Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (3.9) | 0.20% | — | LibarchiveAI | 10/7/2026 | 21/9/2026 | A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of… | |
| Aplazada | Media (4.9) | 0.48% | — | Wp-property-hive Houzez Property FeedAI | 2/7/2026 | 2/7/2026 | The Houzez Property Feed plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 2.5.46 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the prepare_items() method of the… | |
| Pendiente de análisis | Alta (7.5) | 0.73% | — | LibarchiveAI | 30/6/2026 | 2/10/2026 | A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory… | |
| Aplazada | Media (5.4) | 0.13% | — | Sony Optical Disc ArchiveAI | 16/6/2026 | 17/6/2026 | Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulnerability is exploited, arbitrary code may be executed with SYSTEM privileges. | |
| Pendiente de análisis | Alta (8.1) | 0.27% | — | HCL Hive Telco ObservabilityAIKeycloakAI | 4/6/2026 | 22/7/2026 | HCL Hive Telco Observability is affected by a Required directives missing from the CSP issue is detected in keycloak component of the web application. Missing essential directives can leave a site vulnerable. | |
| Aplazada | Media (4.3) | 0.27% | — | Dearhive DearflipAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in DearHive DearFlip allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects DearFlip: from n/a through 2.4.27. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wp-property-hive PropertyhiveAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows DOM-Based XSS.This issue affects PropertyHive: from n/a through <= 2.2.2. | |
| Modificada | Alta (7.5) | 0.45% | — | Archive\ \ | 26/5/2026 | 23/7/2026 | Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value. A… | |
| Modificada | Alta (7.5) | 0.47% | — | Archive\ \ | 26/5/2026 | 24/7/2026 | Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode. A subsequent… | |
| Modificada | Crítica (9.1) | 0.43% | — | Archive\ \ | 26/5/2026 | 24/7/2026 | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file… | |
| Analizada | Media (5.5) | 0.98% | — | Adenhq Hive | 17/5/2026 | 17/6/2026 | A vulnerability was found in adenhq hive up to 0.11.0. This affects the function _read_events_tail of the file core/framework/server/routes_sessions.py of the component Delete Request Handler. Performing a manipulation results in path traversal. The attack may be initiated remotely. The exploit has been made public… | |
| Analizada | Crítica (9.3) | 0.60% | — | Archivebox | 9/5/2026 | 24/7/2026 | ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddView in core/views.py) accepts a config JSON field that gets merged into the crawl config without validation. This config is exported as environment variables when archive plugins run, allowing… | |
| Pendiente de análisis | Media (5.9) | 0.41% | — | Papercut HiveAI | 5/5/2026 | 17/6/2026 | An issue was discovered in the PaperCut Hive Ricoh embedded application. When the "Deep Logging" (diagnostic) mode is enabled, the application inadvertently records administrative credentials in plain text within the log files. An attacker with administrative access to the PaperCut Hive management portal could… | |
| Pendiente de análisis | Alta (7.3) | 0.33% | — | B1 Free ArchiverAI | 29/4/2026 | 17/6/2026 | A vulnerability in B1 Free Archiver v1.5.86 allows files extracted from downloaded archives to bypass Windows Mark of the Web (MotW) protections. When an archive is downloaded from the internet and extracted using B1 Free Archiver, the software fails to propagate the 'Zone.Identifier' alternate data stream to the… | |
| Modificada | Media (5.5) | 0.17% | — | LibarchiveRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 7/4/2026 | 1/9/2026 | A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without subsequent fields), the function fails to perform adequate… | |
| Modificada | Alta (7.5) | 1.4% | — | LibarchiveRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 30/3/2026 | 28/9/2026 | A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code… | |
| Aplazada | Alta (8.8) | 0.52% | — | Miguel Useche JS Archive ListAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows Object Injection.This issue affects JS Archive List: from n/a through <= 6.1.7. | |
| Modificada | Media (6.5) | 0.56% | — | LibarchiveRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 19/3/2026 | 1/9/2026 | A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory… | |
| Modificada | Alta (7.5) | 1.1% | — | LibarchiveRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR Arm64+3 | 19/3/2026 | 28/9/2026 | A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the… | |
| Pendiente de análisis | Alta (7.5) | 0.69% | — | LibarchiveAI | 13/3/2026 | 1/9/2026 | A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in… | |
| Aplazada | Alta (8.5) | 0.36% | — | Robfelty Collapsing ArchivesAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsing Archives collapsing-archives allows Blind SQL Injection.This issue affects Collapsing Archives: from n/a through <= 3.0.7. | |
| Modificada | Crítica (9.3) | 1.0% | — | Blackbeartechhive Atop Ehg2408 FirmwareBlackbeartechhive Atop Ehg2408-2sfp Firmware | 9/3/2026 | 7/7/2026 | EHG2408 series switch developed by Atop Technologies has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code. | |
| Aplazada | Media (5.5) | 0.80% | — | Unigroup Electronic Archives SystemAI | 8/3/2026 | 17/6/2026 | A vulnerability was identified in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). This issue affects some unknown processing of the file /System/Cms/downLoad. The manipulation of the argument path leads to path traversal. The attack can be initiated remotely. The exploit is publicly available and might… | |
| Aplazada | Media (4.8) | 0.36% | — | Perfopsone MailarchiverAI | 7/3/2026 | 17/6/2026 | The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Aplazada | Alta (7.5) | 0.42% | 💥 PoC | JS Archive ListAI | 7/3/2026 | 17/6/2026 | The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1.7 via the 'included' shortcode attribute. This is due to the deserialization of untrusted input supplied via the 'included' parameter of the plugin's shortcode. This makes it possible for… |