Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
286 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.5% | — | Qstar Archive Storage Manager | 13/1/2024 | 17/6/2026 | An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily execute commands. | |
| Modificada | Alta (7.5) | 0.65% | — | Qstar Archive Storage Manager | 13/1/2024 | 17/6/2026 | Incorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to obtain system backups and other sensitive information from the QStar Server. | |
| Modificada | Media (6.1) | 0.38% | — | Qstar Archive Storage Manager | 13/1/2024 | 17/6/2026 | QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based reflected XSS vulnerability within the component qnme-ajax?method=tree_table. | |
| Modificada | Alta (8.8) | 0.32% | — | Qstar Archive Storage Manager | 13/1/2024 | 17/6/2026 | QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based Reflected Cross Site Scripting (XSS) vulnerability within the component qnme-ajax?method=tree_level. | |
| Modificada | Media (5.3) | 0.50% | — | Qstar Archive Storage Manager | 13/1/2024 | 17/6/2026 | An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0 allows attackers to disclose the SMB Log contents via executing a crafted command. | |
| Modificada | Media (5.4) | 0.39% | — | Twinpictures Annual Archive | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twinpictures Annual Archive allows Stored XSS.This issue affects Annual Archive: from n/a through 1.6.0. | |
| Modificada | Media (6.1) | 0.29% | — | Ericteubert Archivist - Custom Archive Templates | 27/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.5 versions. | |
| Modificada | Media (5.4) | 0.41% | — | Osmansorkar Ajax Archive Calendar | 25/10/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Osmansorkar Ajax Archive Calendar plugin <= 2.6.7 versions. | |
| Modificada | Media (5.4) | 0.68% | — | Archivebox | 19/10/2023 | 7/7/2026 | ArchiveBox is an open source self-hosted web archiving system. Any users who are using the `wget` extractor and view the content it outputs. The impact is potentially severe if you are logged in to the ArchiveBox admin site in the same browser session and view an archived malicious page designed to target your… | |
| Modificada | Alta (7.8) | 0.37% | — | Archive Project Archive | 30/8/2023 | 17/6/2026 | An issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file. | |
| Modificada | Alta (7.8) | 0.35% | — | Archive Project Archive | 30/8/2023 | 17/6/2026 | An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing. | |
| Modificada | Media (5.5) | 0.37% | — | Ziparchive Project Ziparchive | 30/8/2023 | 17/6/2026 | An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file. | |
| Modificada | Media (6.1) | 0.46% | — | Perfopsone Mailarchiver | 30/8/2023 | 17/6/2026 | The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Crítica (9.8) | 2.5% | 💥 PoC | Codehaus-plexus Plexus-archiver | 25/7/2023 | 17/6/2026 | Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified `Archiver`/`UnArchiver` API. Prior to version 4.8.0, using AbstractUnArchiver for extracting an archive might lead to an arbitrary file creation and possibly remote code execution. When extracting… | |
| Modificada | Alta (7.8) | 0.16% | — | IBM Spectrum Protect Backup-archive Client | 22/6/2023 | 17/6/2026 | IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access controls. | |
| Modificada | Media (5.3) | 0.19% | — | Libarchive | 29/5/2023 | 17/6/2026 | Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to… | |
| Modificada | Alta (7.1) | 0.30% | — | Opentext Archive Center Administration | 24/5/2023 | 17/6/2026 | The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administration client (Versions 16.2.3, 21.2, and older versions) could upload XML files to the application that it did not sufficiently validate. As a result, attackers could craft… | |
| Modificada | Media (4.8) | 0.37% | — | Simple Yearly Archive Project Simple Yearly Archive | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Oliver Schlöbe Simple Yearly Archive plugin <= 2.1.8 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Archivist - Custom Archive Templates Project Archivist - Custom Archive Templates | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 versions. | |
| Modificada | Media (5.4) | 0.57% | — | Twinpictures Annual Archive | 6/2/2023 | 17/6/2026 | The Annual Archive WordPress plugin before 1.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (8.1) | 0.91% | — | Ziparchive Project Ziparchive | 3/1/2023 | 17/6/2026 | SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item. | |
| Modificada | Crítica (9.1) | 1.2% | — | Cloudfoundry Archiver | 27/12/2022 | 17/6/2026 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | |
| Modificada | Crítica (9.8) | 2.4% | — | LibarchiveDebian LinuxFedoraproject FedoraSplunk Universal Forwarder | 22/11/2022 | 17/6/2026 | In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare… | |
| Modificada | Crítica (9.8) | 1.3% | — | Democritus D8s-archives | 11/10/2022 | 17/6/2026 | The d8s-archives package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0. | |
| Modificada | Crítica (9.8) | 1.7% | — | D8s-archives Project D8s-archives | 19/9/2022 | 17/6/2026 | The d8s-archives for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0. |