Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.32% | — | HCL HiveAI | 24/8/2026 | 28/8/2026 | HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code directly into production environments. | |
| Aplazada | Media (5.3) | 0.15% | — | HCL Hive Keycloak IAMAI | 24/8/2026 | 29/9/2026 | HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources. | |
| Analizada | Media (6.3) | 0.32% | — | Zenhive Machine Payments Protocol | 19/8/2026 | 10/9/2026 | Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote client to redeem one confirmed on-chain payment for multiple paid-resource accesses. The type="hash" credential path in MPP.Methods.Tempo.verify/2 guards against replay with a non-atomic check-then-mark sequence:… | |
| Analizada | Alta (8.3) | 0.59% | — | Zenhive Machine Payments Protocol | 19/8/2026 | 10/9/2026 | Allocation of Resources Without Limits or Throttling in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet through concurrent sponsored payments, denying service to legitimate payers once it is empty. MPP.Methods.Tempo.FeePayerPolicy enforces its ceilings (max_gas, max_fee_per_gas,… | |
| Analizada | Alta (8.2) | 0.60% | — | Zenhive Machine Payments Protocol | 19/8/2026 | 10/9/2026 | Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated third party to obtain paid resources by replaying a transfer settled by an unrelated payer. MPP.Methods.Tempo normally binds a settled TIP-20 TransferWithMemo to the specific challenge under verification through an attribution nonce… | |
| Analizada | Alta (8.7) | 0.60% | — | Zenhive Machine Payments Protocol | 19/8/2026 | 10/9/2026 | Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to obtain paid resources by resubmitting one settled on-chain transfer. MPP.Methods.EVM.verify/2 accepts a transaction-hash credential and matches a transfer purely on token, to and amount (ERC-20) or to and value (native).… | |
| Pendiente de análisis | Alta (7.1) | 0.44% | 💥 PoC | Moby Go-archiveAI | 18/8/2026 | 28/8/2026 | The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a… | |
| Aplazada | Media (6.4) | 0.35% | — | Simple Yearly ArchiveAI | 5/8/2026 | 12/8/2026 | The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `posttype` attribute of the `SimpleYearlyArchive` shortcode in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report configuration that allows authenticated attackers to inject arbitrary web script or HTML via the report name parameter to /Archiver/MailInsights.aspx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configuration that allows authenticated attackers to inject arbitrary web script or HTML via the configured folders parameter to /Archiver/ImportSettingsWizard.ashx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configuration that allows authenticated attackers to inject arbitrary web script or HTML via the excluded extensions parameter to /Archiver/FileArchiveAssistantWizard.aspx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuration that allows authenticated attackers to inject arbitrary web script or HTML via the SMTP server address parameter to /Archiver/GeneralSettingsWizard.aspx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 27/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the proxy server address parameter to /Archiver/CallHomeSettingsWizard.aspx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the server URL parameter to /Archiver/ImapServerWizard.aspx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/FAARetentionPolicyWizard.aspx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/RetentionPolicyWizard.aspx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration that allows authenticated attackers to inject arbitrary web script or HTML via the rule name and email criteria parameters to /Archiver/CategorizationPolicyWizard.aspx. The injected payload is… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Conexware Power ArchiverAI | 22/7/2026 | 24/7/2026 | An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe. | |
| Pendiente de análisis | Baja (2.9) | 0.08% | — | LibarchiveAI | 21/7/2026 | 21/9/2026 | A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting… | |
| Aplazada | Alta (7.1) | 0.35% | — | Strangebee ThehiveAI | 17/7/2026 | 17/7/2026 | TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints that allows any authenticated user to access attachments belonging to other organizations by supplying a content-hash identifier. Attackers can exploit the missing organization-scoped authorization… | |
| Analizada | Media (6.9) | 0.45% | — | Strangebee Thehive | 17/7/2026 | 30/7/2026 | TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a GET request to the /api/status endpoint, which lacks authentication enforcement in the StatusCtrl.scala handler. Attackers can obtain the… | |
| Aplazada | Alta (8.3) | 0.52% | — | Zenhive MPPAI | 17/7/2026 | 17/7/2026 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet in a single request by naming an arbitrarily high gas price. When the mpp Elixir library is configured as fee payer (fee_payer: true), MPP.Tempo.Transaction.cosign_fee_payer/3… | |
| Aplazada | Alta (8.3) | 0.52% | — | Zenhive MPPAI | 17/7/2026 | 17/7/2026 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per payment by a large multiplier, degrading the sponsor's operating margin. When the mpp Elixir library is configured as fee payer (fee_payer: true),… | |
| Aplazada | Alta (8.2) | 0.63% | — | Zenhive MPPAI | 17/7/2026 | 17/7/2026 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet, resulting in denial of service for legitimate clients. When the mpp Elixir library is configured as fee payer (fee_payer: true), the MPP.Methods.Tempo payment method co-signs and… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wp-property-hive PropertyhiveAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Reflected XSS.This issue affects PropertyHive: from n/a through <= 2.2.3. |