Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.24% | — | Hivepress Claim ListingsAI | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in HivePress HivePress Claim Listings hivepress-claim-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HivePress Claim Listings: from n/a through <= 1.1.4. | |
| Aplazada | Media (6.5) | 0.20% | — | Syedbalkhi Compact ArchivesAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Compact Archives compact-archives allows Stored XSS.This issue affects Compact Archives: from n/a through <= 4.1.0. | |
| Aplazada | Media (5.4) | 0.13% | — | Hack Repair GUY Plugin ArchiverAI | 17/9/2025 | 25/9/2026 | The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.4. This is due to missing or incorrect nonce validation on the bulk_remove() function. This makes it possible for unauthenticated attackers to arbitrary directory… | |
| Aplazada | Alta (7.2) | 0.73% | — | Hack Repair GUY Plugin ArchiverAI | 12/9/2025 | 17/6/2026 | The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the prepare_items function in all versions up to, and including, 2.0.4. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Aplazada | Crítica (9.4) | 1.5% | — | InternetarchiveAI | 6/9/2025 | 17/6/2026 | internetarchive is a Python and Command-Line Interface to Archive.org In versions 5.5.0 and below, there is a directory traversal (path traversal) vulnerability in the File.download() method of the internetarchive library. The file.download() method does not properly sanitize user-supplied filenames or validate the… | |
| Aplazada | Media (6.5) | 0.21% | — | Eric Mann WP Publication ArchiveAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric Mann WP Publication Archive wp-publication-archive allows Stored XSS.This issue affects WP Publication Archive : from n/a through <= 3.0.1. | |
| Aplazada | Media (6.5) | 0.21% | — | Wp-property-hive PropertyhiveAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Stored XSS.This issue affects PropertyHive: from n/a through <= 2.1.5. | |
| Aplazada | Crítica (9.3) | 1.5% | 💥 Exploit | Miguel Useche JS Archive ListAIJquery Archive List WidgetAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows SQL Injection.This issue affects JS Archive List: from n/a through < 6.1.6. | |
| Aplazada | Alta (7.5) | 0.50% | — | JS Archive ListAI | 19/8/2025 | 17/6/2026 | The JS Archive List plugin for WordPress is vulnerable to time-based SQL Injection via the build_sql_where() function in all versions up to, and including, 6.1.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Analizada | Media (6.1) | 0.25% | — | Barracuda Message Archiver Firmware | 30/7/2025 | 17/6/2026 | the BMA login interface allows arbitrary JavaScript or HTML to be written straight into the page’s Document Object Model via the error= URL parameter | |
| Aplazada | Alta (7.1) | 0.45% | — | Aveva PI Data ArchiveAI | 12/6/2025 | 17/6/2026 | AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI Data Archive subsystems, resulting in a denial of service. Depending on the timing of the crash, data present in snapshots/write cache may be lost. | |
| Aplazada | Alta (7.1) | 0.39% | — | Aveva PI Data ArchiveAI | 12/6/2025 | 17/6/2026 | AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI Data Archive subsystems, resulting in a denial of service. | |
| Aplazada | Crítica (9.8) | 0.41% | — | Archive Unzip BurstAIInfozipAI | 12/6/2025 | 17/6/2026 | Archive::Unzip::Burst from 0.01 through 0.09 for Perl contains a bundled InfoZip library that is affected by several vulnerabilities. The bundled library is affected by CVE-2014-8139, CVE-2014-8140 and CVE-2014-8141. | |
| Aplazada | Alta (8.1) | 0.38% | — | ArchiverspaapiAI | 10/6/2025 | 17/6/2026 | The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated remote attacker can generate and use a verifiable JWT token to access protected ArchiverSpaApi URL endpoints. | |
| Analizada | Media (6.6) | 0.37% | — | LibarchiveRedhat Openshift Container PlatformRedhat Enterprise Linux | 9/6/2025 | 1/9/2026 | A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a… | |
| Modificada | Media (5) | 0.20% | — | LibarchiveRedhat Openshift Container PlatformRedhat Enterprise Linux | 9/6/2025 | 1/9/2026 | A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior,… | |
| Modificada | Media (5.6) | 0.18% | — | LibarchiveRedhat Openshift Container PlatformRedhat Enterprise Linux | 9/6/2025 | 1/9/2026 | A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading… | |
| Modificada | Media (6.6) | 0.19% | 💥 PoC | LibarchiveRedhat Openshift Container PlatformRedhat Enterprise Linux | 9/6/2025 | 1/9/2026 | A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in… | |
| Modificada | Alta (7.8) | 0.44% | — | LibarchiveRedhat Openshift Container PlatformRedhat Enterprise Linux | 9/6/2025 | 7/10/2026 | A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker… | |
| Aplazada | Media (5.4) | 0.17% | — | Hive SupportAI | 6/6/2025 | 17/6/2026 | The Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing or incorrect nonce validation on the hs_update_ai_chat_settings() function. This makes it possible… | |
| Aplazada | Alta (7.1) | 0.32% | — | Hive SupportAI | 6/6/2025 | 17/6/2026 | The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the hs_update_ai_chat_settings() and hive_lite_support_get_all_binbox() functions in all versions up to, and including, 1.2.5. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.8) | 0.32% | — | Strangebee ThehiveAI | 23/5/2025 | 17/6/2026 | A Broken Access Control vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, and 5.4.0 before 5.4.10 allows remote, authenticated, and unprivileged users to retrieve alerts, cases, logs, observables, or tasks, regardless of the user's permissions, through a specific API endpoint. | |
| Aplazada | Media (5.9) | 0.26% | — | Strangebee ThehiveAI | 23/5/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows a remote attacker to trigger requests on their victim's behalf, if the attacker lures a privileged user, authenticated with basic authentication. | |
| Aplazada | Media (4.6) | 0.42% | — | Strangebee ThehiveAI | 23/5/2025 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows remote authenticated attackers with admin permissions (allowing them to access specific API endpoints) to manipulate URLs to direct requests to… | |
| Aplazada | Media (6.9) | 0.51% | — | Strangebee ThehiveAI | 23/5/2025 | 17/6/2026 | An e-mail flooding vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows unauthenticated remote attackers to use the password reset feature without limits. This can lead to several consequences, including mailbox storage exhaustion for targeted… |