Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

286 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.56%💥 PoCRarlab RAR Extractor - UnarchiverAIRarlab RAR Extractor - Unarchiver PROAI21/1/202517/6/2026
An issue in RAR Extractor - Unarchiver Free and Pro v.6.4.0 allows local attackers to inject arbitrary code potentially leading to remote control and unauthorized access to sensitive user data via the exploit_combined.dylib component on MacOS.
AplazadaMedia (5.3)0.32%—Unigroup Electronic Archives SystemAI5/1/202517/6/2026
A vulnerability, which was classified as problematic, was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). This affects an unknown part of the file /Logs/Annals/downLoad.html. The manipulation of the argument path leads to information disclosure. It is possible to initiate the attack remotely.…
AplazadaMedia (5.3)0.42%—Unigroup Electronic Archives SystemAI5/1/202517/6/2026
A vulnerability, which was classified as problematic, has been found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this issue is the function download of the file /collect/PortV4/downLoad.html. The manipulation of the argument path leads to information disclosure. The attack may be…
AplazadaMedia (5.3)0.47%—Unigroup Electronic Archives SystemAI5/1/202517/6/2026
A vulnerability classified as problematic was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is an unknown functionality of the file /setting/ClassFy/exampleDownload.html. The manipulation of the argument name leads to path traversal: '/../filedir'. The attack…
AplazadaMedia (5.3)0.38%—Tsinghua Unigroup Electronic Archives Management SystemAI30/12/202417/6/2026
A vulnerability was found in Tsinghua Unigroup Electronic Archives Management System 3.2.210802(62532). It has been classified as problematic. Affected is the function download of the file /Searchnew/Subject/download.html. The manipulation of the argument path leads to information disclosure. It is possible to launch…
AplazadaAlta (8.8)2.1%💥 PoCPython-libarchiveAI12/12/202417/6/2026
python-libarchive through 4.2.1 allows directory traversal (to create files) in extract in zip.py for ZipFile.extractall and ZipFile.extract.
AnalizadaAlta (8.8)0.79%—GFI Archiver12/12/202417/6/2026
GFI Archiver Store Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is required to exploit this vulnerability. The specific flaw exists within the Store Service,…
AnalizadaCrítica (9.8)1.4%—GFI Archiver12/12/202417/6/2026
GFI Archiver Telerik Web UI Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability. The specific flaw exists within the product installer. The issue results from…
AnalizadaAlta (8.8)0.79%—GFI Archiver12/12/202417/6/2026
GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is required to exploit this vulnerability. The specific flaw exists within the Core Service,…
AnalizadaMedia (5.9)0.19%—Google Safearchive4/11/202417/6/2026
There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction containing symbolic links. We recommend upgrading past commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc
ModificadaAlta (7.8)0.55%—Libarchive10/10/202417/6/2026
execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.
AnalizadaAlta (7.8)0.51%—Libarchive10/10/202417/6/2026
execute_filter_audio in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.
AnalizadaMedia (5.4)0.26%—Robfelty Collapsing Archives29/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Robert Felty Collapsing Archives allows Stored XSS.This issue affects Collapsing Archives: from n/a through 3.0.5.
AnalizadaCrítica (9.1)0.97%—Libarchive8/6/202417/6/2026
Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled. This occurs in slurp_central_directory in archive_read_support_format_zip.c.
AplazadaMedia (5.9)0.44%—Archives Calendar WidgetAI14/5/202417/6/2026
Administrator Cross Site Scripting (XSS) in Archives Calendar Widget <= 1.0.15 versions.
AplazadaBaja (3.3)0.15%—Macpaw THE UnarchiverAI29/4/202417/6/2026
MacPaw The Unarchiver before 4.3.6 contains vulnerability related to missing quarantine attributes for extracted items.
AplazadaMedia (5.9)0.36%—Twinpictures Annual ArchiveAI26/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twinpictures Annual Archive allows Stored XSS.This issue affects Annual Archive: from n/a through 1.6.0.
AplazadaMedia (6.1)0.82%💥 PoCArchive Tainacan CollectionAI16/4/202417/6/2026
The archive-tainacan-collection theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in version 2.7.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can…
AnalizadaAlta (7.8)85%—LibarchiveFedoraproject FedoraMicrosoft Windows 11 22h2Microsoft Windows 11 23h2+19/4/202417/6/2026
Libarchive Remote Code Execution Vulnerability
AnalizadaAlta (7.8)0.93%💥 PoCMholt ArchiverRedhat Advanced Cluster SecurityRedhat Openshift Container Platform6/4/202417/6/2026
A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.
ModificadaMedia (5.5)0.36%—Munsoft Easy Archive Recovery2/2/202417/6/2026
A vulnerability classified as problematic was found in Munsoft Easy Archive Recovery 2.0. This vulnerability affects unknown code of the component Registration Key Handler. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.…
ModificadaMedia (6.5)0.51%—Qstar Archive Storage Manager13/1/202417/6/2026
An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily disable the SMB service on a victim's Qstar instance by executing a specific command in a link.
ModificadaAlta (7.5)0.55%—Qstar Archive Storage Manager13/1/202417/6/2026
An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensitive SMB settings on the QStar Server.
ModificadaMedia (5.4)0.35%—Qstar Archive Storage Manager13/1/202417/6/2026
An authenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link.
ModificadaMedia (6.1)0.41%—Qstar Archive Storage Manager13/1/202417/6/2026
An unauthenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link.
Orbitaley — Vulnerabilidades