Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
3322 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.24% | — | Dani-garcia Vaultwarden | 4/3/2026 | 17/6/2026 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, an authenticated regular user can specify another user’s cipher_id and call "PUT /api/ciphers/{id}/partial" Even though the standard retrieval API correctly denies access to that cipher,… | |
| Analizada | Alta (8.3) | 0.39% | — | Dani-garcia Vaultwarden | 4/3/2026 | 17/6/2026 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=false for a given collection, they can still perform several management operations as long as they have access to the collection. This issue has been patched in… | |
| Analizada | Alta (8.3) | 0.39% | — | Dani-garcia Vaultwarden | 4/3/2026 | 17/6/2026 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privilege escalation vulnerability via bulk permission update to unauthorized collections by Manager. This issue has been patched in version 1.35.4. | |
| Analizada | Media (6) | 0.25% | — | Dani-garcia Vaultwarden | 4/3/2026 | 17/6/2026 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden versions 1.34.3 and prior are susceptible to a 2FA bypass when performing protected actions. An attacker who gains authenticated access to a user’s account can exploit this bypass to perform protected… | |
| Analizada | Media (6.3) | 0.11% | — | Nozominetworks ARC | 4/3/2026 | 17/6/2026 | The server certificate was not verified when an Arc agent connected to a Guardian or CMC. A malicious actor could perform a man-in-the-middle attack and intercept the communication between the Arc agent and the Guardian or CMC. This could result in theft of the client token and sensitive information (such as assets… | |
| Modificada | Alta (7.2) | 0.44% | — | Oretnom23 Simple Logistic HUB Parcel's Management System | 3/3/2026 | 17/6/2026 | Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_carrier.php. | |
| Analizada | Baja (2.7) | 0.34% | — | Oretnom23 Simple Logistic HUB Parcel's Management System | 3/3/2026 | 17/6/2026 | Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_parcel_type.php. | |
| Aplazada | Media (4.9) | 0.45% | — | Perfopsone MailarchiverAI | 27/2/2026 | 17/6/2026 | The MailArchiver plugin for WordPress is vulnerable to SQL Injection via the ‘logid’ parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (7.5) | 0.71% | — | Elasticsearch Packetbeat | 26/2/2026 | 17/6/2026 | Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can send a specially crafted packet causing a Go runtime panic that terminates the Packetbeat process. This vulnerability requires the pgsql… | |
| Analizada | Media (5.3) | 0.21% | — | Arcinfo Pcvue | 26/2/2026 | 9/7/2026 | A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject harmful payloads that manipulate server-side behavior. This vulnerability only affects the endpoints /Authentication/ExternalLogin,… | |
| Analizada | Media (5.3) | 0.12% | — | Arcinfo Pcvue | 26/2/2026 | 9/7/2026 | The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included. | |
| Analizada | Baja (2.3) | 0.15% | — | Arcinfo Pcvue | 26/2/2026 | 9/7/2026 | Some HTTP security headers are not properly set by the web server when sending responses to the client application. | |
| Analizada | Media (5.3) | 0.21% | — | Arcinfo Pcvue | 26/2/2026 | 9/7/2026 | An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to trick a legitimate user into loading content from another site upon unsuccessful user authentication on an unknown… | |
| Analizada | Baja (2.3) | 0.17% | — | Arcinfo Pcvue | 26/2/2026 | 9/7/2026 | HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of the webservices used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It unnecessarily exposes sensitive information about the server… | |
| Analizada | Media (5.3) | 0.32% | — | Arcinfo Pcvue | 26/2/2026 | 9/7/2026 | The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being deprecated. It might allow a remote attacker to steal user credentials. | |
| Analizada | Media (5.3) | 0.11% | — | Arcinfo Pcvue | 26/2/2026 | 9/7/2026 | A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to lure a successfully authenticated user to a malicious website. This… | |
| Analizada | Crítica (9.8) | 0.69% | — | GFI Archiver | 20/2/2026 | 17/6/2026 | GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the… | |
| Analizada | Crítica (9.8) | 0.66% | — | GFI Archiver | 20/2/2026 | 17/6/2026 | GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the… | |
| Analizada | Alta (8.8) | 1.2% | — | GFI Archiver | 20/2/2026 | 17/6/2026 | GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be… | |
| Analizada | Alta (8.8) | 1.2% | — | GFI Archiver | 20/2/2026 | 17/6/2026 | GFI Archiver MArc.Store Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be… | |
| Aplazada | Alta (7.1) | 0.18% | — | Peterwsterling Simple Archive GeneratorAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in peterwsterling Simple Archive Generator simple-archive-generator allows Reflected XSS.This issue affects Simple Archive Generator: from n/a through <= 5.2. | |
| Aplazada | Alta (7.6) | 0.29% | — | Yoren Chang Media Search EnhancedAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yoren Chang Media Search Enhanced media-search-enhanced allows SQL Injection.This issue affects Media Search Enhanced: from n/a through <= 0.9.1. | |
| Analizada | Media (5.5) | 0.72% | — | Unigroup Electronic Archives System | 19/2/2026 | 17/6/2026 | A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted element is an unknown function of the file /Archive/ErecordManage/uploadFile.html. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be launched remotely. The… | |
| Analizada | Baja (2.1) | 0.71% | — | Unigroup Electronic Archives System | 18/2/2026 | 17/6/2026 | A vulnerability was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). The affected element is an unknown function of the file /Using/Subject/downLoad.html. Performing a manipulation of the argument path results in path traversal. The attack may be initiated remotely. The exploit has been made… | |
| Analizada | Baja (2.1) | 0.52% | — | Unigroup Electronic Archives System | 18/2/2026 | 17/6/2026 | A vulnerability has been found in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). Impacted is an unknown function of the file /mine/PublicReport/prinReport.html?token=java. Such manipulation of the argument comid leads to sql injection. The attack can be launched remotely. The exploit has been… |