory name to inject some XSS content and gain some privileges such admin user.
ModificadaMedia (5.4)0.57%—Twinpictures Annual Archive6/2/202317/6/2026
The Annual Archive WordPress plugin before 1.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaAlta (7.5)0.52%—Oracle HCM Common Architecture18/1/202317/6/2026
Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Auomated Test Suite). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HCM Common Architecture.…
ModificadaMedia (4.3)0.46%—Archibus WEB Central10/1/202317/6/2026
An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application allows a basic user to access the profile information of all connected users.
ModificadaMedia (4.3)0.48%—Archibus WEB Central10/1/202317/6/2026
An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a set of user-controlled parameters that are used to act on the data returned to the user. It allows a basic user to access data unrelated to their role.
ModificadaAlta (8.8)0.64%—Archibus WEB Central10/1/202317/6/2026
An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a user-controlled parameter that is used to create an SQL query. It causes this service to be prone to SQL injection.
ModificadaMedia (4.3)0.41%—Archibus WEB Central10/1/202317/6/2026
An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application allows a basic user to cancel (delete) a booking, created by someone else - even if this basic user is not a member of the booking
ModificadaAlta (8.1)0.91%—Ziparchive Project Ziparchive3/1/202317/6/2026
SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item.
ModificadaCrítica (9.1)1.2%—Cloudfoundry Archiver27/12/202217/6/2026
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
ModificadaCrítica (9.8)2.4%—LibarchiveDebian LinuxFedoraproject FedoraSplunk Universal Forwarder22/11/202217/6/2026
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare…
ModificadaCrítica (9.8)0.59%—Hostel Searching Project17/11/202217/6/2026
A vulnerability has been found in Hostel Searching Project and classified as critical. This vulnerability affects unknown code of the file view-property.php. The manipulation of the argument property_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may…
ModificadaMedia (4.3)1.4%—Apache Archiva15/11/202217/6/2026
Users with write permissions to a repository can delete arbitrary directories.
ModificadaAlta (7.5)1.3%—Apache Archiva15/11/202217/6/2026
If anonymous read enabled, it's possible to read the database file directly without logging in.
ModificadaAlta (7.8)0.40%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+721/10/202217/6/2026
A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
Orbitaley — Vulnerabilidades