Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

754 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)0.99%—Archisteamfarm Project Archisteamfarm8/2/202217/6/2026
ArchiSteamFarm (ASF) is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code, introduced in version V5.2.2.2, the program didn't adequately verify effective access of the user sending proxy (i.e. `[Bots]`) commands. In particular, a proxy-like…
ModificadaAlta (7.8)2.3%—Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+725/1/202217/6/2026
An Information Disclosure vulnerability for JT files in Autodesk Inventor 2022, 2021, 2020, 2019 in conjunction with other vulnerabilities may lead to code execution through maliciously crafted JT files in the context of the current process.
ModificadaAlta (7.8)2.9%—Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+725/1/202217/6/2026
A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond allocated boundaries when parsing the JT file. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
ModificadaCrítica (9.8)2.8%—Online Thesis Archiving System Project Online Thesis Archiving System10/1/202217/6/2026
Sourcecodester Online Thesis Archiving System 1.0 is vulnerable to SQL Injection. An attacker can bypass admin authentication and gain access to admin panel using SQL Injection
ModificadaMedia (4.3)0.38%—Archivy Project Archivy25/12/202117/6/2026
archivy is vulnerable to Cross-Site Request Forgery (CSRF)
ModificadaAlta (7.8)1.4%—Autodesk RevitAutodesk NavisworksAutodesk Advance SteelAutodesk Autocad+923/12/202117/6/2026
A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through PDFTron earlier than 9.0.7 version.
ModificadaAlta (7.8)1.5%—Autodesk RevitAutodesk NavisworksAutodesk Advance SteelAutodesk Autocad+923/12/202117/6/2026
PDFTron prior to 9.0.7 version may be forced to read beyond allocated boundaries when parsing a maliciously crafted PDF file. This vulnerability can be exploited to execute arbitrary code.
ModificadaMedia (5.5)0.29%—IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Space Management13/12/202117/6/2026
IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 214438.
ModificadaAlta (7.8)0.86%—Comprehensive Perl Archive NetworkFedoraproject Fedora13/12/202117/6/2026
CPAN 2.28 allows Signature Verification Bypass.
ModificadaMedia (6.7)0.29%—AMD Generic Encapsulated Software Architecture10/12/202117/6/2026
Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with physical or administrative access to potentially manipulate the AMD Generic Encapsulated Software Architecture (AGESA) to execute arbitrary code undetected by the operating system.
ModificadaCrítica (9.8)1.2%—Archibus WEB Central5/10/202117/6/2026
In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), the Web Application in /archibus/login.axvw assign a session token that could be already in use by another user. It was therefore possible to access the application through a user whose credentials were not known, without any attempt by the testers to modify…
ModificadaMedia (6.1)0.77%—Archibus WEB Central5/10/202117/6/2026
In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), XSS occurs in /archibus/dwr/call/plaincall/workflow.runWorkflowRule.dwr because the data received as input from clients is re-included within the HTTP response returned by the application without adequate validation. In this way, if HTML code or client-side…
ModificadaAlta (8.8)0.88%—Archibus WEB Central5/10/202117/6/2026
ARCHIBUS Web Central 21.3.3.815 (a version from 2014) does not properly validate requests for access to data and functionality in these affected endpoints: /archibus/schema/ab-edit-users.axvw, /archibus/schema/ab-data-dictionary-table.axvw, /archibus/schema/ab-schema-add-field.axvw,…
ModificadaAlta (7.1)73%—PHP Archive TARDebian LinuxFedoraproject Fedora30/7/202117/6/2026
In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
ModificadaMedia (5.9)1.7%—Archisteamfarm Project Archisteamfarm26/7/202117/6/2026
ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. In versions prior to 4.3.1.0 a Denial of Service (aka DoS) vulnerability which allows attacker to remotely crash running ASF instance through sending a specifically-crafted Steam chat message exists.…
ModificadaAlta (7.5)1.0%—Archisteamfarm Project Archisteamfarm26/7/202117/6/2026
ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code `POST /Api/ASF` ASF API endpoint responsible for updating global ASF config incorrectly removed `IPCPassword` from the resulting config when the caller did not specify it…
ModificadaMedia (6.5)2.8%—LibarchiveFedoraproject FedoraApple IpadosApple Iphone OS+320/7/202117/6/2026
libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
ModificadaAlta (7.8)0.88%—Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+725/6/202117/6/2026
An Arbitrary Address Write issue in the Autodesk DWG application can allow a malicious user to leverage the application to write in unexpected paths. In order to exploit this the attacker would need the victim to enable full page heap in the application.
ModificadaAlta (7.8)1.8%—Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+625/6/202117/6/2026
A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. The vulnerability exists because the application fails to handle a crafted DWG file, which causes an unhandled exception. An attacker can leverage this vulnerability to execute arbitrary code.
ModificadaAlta (7.8)1.7%—Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+925/6/202117/6/2026
A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. This vulnerability can be exploited to execute arbitrary code
ModificadaBaja (3.3)2.7%—Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+925/6/202117/6/2026
A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code.
ModificadaMedia (4.3)0.92%—Powerarchiver21/6/202117/6/2026
The XML parser used in ConeXware PowerArchiver before 20.10.02 allows processing of external entities, which might lead to exfiltration of local files over the network (via an XXE attack).
ModificadaAlta (7.8)0.21%—IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Virtual Environments26/4/202117/6/2026
IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full control of the system due to insecure directory permissions. IBM X-Force ID: 198811.
ModificadaAlta (8.1)1.1%—Oracle Bill Presentment Architecture22/4/202117/6/2026
Vulnerability in the Oracle Bill Presentment Architecture product of Oracle E-Business Suite (component: Template Search). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bill…
ModificadaAlta (7.1)1.0%—Eikisoft Archive Collectively Operation Utility7/4/202117/6/2026
Directory traversal vulnerability in Archive collectively operation utility Ver.2.10.1.0 and earlier allows an attacker to create or overwrite files by leading a user to expand a malicious ZIP archives.