Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
286 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.73% | — | Hack Repair GUY Plugin ArchiverAI | 12/9/2025 | 17/6/2026 | The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the prepare_items function in all versions up to, and including, 2.0.4. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Aplazada | Crítica (9.4) | 1.5% | — | InternetarchiveAI | 6/9/2025 | 17/6/2026 | internetarchive is a Python and Command-Line Interface to Archive.org In versions 5.5.0 and below, there is a directory traversal (path traversal) vulnerability in the File.download() method of the internetarchive library. The file.download() method does not properly sanitize user-supplied filenames or validate the… | |
| Aplazada | Media (6.5) | 0.21% | — | Eric Mann WP Publication ArchiveAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric Mann WP Publication Archive wp-publication-archive allows Stored XSS.This issue affects WP Publication Archive : from n/a through <= 3.0.1. | |
| Aplazada | Crítica (9.3) | 1.5% | 💥 Exploit | Miguel Useche JS Archive ListAIJquery Archive List WidgetAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows SQL Injection.This issue affects JS Archive List: from n/a through < 6.1.6. | |
| Aplazada | Alta (7.5) | 0.50% | — | JS Archive ListAI | 19/8/2025 | 17/6/2026 | The JS Archive List plugin for WordPress is vulnerable to time-based SQL Injection via the build_sql_where() function in all versions up to, and including, 6.1.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Analizada | Media (6.1) | 0.25% | — | Barracuda Message Archiver Firmware | 30/7/2025 | 17/6/2026 | the BMA login interface allows arbitrary JavaScript or HTML to be written straight into the page’s Document Object Model via the error= URL parameter | |
| Aplazada | Alta (7.1) | 0.45% | — | Aveva PI Data ArchiveAI | 12/6/2025 | 17/6/2026 | AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI Data Archive subsystems, resulting in a denial of service. Depending on the timing of the crash, data present in snapshots/write cache may be lost. | |
| Aplazada | Alta (7.1) | 0.39% | — | Aveva PI Data ArchiveAI | 12/6/2025 | 17/6/2026 | AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI Data Archive subsystems, resulting in a denial of service. | |
| Aplazada | Crítica (9.8) | 0.41% | — | Archive Unzip BurstAIInfozipAI | 12/6/2025 | 17/6/2026 | Archive::Unzip::Burst from 0.01 through 0.09 for Perl contains a bundled InfoZip library that is affected by several vulnerabilities. The bundled library is affected by CVE-2014-8139, CVE-2014-8140 and CVE-2014-8141. | |
| Aplazada | Alta (8.1) | 0.38% | — | ArchiverspaapiAI | 10/6/2025 | 17/6/2026 | The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated remote attacker can generate and use a verifiable JWT token to access protected ArchiverSpaApi URL endpoints. | |
| Analizada | Media (6.6) | 0.37% | — | LibarchiveRedhat Openshift Container PlatformRedhat Enterprise Linux | 9/6/2025 | 1/9/2026 | A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a… | |
| Modificada | Media (5) | 0.20% | — | LibarchiveRedhat Openshift Container PlatformRedhat Enterprise Linux | 9/6/2025 | 1/9/2026 | A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior,… | |
| Modificada | Media (5.6) | 0.18% | — | LibarchiveRedhat Openshift Container PlatformRedhat Enterprise Linux | 9/6/2025 | 1/9/2026 | A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading… | |
| Modificada | Media (6.6) | 0.19% | 💥 PoC | LibarchiveRedhat Openshift Container PlatformRedhat Enterprise Linux | 9/6/2025 | 1/9/2026 | A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in… | |
| Modificada | Alta (7.8) | 0.44% | — | LibarchiveRedhat Openshift Container PlatformRedhat Enterprise Linux | 9/6/2025 | 7/10/2026 | A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker… | |
| Analizada | Media (4.3) | 0.17% | — | Philipwalton Simple NAV Archives | 15/5/2025 | 17/6/2026 | The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Analizada | Alta (8.8) | 0.25% | — | Artec-it Enterprise Mail Archive | 12/5/2025 | 17/6/2026 | ARTEC EMA Mail 6.92 allows CSRF. | |
| Analizada | Media (4.9) | 0.45% | ⚠ Explotación activa | Telemessage Text Message Archiver | 8/5/2025 | 17/6/2026 | The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild… | |
| Aplazada | Alta (8.1) | 0.50% | — | Mholt ArchiverAI | 13/4/2025 | 17/6/2026 | A Path Traversal "Zip Slip" vulnerability has been identified in mholt/archiver in Go. This vulnerability allows using a crafted ZIP file containing path traversal symlinks to create or overwrite files with the user's privileges or application utilizing the library. When using the archiver.Unarchive functionality with… | |
| Analizada | Alta (7.5) | 0.53% | — | Libarchive | 28/3/2025 | 17/6/2026 | Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8. | |
| Analizada | Alta (7.8) | 0.37% | — | Libarchive | 2/3/2025 | 17/6/2026 | list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale. | |
| Aplazada | Media (6.5) | 0.27% | — | Alobaidi Archive PageAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alobaidi Archive Page archive-page allows DOM-Based XSS.This issue affects Archive Page: from n/a through <= 1.0.2. | |
| Analizada | Media (4.8) | 0.34% | — | Libarchive | 24/2/2025 | 17/6/2026 | A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The… | |
| Analizada | Crítica (9.8) | 0.64% | — | Keesiemeijer Custom Post Type Date Archives | 22/2/2025 | 17/6/2026 | The The Custom Post Type Date Archives plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.7.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for… | |
| Aplazada | Media (4) | 0.25% | — | LibarchiveAI | 16/2/2025 | 17/6/2026 | libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname. |