Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)4.2%—Freebsd Libarchive13/4/201216/6/2026
Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660.c in libarchive through 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ISO9660 image.
ModificadaAlta (7.5)2.1%—Freebsd Libarchive13/4/201216/6/2026
Buffer overflow in libarchive 3.0 pre-release code allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CAB file, which is not properly handled during the reading of Huffman code data within LZX compressed data.
ModificadaMedia (4.3)1.5%💥 ExploitBeehive Forum20/1/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Beehive Forum 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) forum/register.php or (2) forum/logon.php.
ModificadaAlta (7.5)76%💥 ExploitOracle Beehive19/1/201116/6/2026
Unspecified vulnerability in the Services for Beehive component in Oracle Fusion Middleware 2.0.1.0, 2.0.1.1, 2.0.1.2, 2.0.1.2.1, and 2.0.1.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2011 CPU. Oracle…
ModificadaMedia (6.9)0.28%—Ponsoftware Archive Decoder25/10/201016/6/2026
Untrusted search path vulnerability in Archive Decoder 1.23 and earlier allows local users to gain privileges via a Trojan horse executable file in the current working directory.
ModificadaMedia (6.5)4.8%💥 ExploitInfireal Mxcamarchive12/8/200916/6/2026
Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to inject arbitrary PHP code into an unspecified program via the description parameter, which is executed by invocation of index.php. NOTE: some of these details are obtained from third party…
ModificadaAlta (7.5)6.4%💥 ExploitInfireal Mxcamarchive12/8/200916/6/2026
mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain configuration details and passwords via a direct request for archive/config.ini.
ModificadaMedia (6.8)1.7%💥 ExploitHivemaker6/3/200916/6/2026
SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ModificadaBaja (3.5)1.5%—Barracuda Networks Barracuda IM FirewallBarracuda Networks Barracuda Load BalancerBarracuda Networks Barracuda Message ArchiverBarracuda Networks Barracuda Spam Firewall+119/12/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in Barracuda Spam Firewall (BSF) before 3.5.12.007, Message Archiver before 1.2.1.002, Web Filter before 3.3.0.052, IM Firewall before 3.1.01.017, and Load Balancer before 2.3.024 allow remote attackers to inject arbitrary web script or HTML via (1) the…
ModificadaAlta (7.5)0.91%💥 ExploitFichive23/5/200816/6/2026
SQL injection vulnerability in index.php in FicHive 1.0 allows remote attackers to execute arbitrary SQL commands via the letter parameter in a Search action, a different vector than CVE-2008-2416. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (6.8)1.9%💥 ExploitDigitalhive22/5/200816/6/2026
Directory traversal vulnerability in template/purpletech/base_include.php in DigitalHive (aka hive) 2.0 RC2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
ModificadaAlta (7.5)0.97%💥 ExploitFichive22/5/200816/6/2026
SQL injection vulnerability in index.php in FicHive 1.0 allows remote attackers to execute arbitrary SQL commands via the category parameter in a Fiction action, possibly related to sources/fiction.class.php.
ModificadaMedia (4.3)1.5%💥 ExploitDigital Hive Digitalhive27/4/200816/6/2026
Cross-site scripting (XSS) vulnerability in base.php in DigitalHive 2.0 RC2 allows remote attackers to inject arbitrary web script or HTML via the mt parameter, possibly related to membres.php.
ModificadaAlta (7.5)1.4%—Beehive Software Sendfile.net4/3/200816/6/2026
The outboxWriteUnsent function in FTPThread.class in SendFile.jar for Beehive Software SendFile.NET uses hard-coded credentials for an FTP server, which allows remote attackers to gain privileges.
ModificadaMedia (4.3)1.1%—Drupal Archive ModuleDrupal25/1/200816/6/2026
Cross-site scripting (XSS) vulnerability in the Archive 5.x before 5.x-1.8 module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)0.96%💥 ExploitDigitalhive16/1/200816/6/2026
Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and earlier allow (1) remote attackers to execute arbitrary SQL commands via the selectskin parameter to an unspecified program, or (2) remote authenticated administrators to execute arbitrary SQL commands via the user_id parameter in the…
ModificadaAlta (7.5)1.3%—Beehive Forum5/12/200716/6/2026
SQL injection vulnerability in post.php in Beehive Forum 0.7.1 and earlier allows remote attackers to execute arbitrary SQL commands via the t_dedupe parameter.
ModificadaAlta (7.5)0.99%—Beehive Forum5/12/200716/6/2026
Multiple unspecified vulnerabilities in Beehive Forum 0.7.1 have unknown "critical" impact and attack vectors, different issues than CVE-2007-6014.
ModificadaMedia (6.8)4.3%—Archive\ \Canonical Ubuntu Linux2/11/200716/6/2026
Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files via a TAR archive that contains a file whose name is an absolute path or has ".." sequences.
ModificadaAlta (9.3)4.8%—Conexware Powerarchiver9/10/200716/6/2026
Heap-based buffer overflow in ConeXware PowerArchiver before 10.20.21 might allow remote attackers to execute arbitrary code via a long filename in a BlackHole archive.
ModificadaMedia (4.3)3.4%—Freebsd Libarchive15/7/200716/6/2026
archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (crash) via (1) an end-of-file condition within a tar header that follows a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive, which results in a…
ModificadaMedia (4.3)3.9%—Freebsd Libarchive14/7/200716/6/2026
archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (infinite loop) via (1) an end-of-file condition within a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive.
ModificadaAlta (9.3)7.4%—Freebsd Libarchive14/7/200716/6/2026
archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly compute the length of a certain buffer when processing a malformed pax extension header, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PAX or (2) TAR…
ModificadaAlta (9.3)4.6%—Wakwak Lhaca File Archiver3/7/200716/6/2026
Stack-based buffer overflow in Lhaca File Archiver before 1.22 allows user-assisted remote attackers to execute arbitrary code via a large LHA "Extended Header Size" value in an LZH archive, a different issue than CVE-2007-3375.
ModificadaMedia (6.8)4.7%—Lhaca File Archiver25/6/200716/6/2026
Stack-based buffer overflow in Lhaca File Archiver before 1.21 allows user-assisted remote attackers to execute arbitrary code via a crafted LZH archive, as exploited by malware such as Trojan.Lhdropper.
Orbitaley — Vulnerabilidades