Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
54 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 1.4% | — | GFI Archiver | 12/12/2024 | 17/6/2026 | GFI Archiver Telerik Web UI Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability. The specific flaw exists within the product installer. The issue results from… | |
| Analizada | Alta (8.8) | 0.79% | — | GFI Archiver | 12/12/2024 | 17/6/2026 | GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is required to exploit this vulnerability. The specific flaw exists within the Core Service,… | |
| Aplazada | Baja (3.3) | 0.15% | — | Macpaw THE UnarchiverAI | 29/4/2024 | 17/6/2026 | MacPaw The Unarchiver before 4.3.6 contains vulnerability related to missing quarantine attributes for extracted items. | |
| Analizada | Alta (7.8) | 0.93% | 💥 PoC | Mholt ArchiverRedhat Advanced Cluster SecurityRedhat Openshift Container Platform | 6/4/2024 | 17/6/2026 | A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library. | |
| Modificada | Media (6.1) | 0.46% | — | Perfopsone Mailarchiver | 30/8/2023 | 17/6/2026 | The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Crítica (9.8) | 2.5% | 💥 PoC | Codehaus-plexus Plexus-archiver | 25/7/2023 | 17/6/2026 | Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified `Archiver`/`UnArchiver` API. Prior to version 4.8.0, using AbstractUnArchiver for extracting an archive might lead to an arbitrary file creation and possibly remote code execution. When extracting… | |
| Modificada | Crítica (9.1) | 1.2% | — | Cloudfoundry Archiver | 27/12/2022 | 17/6/2026 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | |
| Modificada | Crítica (9.8) | 2.6% | — | GFI Archiver | 7/7/2022 | 17/6/2026 | File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which is affected by CVE-2014-2217, and CVE-2017-11317. | |
| Modificada | Media (4.3) | 0.92% | — | Powerarchiver | 21/6/2021 | 17/6/2026 | The XML parser used in ConeXware PowerArchiver before 20.10.02 allows processing of external entities, which might lead to exfiltration of local files over the network (via an XXE attack). | |
| Modificada | Media (5.5) | 6.4% | 💥 PoC | Archiver Project Archiver | 29/10/2019 | 17/6/2026 | All versions of archiver allow attacker to perform a Zip Slip attack via the "unarchive" functions. It is exploited using a specially crafted zip archive, that holds path traversal filenames. When exploited, a filename in a malicious archive is concatenated to the target extraction directory, which results in the… | |
| Modificada | Media (6.1) | 2.3% | 💥 Exploit | Heidelberg Prinect Archiver | 24/5/2019 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0. | |
| Modificada | Media (6.1) | 0.69% | — | Barracuda Message Archiver | 23/12/2018 | 17/6/2026 | Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry.cgi module. The injection point of the issue is the Add_Update module. | |
| Modificada | Media (5.5) | 2.5% | — | Archiver Project Archiver | 25/7/2018 | 17/6/2026 | mholt/archiver golang package before e4ef56d48eb029648b0e895bb0b6a393ef0829c3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'. | |
| Modificada | Media (5.5) | 12% | 💥 PoC | Codehaus-plexus Plexus-archiverDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+1 | 25/7/2018 | 17/6/2026 | plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'. | |
| Modificada | Alta (7.5) | 5.8% | — | Debian LinuxFedoraproject FedoraARJ Software ARJ Archiver | 8/4/2015 | 17/6/2026 | Buffer overflow in Open-source ARJ archiver 3.10.22 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ARJ archive. | |
| Modificada | Media (5.8) | 3.3% | — | ARJ Software ARJ ArchiverFedoraproject Fedora | 8/4/2015 | 17/6/2026 | Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive. | |
| Modificada | Media (5.8) | 3.8% | — | ARJ Software ARJ ArchiverFedoraproject Fedora | 8/4/2015 | 17/6/2026 | Open-source ARJ archiver 3.10.22 allows remote attackers to conduct directory traversal attacks via a symlink attack in an ARJ archive. | |
| Modificada | Media (6.9) | 0.64% | — | Hamstersoft Hamster Free ZIP Archiver | 23/10/2014 | 17/6/2026 | Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the current working directory. | |
| Modificada | Alta (9.3) | 11% | 💥 Exploit | Powersoftware Winarchiver | 25/4/2014 | 16/6/2026 | Buffer overflow in Power Software WinArchiver 3.2 allows remote attackers to execute arbitrary code via a crafted .zip file. | |
| Modificada | Media (5) | 0.76% | — | Powerarchiver | 14/3/2014 | 17/6/2026 | The Encrypt Files feature in ConeXware PowerArchiver before 14.02.05 uses legacy ZIP encryption even if the AES 256-bit selection is chosen, which makes it easier for context-dependent attackers to obtain sensitive information via a known-plaintext attack. | |
| Modificada | Baja (3.5) | 1.5% | — | Barracuda Networks Barracuda IM FirewallBarracuda Networks Barracuda Load BalancerBarracuda Networks Barracuda Message ArchiverBarracuda Networks Barracuda Spam Firewall+1 | 19/12/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in Barracuda Spam Firewall (BSF) before 3.5.12.007, Message Archiver before 1.2.1.002, Web Filter before 3.3.0.052, IM Firewall before 3.1.01.017, and Load Balancer before 2.3.024 allow remote attackers to inject arbitrary web script or HTML via (1) the… | |
| Modificada | Alta (9.3) | 4.8% | — | Conexware Powerarchiver | 9/10/2007 | 16/6/2026 | Heap-based buffer overflow in ConeXware PowerArchiver before 10.20.21 might allow remote attackers to execute arbitrary code via a long filename in a BlackHole archive. | |
| Modificada | Alta (9.3) | 4.6% | — | Wakwak Lhaca File Archiver | 3/7/2007 | 16/6/2026 | Stack-based buffer overflow in Lhaca File Archiver before 1.22 allows user-assisted remote attackers to execute arbitrary code via a large LHA "Extended Header Size" value in an LZH archive, a different issue than CVE-2007-3375. | |
| Modificada | Media (6.8) | 4.7% | — | Lhaca File Archiver | 25/6/2007 | 16/6/2026 | Stack-based buffer overflow in Lhaca File Archiver before 1.21 allows user-assisted remote attackers to execute arbitrary code via a crafted LZH archive, as exploited by malware such as Trojan.Lhdropper. | |
| Modificada | Alta (9.3) | 3.5% | — | Conexware Powerarchiver 2006 | 5/1/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the (1) LoadTree and (2) ReadHeader functions in PAISO.DLL 1.7.3.0 (1.7.3 beta) in ConeXware PowerArchiver 2006 9.64.02 allow user-assisted attackers to execute arbitrary code via a crafted ISO file containing a file within several nested directories. |