Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
754 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.35% | — | Simple Yearly ArchiveAI | 5/8/2026 | 12/8/2026 | The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `posttype` attribute of the `SimpleYearlyArchive` shortcode in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Media (5.5) | 0.25% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 29/7/2026 | 2/9/2026 | A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information. | |
| Analizada | Alta (7.1) | 0.26% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 29/7/2026 | 2/9/2026 | A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information. | |
| Analizada | Alta (7.8) | 0.28% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 29/7/2026 | 2/9/2026 | A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report configuration that allows authenticated attackers to inject arbitrary web script or HTML via the report name parameter to /Archiver/MailInsights.aspx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configuration that allows authenticated attackers to inject arbitrary web script or HTML via the configured folders parameter to /Archiver/ImportSettingsWizard.ashx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configuration that allows authenticated attackers to inject arbitrary web script or HTML via the excluded extensions parameter to /Archiver/FileArchiveAssistantWizard.aspx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuration that allows authenticated attackers to inject arbitrary web script or HTML via the SMTP server address parameter to /Archiver/GeneralSettingsWizard.aspx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 27/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the proxy server address parameter to /Archiver/CallHomeSettingsWizard.aspx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the server URL parameter to /Archiver/ImapServerWizard.aspx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/FAARetentionPolicyWizard.aspx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/RetentionPolicyWizard.aspx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration that allows authenticated attackers to inject arbitrary web script or HTML via the rule name and email criteria parameters to /Archiver/CategorizationPolicyWizard.aspx. The injected payload is… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Conexware Power ArchiverAI | 22/7/2026 | 24/7/2026 | An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe. | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle HCM Common Architecture | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HCM Common Architecture.… | |
| Pendiente de análisis | Baja (2.9) | 0.08% | — | LibarchiveAI | 21/7/2026 | 21/9/2026 | A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting… | |
| Pendiente de análisis | Baja (3.9) | 0.20% | — | LibarchiveAI | 10/7/2026 | 21/9/2026 | A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of… | |
| Pendiente de análisis | Alta (7.5) | 0.73% | — | LibarchiveAI | 30/6/2026 | 2/10/2026 | A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory… | |
| Aplazada | Media (5.4) | 0.13% | — | Sony Optical Disc ArchiveAI | 16/6/2026 | 17/6/2026 | Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulnerability is exploited, arbitrary code may be executed with SYSTEM privileges. | |
| Modificada | Alta (7.5) | 0.45% | — | Archive\ \ | 26/5/2026 | 23/7/2026 | Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value. A… | |
| Modificada | Alta (7.5) | 0.47% | — | Archive\ \ | 26/5/2026 | 24/7/2026 | Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode. A subsequent… | |
| Modificada | Crítica (9.1) | 0.43% | — | Archive\ \ | 26/5/2026 | 24/7/2026 | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file… | |
| Analizada | Media (5.1) | 0.32% | — | Simple Hierarchical Select Project Simple Hierarchical Select | 21/5/2026 | 23/7/2026 | Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper output escaping of term-derived text. Confirmed affected paths include field formatter output (shs_field_formatter_view) and term-tree child-term data generation (shs_term_get_children). Malicious taxonomy term names can… | |
| Pendiente de análisis | Alta (8.7) | 0.43% | — | Sparxsystems Enterprise ArchitectAI | 19/5/2026 | 17/6/2026 | Sparx Enterprise Architect software has a security feature that limits user's actions to those specified in the role. An authenticated attacker can modify the Enterprise Architect client behavior (e.g. using a debugger) and log in as any other user or administrator - then it is possible to do every possible change to… | |
| Analizada | Crítica (9.3) | 0.60% | — | Archivebox | 9/5/2026 | 24/7/2026 | ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddView in core/views.py) accepts a config JSON field that gets merged into the crawl config without validation. This config is exported as environment variables when archive plugins run, allowing… |