Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
3322 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.32% | — | Elated-themes Search AND GOAI | 25/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issue affects Search & Go: from n/a through <= 2.8. | |
| Analizada | Alta (8.5) | 0.13% | — | Tp-link Archer Nx600 FirmwareTp-link Archer Nx500 FirmwareTp-link Archer Nx210 FirmwareTp-link Archer Nx200 Firmware | 23/3/2026 | 17/6/2026 | A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables decryption and re-encryption of device configuration data. An authenticated attacker may decrypt configuration files, modify them, and re-encrypt them, affecting the confidentiality and integrity of… | |
| Analizada | Alta (8.5) | 0.62% | — | Tp-link Archer Nx600 FirmwareTp-link Archer Nx500 FirmwareTp-link Archer Nx210 FirmwareTp-link Archer Nx200 Firmware | 23/3/2026 | 17/6/2026 | Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be executed as part of an operating system command. An authenticated attacker with administrative privileges may execute arbitrary commands on the operating system, impacting… | |
| Analizada | Alta (8.5) | 0.62% | — | Tp-link Archer Nx600 FirmwareTp-link Archer Nx500 FirmwareTp-link Archer Nx210 FirmwareTp-link Archer Nx200 Firmware | 23/3/2026 | 17/6/2026 | Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be executed as part of an operating system command. An authenticated attacker with administrative privileges may execute arbitrary commands on the operating system, impacting… | |
| Analizada | Alta (8.6) | 3.0% | — | Tp-link Archer Nx600 FirmwareTp-link Archer Nx500 FirmwareTp-link Archer Nx210 FirmwareTp-link Archer Nx200 Firmware | 23/3/2026 | 17/6/2026 | A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated access intended for authenticated users. An attacker may perform privileged HTTP actions without authentication, including firmware upload and configuration operations. | |
| Aplazada | Media (6.8) | 0.11% | — | GsearchAI | 22/3/2026 | 17/6/2026 | GSearch 1.0.1.0 contains a denial of service vulnerability that allows local attackers to crash the application by inputting an excessively long string in the search bar. Attackers can paste a buffer of 2000 characters into the search field, click search, and select any result to trigger an application crash. | |
| Aplazada | Media (6.9) | 0.18% | — | Nsasoft Domain Name Search SoftwareAI | 22/3/2026 | 17/6/2026 | DNSS Domain Name Search Software 2.1.8 contains a buffer overflow vulnerability in the registration code input field that allows local attackers to crash the application by submitting an excessively long string. Attackers can trigger a denial of service by pasting a malicious registration code containing 300 repeated… | |
| Aplazada | Alta (8.8) | 0.44% | — | Linksy Search AND ReplaceAI | 21/3/2026 | 17/6/2026 | The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'linksy_search_and_replace_item_details' function in all versions up to, and including, 1.0.4. This makes it possible for authenticated attackers, with subscriber-level access… | |
| Analizada | Media (6.5) | 0.19% | — | Thebrowser ARC Search | 20/3/2026 | 17/6/2026 | ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content. | |
| Modificada | Alta (7.7) | 0.64% | — | Tp-link Archer Ax53 Firmware | 20/3/2026 | 12/8/2026 | This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected service to crash and, under specific conditions, may enable remote code execution… | |
| Analizada | Alta (7.3) | 2.0% | — | Tp-link Archer Ax53 Firmware | 20/3/2026 | 17/6/2026 | A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allowing log redirection to arbitrary files and concatenation of unvalidated file content into shell commands, enabling authenticated attackers to inject and execute arbitrary commands. Successful… | |
| Analizada | Media (5.7) | 0.29% | — | Elasticsearch Packetbeat | 19/3/2026 | 17/6/2026 | Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker with the ability to send specially crafted, malformed network packets to a monitored network interface can trigger out-of-bounds read… | |
| Modificada | Media (6.5) | 0.56% | — | LibarchiveRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 19/3/2026 | 1/9/2026 | A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory… | |
| Modificada | Alta (7.5) | 1.1% | — | LibarchiveRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR Arm64+3 | 19/3/2026 | 28/9/2026 | A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the… | |
| Pendiente de análisis | Alta (7.5) | 0.69% | — | LibarchiveAI | 13/3/2026 | 1/9/2026 | A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in… | |
| Aplazada | Alta (8.5) | 0.36% | — | Robfelty Collapsing ArchivesAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsing Archives collapsing-archives allows Blind SQL Injection.This issue affects Collapsing Archives: from n/a through <= 3.0.7. | |
| Analizada | Alta (7.8) | 0.31% | — | Microsoft ARC Enabled Servers Azure Connected Machine Agent | 10/3/2026 | 17/6/2026 | Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (6.1) | 0.15% | — | IBM Infosphere Data Architect | 10/3/2026 | 17/6/2026 | Affected Product(s)Version(s)InfoSphere Data Architect9.2.1 | |
| Analizada | Alta (8.5) | 1.5% | — | Tp-link Archer Axe75 Firmware | 9/3/2026 | 17/6/2026 | A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated attacker with adjacent-network access may be able to perform remote code execution (RCE) when the router is configured with sysmode=ap. Successful exploitation results in root-level privileges and… | |
| Aplazada | Media (5.5) | 0.80% | — | Unigroup Electronic Archives SystemAI | 8/3/2026 | 17/6/2026 | A vulnerability was identified in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). This issue affects some unknown processing of the file /System/Cms/downLoad. The manipulation of the argument path leads to path traversal. The attack can be initiated remotely. The exploit is publicly available and might… | |
| Aplazada | Media (4.8) | 0.36% | — | Perfopsone MailarchiverAI | 7/3/2026 | 17/6/2026 | The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Aplazada | Alta (7.5) | 0.42% | 💥 PoC | JS Archive ListAI | 7/3/2026 | 17/6/2026 | The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1.7 via the 'included' shortcode attribute. This is due to the deserialization of untrusted input supplied via the 'included' parameter of the plugin's shortcode. This makes it possible for… | |
| Aplazada | Alta (8.1) | 0.58% | — | Themerex MarcellAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Marcell marcell allows PHP Local File Inclusion.This issue affects Marcell: from n/a through <= 1.2.14. | |
| Aplazada | Alta (7.1) | 0.26% | — | Themegoods ArchitecturerAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Architecturer architecturer allows Reflected XSS.This issue affects Architecturer: from n/a through < 3.9.5. | |
| Aplazada | Crítica (9.9) | 0.45% | — | Zozothemes KeenarchAI | 5/3/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Keenarch keenarch allows Using Malicious Files.This issue affects Keenarch: from n/a through < 2.0.1. |