Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
754 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.99% | — | Archisteamfarm Project Archisteamfarm | 8/2/2022 | 17/6/2026 | ArchiSteamFarm (ASF) is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code, introduced in version V5.2.2.2, the program didn't adequately verify effective access of the user sending proxy (i.e. `[Bots]`) commands. In particular, a proxy-like… | |
| Modificada | Alta (7.8) | 2.3% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 25/1/2022 | 17/6/2026 | An Information Disclosure vulnerability for JT files in Autodesk Inventor 2022, 2021, 2020, 2019 in conjunction with other vulnerabilities may lead to code execution through maliciously crafted JT files in the context of the current process. | |
| Modificada | Alta (7.8) | 2.9% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 25/1/2022 | 17/6/2026 | A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond allocated boundaries when parsing the JT file. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | |
| Modificada | Crítica (9.8) | 2.8% | — | Online Thesis Archiving System Project Online Thesis Archiving System | 10/1/2022 | 17/6/2026 | Sourcecodester Online Thesis Archiving System 1.0 is vulnerable to SQL Injection. An attacker can bypass admin authentication and gain access to admin panel using SQL Injection | |
| Modificada | Media (4.3) | 0.38% | — | Archivy Project Archivy | 25/12/2021 | 17/6/2026 | archivy is vulnerable to Cross-Site Request Forgery (CSRF) | |
| Modificada | Alta (7.8) | 1.4% | — | Autodesk RevitAutodesk NavisworksAutodesk Advance SteelAutodesk Autocad+9 | 23/12/2021 | 17/6/2026 | A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through PDFTron earlier than 9.0.7 version. | |
| Modificada | Alta (7.8) | 1.5% | — | Autodesk RevitAutodesk NavisworksAutodesk Advance SteelAutodesk Autocad+9 | 23/12/2021 | 17/6/2026 | PDFTron prior to 9.0.7 version may be forced to read beyond allocated boundaries when parsing a maliciously crafted PDF file. This vulnerability can be exploited to execute arbitrary code. | |
| Modificada | Media (5.5) | 0.29% | — | IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Space Management | 13/12/2021 | 17/6/2026 | IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 214438. | |
| Modificada | Alta (7.8) | 0.86% | — | Comprehensive Perl Archive NetworkFedoraproject Fedora | 13/12/2021 | 17/6/2026 | CPAN 2.28 allows Signature Verification Bypass. | |
| Modificada | Media (6.7) | 0.29% | — | AMD Generic Encapsulated Software Architecture | 10/12/2021 | 17/6/2026 | Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with physical or administrative access to potentially manipulate the AMD Generic Encapsulated Software Architecture (AGESA) to execute arbitrary code undetected by the operating system. | |
| Modificada | Crítica (9.8) | 1.2% | — | Archibus WEB Central | 5/10/2021 | 17/6/2026 | In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), the Web Application in /archibus/login.axvw assign a session token that could be already in use by another user. It was therefore possible to access the application through a user whose credentials were not known, without any attempt by the testers to modify… | |
| Modificada | Media (6.1) | 0.77% | — | Archibus WEB Central | 5/10/2021 | 17/6/2026 | In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), XSS occurs in /archibus/dwr/call/plaincall/workflow.runWorkflowRule.dwr because the data received as input from clients is re-included within the HTTP response returned by the application without adequate validation. In this way, if HTML code or client-side… | |
| Modificada | Alta (8.8) | 0.88% | — | Archibus WEB Central | 5/10/2021 | 17/6/2026 | ARCHIBUS Web Central 21.3.3.815 (a version from 2014) does not properly validate requests for access to data and functionality in these affected endpoints: /archibus/schema/ab-edit-users.axvw, /archibus/schema/ab-data-dictionary-table.axvw, /archibus/schema/ab-schema-add-field.axvw,… | |
| Modificada | Alta (7.1) | 73% | — | PHP Archive TARDebian LinuxFedoraproject Fedora | 30/7/2021 | 17/6/2026 | In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193. | |
| Modificada | Media (5.9) | 1.7% | — | Archisteamfarm Project Archisteamfarm | 26/7/2021 | 17/6/2026 | ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. In versions prior to 4.3.1.0 a Denial of Service (aka DoS) vulnerability which allows attacker to remotely crash running ASF instance through sending a specifically-crafted Steam chat message exists.… | |
| Modificada | Alta (7.5) | 1.0% | — | Archisteamfarm Project Archisteamfarm | 26/7/2021 | 17/6/2026 | ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code `POST /Api/ASF` ASF API endpoint responsible for updating global ASF config incorrectly removed `IPCPassword` from the resulting config when the caller did not specify it… | |
| Modificada | Media (6.5) | 2.8% | — | LibarchiveFedoraproject FedoraApple IpadosApple Iphone OS+3 | 20/7/2021 | 17/6/2026 | libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block). | |
| Modificada | Alta (7.8) | 0.88% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 25/6/2021 | 17/6/2026 | An Arbitrary Address Write issue in the Autodesk DWG application can allow a malicious user to leverage the application to write in unexpected paths. In order to exploit this the attacker would need the victim to enable full page heap in the application. | |
| Modificada | Alta (7.8) | 1.8% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+6 | 25/6/2021 | 17/6/2026 | A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. The vulnerability exists because the application fails to handle a crafted DWG file, which causes an unhandled exception. An attacker can leverage this vulnerability to execute arbitrary code. | |
| Modificada | Alta (7.8) | 1.7% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+9 | 25/6/2021 | 17/6/2026 | A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. This vulnerability can be exploited to execute arbitrary code | |
| Modificada | Baja (3.3) | 2.7% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+9 | 25/6/2021 | 17/6/2026 | A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code. | |
| Modificada | Media (4.3) | 0.92% | — | Powerarchiver | 21/6/2021 | 17/6/2026 | The XML parser used in ConeXware PowerArchiver before 20.10.02 allows processing of external entities, which might lead to exfiltration of local files over the network (via an XXE attack). | |
| Modificada | Alta (7.8) | 0.21% | — | IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Virtual Environments | 26/4/2021 | 17/6/2026 | IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full control of the system due to insecure directory permissions. IBM X-Force ID: 198811. | |
| Modificada | Alta (8.1) | 1.1% | — | Oracle Bill Presentment Architecture | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Bill Presentment Architecture product of Oracle E-Business Suite (component: Template Search). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bill… | |
| Modificada | Alta (7.1) | 1.0% | — | Eikisoft Archive Collectively Operation Utility | 7/4/2021 | 17/6/2026 | Directory traversal vulnerability in Archive collectively operation utility Ver.2.10.1.0 and earlier allows an attacker to create or overwrite files by leading a user to expand a malicious ZIP archives. |