Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.8) | 3.8% | — | ARJ Software ARJ ArchiverFedoraproject Fedora | 8/4/2015 | 17/6/2026 | Open-source ARJ archiver 3.10.22 allows remote attackers to conduct directory traversal attacks via a symlink attack in an ARJ archive. | |
| Modificada | Media (6.4) | 4.9% | — | LibarchiveCanonical Ubuntu LinuxOpensuse | 15/3/2015 | 17/6/2026 | Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Beehive Forum | 3/3/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in edit_prefs.php in Beehive Forum 1.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) homepage_url, (2) pic_url, or (3) avatar_url parameter, which are not properly handled in an error message. | |
| Modificada | Media (4.6) | 0.63% | — | OpensuseRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+2 | 8/12/2014 | 17/6/2026 | lib/handle.c in Hivex before 1.3.11 allows local users to execute arbitrary code and gain privileges via a small hive files, which triggers an out-of-bounds read or write. | |
| Modificada | Baja (3.5) | 3.5% | — | Apache Hive | 16/11/2014 | 17/6/2026 | Apache Hive before 0.13.1, when in SQL standards based authorization mode, does not properly check the file permissions for (1) import and (2) export statements, which allows remote authenticated users to obtain sensitive information via a crafted URI. | |
| Modificada | Media (6.9) | 0.64% | — | Hamstersoft Hamster Free ZIP Archiver | 23/10/2014 | 17/6/2026 | Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the current working directory. | |
| Modificada | Media (5.4) | 0.27% | — | Withive Knights N Squires | 9/9/2014 | 17/6/2026 | The Knights N Squires (aka com.com2us.imhero.normal.freefull.google.global.android.common) application 1.1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Withhive Kakao | 9/9/2014 | 17/6/2026 | The Kakao (aka com.com2us.tinypang.kakao.freefull2.google.global.android.common) application 2.11.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Withhive Tiny Farm | 9/9/2014 | 17/6/2026 | The Tiny Farm (aka com.com2us.tinyfarm.normal.freefull.google.global.android.common) application 2.02.00 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Withhive Puzzle Family | 9/9/2014 | 17/6/2026 | The Puzzle Family (aka com.com2us.puzzlefamily.up.freefull.google.global.android.common) application 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Withhive 9 Innings\ | 9/9/2014 | 17/6/2026 | The 9 Innings: 2014 Pro Baseball (aka com.com2us.nipb2013.normal.freefull.google.global.android.common) application 4.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Withhive Homerun Battle 2 | 9/9/2014 | 17/6/2026 | The Homerun Battle 2 (aka com.com2us.homerunbattle2.normal.freefull.google.global.android.common) application 1.2.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Withhive Actionpuzzlefamily FOR Kakao | 9/9/2014 | 17/6/2026 | The actionpuzzlefamily for Kakao (aka com.com2us.actionpuzzlefamily.kakao.freefull.google.global.android.common) application 1.4.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (9.3) | 11% | 💥 Exploit | Powersoftware Winarchiver | 25/4/2014 | 16/6/2026 | Buffer overflow in Power Software WinArchiver 3.2 allows remote attackers to execute arbitrary code via a crafted .zip file. | |
| Modificada | Media (5) | 1.2% | — | SAP Guided Procedures Archive Monitor | 10/4/2014 | 17/6/2026 | Unspecified vulnerability in SAP Guided Procedures Archive Monitor allows remote attackers to obtain usernames, roles, profiles, and possibly other identity information via unknown vectors. | |
| Modificada | Media (5) | 0.76% | — | Powerarchiver | 14/3/2014 | 17/6/2026 | The Encrypt Files feature in ConeXware PowerArchiver before 14.02.05 uses legacy ZIP encryption even if the AES 256-bit selection is chosen, which makes it easier for context-dependent attackers to obtain sensitive information via a known-plaintext attack. | |
| Modificada | Media (6.5) | 3.1% | 💥 Exploit | Webhive Timeline | 29/1/2014 | 16/6/2026 | Unrestricted file upload vulnerability in the user profile page feature in the Timeline Plugin 4.2.5p9 for SocialEngine allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in public/temporary/timeline/. | |
| Modificada | Media (5) | 3.9% | — | LibarchiveCanonical Ubuntu LinuxOpensuseFedoraproject Fedora+1 | 30/9/2013 | 16/6/2026 | Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecified vectors, which triggers an improper conversion between unsigned and… | |
| Modificada | Media (5.8) | 1.2% | — | Earl Dunovant Monthly Archive BY Node Type | 31/10/2012 | 16/6/2026 | The Monthly Archive by Node Type module 6.x for Drupal does not properly check permissions defined by node_access modules, which allows remote attackers to access restricted nodes via unspecified vectors. | |
| Modificada | Media (6) | 1.5% | — | Efstechnology Autoform PDM Archive | 13/6/2012 | 16/6/2026 | AutoFORM PDM Archive before 7.0 implements user accounts in a way that allows for JMX Console authentication, which allows remote authenticated users to bypass intended access restrictions via the /jmx-console URI, and then upload and execute arbitrary JSP code via a JBoss remote-deployment mechanism, a different… | |
| Modificada | Baja (3.5) | 1.1% | — | Efstechnology Autoform PDM Archive | 13/6/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in AutoFORM PDM Archive before 6.920 allow remote authenticated users to inject arbitrary web script or HTML via unspecified fields. | |
| Modificada | Media (6.5) | 1.6% | — | Efstechnology Autoform PDM Archive | 13/6/2012 | 16/6/2026 | The administrative functions in AutoFORM PDM Archive before 7.1 do not have authorization requirements, which allows remote authenticated users to perform administrative actions by leveraging knowledge of a hidden function, as demonstrated by the password-change function. | |
| Modificada | Media (6.5) | 1.6% | — | Efstechnology Autoform PDM Archive | 13/6/2012 | 16/6/2026 | The web service in AutoFORM PDM Archive before 7.1 does not have authorization requirements, which allows remote authenticated users to perform database operations via a SOAP request, as demonstrated by the initializeQueryDatabase2 request. | |
| Modificada | Alta (7.5) | 1.4% | — | Freebsd Libarchive | 13/4/2012 | 16/6/2026 | Multiple use-after-free vulnerabilities in libarchive 2.8.4 and 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted (1) TAR archive or (2) ISO9660 image. | |
| Modificada | Media (6.8) | 4.2% | — | Freebsd Libarchive | 13/4/2012 | 16/6/2026 | Buffer overflow in libarchive through 2.8.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TAR archive. |