Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

54 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)1.4%—GFI Archiver12/12/202417/6/2026
GFI Archiver Telerik Web UI Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability. The specific flaw exists within the product installer. The issue results from…
AnalizadaAlta (8.8)0.79%—GFI Archiver12/12/202417/6/2026
GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is required to exploit this vulnerability. The specific flaw exists within the Core Service,…
AplazadaBaja (3.3)0.15%—Macpaw THE UnarchiverAI29/4/202417/6/2026
MacPaw The Unarchiver before 4.3.6 contains vulnerability related to missing quarantine attributes for extracted items.
AnalizadaAlta (7.8)0.93%💥 PoCMholt ArchiverRedhat Advanced Cluster SecurityRedhat Openshift Container Platform6/4/202417/6/2026
A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.
ModificadaMedia (6.1)0.46%—Perfopsone Mailarchiver30/8/202317/6/2026
The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute…
ModificadaCrítica (9.8)2.5%💥 PoCCodehaus-plexus Plexus-archiver25/7/202317/6/2026
Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified `Archiver`/`UnArchiver` API. Prior to version 4.8.0, using AbstractUnArchiver for extracting an archive might lead to an arbitrary file creation and possibly remote code execution. When extracting…
ModificadaCrítica (9.1)1.2%—Cloudfoundry Archiver27/12/202217/6/2026
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
ModificadaCrítica (9.8)2.6%—GFI Archiver7/7/202217/6/2026
File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which is affected by CVE-2014-2217, and CVE-2017-11317.
ModificadaMedia (4.3)0.92%—Powerarchiver21/6/202117/6/2026
The XML parser used in ConeXware PowerArchiver before 20.10.02 allows processing of external entities, which might lead to exfiltration of local files over the network (via an XXE attack).
ModificadaMedia (5.5)6.4%💥 PoCArchiver Project Archiver29/10/201917/6/2026
All versions of archiver allow attacker to perform a Zip Slip attack via the "unarchive" functions. It is exploited using a specially crafted zip archive, that holds path traversal filenames. When exploited, a filename in a malicious archive is concatenated to the target extraction directory, which results in the…
ModificadaMedia (6.1)2.3%💥 ExploitHeidelberg Prinect Archiver24/5/201917/6/2026
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0.
ModificadaMedia (6.1)0.69%—Barracuda Message Archiver23/12/201817/6/2026
Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry.cgi module. The injection point of the issue is the Add_Update module.
ModificadaMedia (5.5)2.5%—Archiver Project Archiver25/7/201817/6/2026
mholt/archiver golang package before e4ef56d48eb029648b0e895bb0b6a393ef0829c3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
ModificadaMedia (5.5)12%💥 PoCCodehaus-plexus Plexus-archiverDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+125/7/201817/6/2026
plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
ModificadaAlta (7.5)5.8%—Debian LinuxFedoraproject FedoraARJ Software ARJ Archiver8/4/201517/6/2026
Buffer overflow in Open-source ARJ archiver 3.10.22 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ARJ archive.
ModificadaMedia (5.8)3.3%—ARJ Software ARJ ArchiverFedoraproject Fedora8/4/201517/6/2026
Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive.
ModificadaMedia (5.8)3.8%—ARJ Software ARJ ArchiverFedoraproject Fedora8/4/201517/6/2026
Open-source ARJ archiver 3.10.22 allows remote attackers to conduct directory traversal attacks via a symlink attack in an ARJ archive.
ModificadaMedia (6.9)0.64%—Hamstersoft Hamster Free ZIP Archiver23/10/201417/6/2026
Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the current working directory.
ModificadaAlta (9.3)11%💥 ExploitPowersoftware Winarchiver25/4/201416/6/2026
Buffer overflow in Power Software WinArchiver 3.2 allows remote attackers to execute arbitrary code via a crafted .zip file.
ModificadaMedia (5)0.76%—Powerarchiver14/3/201417/6/2026
The Encrypt Files feature in ConeXware PowerArchiver before 14.02.05 uses legacy ZIP encryption even if the AES 256-bit selection is chosen, which makes it easier for context-dependent attackers to obtain sensitive information via a known-plaintext attack.
ModificadaBaja (3.5)1.5%—Barracuda Networks Barracuda IM FirewallBarracuda Networks Barracuda Load BalancerBarracuda Networks Barracuda Message ArchiverBarracuda Networks Barracuda Spam Firewall+119/12/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in Barracuda Spam Firewall (BSF) before 3.5.12.007, Message Archiver before 1.2.1.002, Web Filter before 3.3.0.052, IM Firewall before 3.1.01.017, and Load Balancer before 2.3.024 allow remote attackers to inject arbitrary web script or HTML via (1) the…
ModificadaAlta (9.3)4.8%—Conexware Powerarchiver9/10/200716/6/2026
Heap-based buffer overflow in ConeXware PowerArchiver before 10.20.21 might allow remote attackers to execute arbitrary code via a long filename in a BlackHole archive.
ModificadaAlta (9.3)4.6%—Wakwak Lhaca File Archiver3/7/200716/6/2026
Stack-based buffer overflow in Lhaca File Archiver before 1.22 allows user-assisted remote attackers to execute arbitrary code via a large LHA "Extended Header Size" value in an LZH archive, a different issue than CVE-2007-3375.
ModificadaMedia (6.8)4.7%—Lhaca File Archiver25/6/200716/6/2026
Stack-based buffer overflow in Lhaca File Archiver before 1.21 allows user-assisted remote attackers to execute arbitrary code via a crafted LZH archive, as exploited by malware such as Trojan.Lhdropper.
ModificadaAlta (9.3)3.5%—Conexware Powerarchiver 20065/1/200716/6/2026
Multiple stack-based buffer overflows in the (1) LoadTree and (2) ReadHeader functions in PAISO.DLL 1.7.3.0 (1.7.3 beta) in ConeXware PowerArchiver 2006 9.64.02 allow user-assisted attackers to execute arbitrary code via a crafted ISO file containing a file within several nested directories.
Orbitaley — Vulnerabilidades