Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

754 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.3)0.33%—B1 Free ArchiverAI29/4/202617/6/2026
A vulnerability in B1 Free Archiver v1.5.86 allows files extracted from downloaded archives to bypass Windows Mark of the Web (MotW) protections. When an archive is downloaded from the internet and extracted using B1 Free Archiver, the software fails to propagate the 'Zone.Identifier' alternate data stream to the…
AnalizadaAlta (7.5)0.44%—Oracle HCM Common Architecture21/4/202617/6/2026
Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Knowledge Integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HCM Common Architecture.…
Pendiente de análisisMedia (6.2)0.15%—Sparxsystems Enterprise ArchitectAI17/4/20267/10/2026
Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals plaintext OAuth2 client secretDesktop client decodes the secret and uses the plaintext secret to exchange it into an access and id tokens as part of the OpenID authentication flow.
AnalizadaMedia (5.7)0.11%—Sparxsystems Enterprise Architect16/4/20267/10/2026
Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication
AplazadaBaja (2.7)0.31%—Sourcecodester Online Thesis Archiving SystemAI13/4/202617/6/2026
Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in the file /otas/admin/curriculum/manage_curriculum.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Thesis Archiving SystemAI13/4/202617/6/2026
Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in /otas/projects_per_department.php.
AplazadaAlta (7.3)0.29%—Sourcecodester Online Thesis Archiving SystemAI13/4/202617/6/2026
Sourcecodester Online Thesis Archiving System v1.0 is vulnerale to SQL injection in the file /otas/view_archive.php.
ModificadaMedia (5.5)0.17%—LibarchiveRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux7/4/20261/9/2026
A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without subsequent fields), the function fails to perform adequate…
ModificadaAlta (7.5)1.4%—LibarchiveRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux30/3/202628/9/2026
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code…
AnalizadaAlta (8.6)0.21%—HNB Project Hierarchical Notebook28/3/20267/10/2026
HNB Organizer 1.9.18-10 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized argument to the -rc command-line parameter. Attackers can craft a malicious input string exceeding 108 bytes containing shellcode and a return address to overwrite the…
AplazadaAlta (8.8)0.52%—Miguel Useche JS Archive ListAI25/3/202617/6/2026
Deserialization of Untrusted Data vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows Object Injection.This issue affects JS Archive List: from n/a through <= 6.1.7.
AplazadaMedia (5.4)0.24%—Edge-themes ArchiconAI25/3/202617/6/2026
Deserialization of Untrusted Data vulnerability in Edge-Themes Archicon archicon allows Object Injection.This issue affects Archicon: from n/a through < 1.7.
ModificadaMedia (6.5)0.56%—LibarchiveRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux19/3/20261/9/2026
A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory…
ModificadaAlta (7.5)1.1%—LibarchiveRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR Arm64+319/3/202628/9/2026
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the…
Pendiente de análisisAlta (7.5)0.69%—LibarchiveAI13/3/20261/9/2026
A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in…
AplazadaAlta (8.5)0.36%—Robfelty Collapsing ArchivesAI13/3/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsing Archives collapsing-archives allows Blind SQL Injection.This issue affects Collapsing Archives: from n/a through <= 3.0.7.
AnalizadaMedia (6.1)0.15%—IBM Infosphere Data Architect10/3/202617/6/2026
Affected Product(s)Version(s)InfoSphere Data Architect9.2.1
AplazadaMedia (5.5)0.80%—Unigroup Electronic Archives SystemAI8/3/202617/6/2026
A vulnerability was identified in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). This issue affects some unknown processing of the file /System/Cms/downLoad. The manipulation of the argument path leads to path traversal. The attack can be initiated remotely. The exploit is publicly available and might…
AplazadaMedia (4.8)0.36%—Perfopsone MailarchiverAI7/3/202617/6/2026
The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject…
AplazadaAlta (7.5)0.42%💥 PoCJS Archive ListAI7/3/202617/6/2026
The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1.7 via the 'included' shortcode attribute. This is due to the deserialization of untrusted input supplied via the 'included' parameter of the plugin's shortcode. This makes it possible for…
AplazadaAlta (7.1)0.26%—Themegoods ArchitecturerAI5/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Architecturer architecturer allows Reflected XSS.This issue affects Architecturer: from n/a through < 3.9.5.
AplazadaMedia (4.9)0.45%—Perfopsone MailarchiverAI27/2/202617/6/2026
The MailArchiver plugin for WordPress is vulnerable to SQL Injection via the ‘logid’ parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with…
AnalizadaCrítica (9.8)0.69%—GFI Archiver20/2/202617/6/2026
GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the…
AnalizadaCrítica (9.8)0.66%—GFI Archiver20/2/202617/6/2026
GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the…
AnalizadaAlta (8.8)1.2%—GFI Archiver20/2/202617/6/2026
GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be…
Orbitaley — Vulnerabilidades