Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.17% | — | Philipwalton Simple NAV Archives | 15/5/2025 | 17/6/2026 | The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Aplazada | Baja (2.4) | 0.13% | — | ToolhiveAI | 12/5/2025 | 17/6/2026 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Due to the ordering of code used to start an MCP server container, versions of ToolHive prior to 0.0.33 inadvertently store secrets in the run config files which are used to restart stopped containers.… | |
| Analizada | Alta (8.8) | 0.25% | — | Artec-it Enterprise Mail Archive | 12/5/2025 | 17/6/2026 | ARTEC EMA Mail 6.92 allows CSRF. | |
| Analizada | Media (4.9) | 0.45% | ⚠ Explotación activa | Telemessage Text Message Archiver | 8/5/2025 | 17/6/2026 | The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild… | |
| Aplazada | Alta (7.1) | 0.29% | — | Hive SupportAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hive Support Hive Support hive-support allows Reflected XSS.This issue affects Hive Support: from n/a through <= 1.2.5. | |
| Aplazada | Alta (7.5) | 0.47% | — | Hive SupportAI | 17/4/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Hive Support Hive Support hive-support allows Retrieve Embedded Sensitive Data.This issue affects Hive Support: from n/a through <= 1.2.6. | |
| Aplazada | Media (6.5) | 0.32% | — | Wp-property-hive PropertyhiveAI | 16/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Stored XSS.This issue affects PropertyHive: from n/a through <= 2.1.2. | |
| Aplazada | Alta (8.1) | 0.50% | — | Mholt ArchiverAI | 13/4/2025 | 17/6/2026 | A Path Traversal "Zip Slip" vulnerability has been identified in mholt/archiver in Go. This vulnerability allows using a crafted ZIP file containing path traversal symlinks to create or overwrite files with the user's privileges or application utilizing the library. When using the archiver.Unarchive functionality with… | |
| Aplazada | Media (6.5) | 0.29% | — | Hive SupportAI | 10/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Hive Support Hive Support hive-support allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Hive Support: from n/a through <= 1.2.5. | |
| Aplazada | Media (6.5) | 0.22% | — | Hive SupportAI | 10/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hive Support Hive Support hive-support allows Stored XSS.This issue affects Hive Support: from n/a through <= 1.2.11. | |
| Aplazada | Media (6.5) | 0.33% | — | Hive SupportAI | 10/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Hive Support Hive Support hive-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hive Support: from n/a through <= 1.2.5. | |
| Aplazada | Alta (7.1) | 0.38% | — | Hivedigital Canonical AttachmentsAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hivedigital Canonical Attachments canonical-attachments allows Reflected XSS.This issue affects Canonical Attachments: from n/a through <= 1.8. | |
| Aplazada | Alta (8.8) | 0.62% | — | Insightsoftware Hive JdbcAI | 3/4/2025 | 17/6/2026 | insightsoftware Hive JDBC through 2.6.13 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution. | |
| Aplazada | Alta (7.5) | 0.60% | — | Wp-property-hive Houzez Property FeedAI | 1/4/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Property Hive Houzez Property Feed houzez-property-feed allows Path Traversal.This issue affects Houzez Property Feed: from n/a through <= 2.5.4. | |
| Analizada | Alta (7.5) | 0.53% | — | Libarchive | 28/3/2025 | 17/6/2026 | Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8. | |
| Aplazada | Media (4.3) | 0.34% | — | Openshift DedicatedAIOpenshift HiveAI | 19/3/2025 | 17/6/2026 | A flaw was found in the Hive hibernation controller component of OpenShift Dedicated. The ClusterDeployment.hive.openshift.io/v1 resource can be created with the spec.installed field set to true, regardless of the installation status, and a positive timespan for the spec.hibernateAfter value. If a… | |
| Aplazada | Alta (8.2) | 0.49% | — | Redhat Multicluster EngineAIRedhat Advanced Cluster ManagementAIRedhat HiveAI | 17/3/2025 | 21/8/2026 | A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials… | |
| Analizada | Alta (7.8) | 0.37% | — | Libarchive | 2/3/2025 | 17/6/2026 | list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale. | |
| Aplazada | Media (6.5) | 0.27% | — | Alobaidi Archive PageAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alobaidi Archive Page archive-page allows DOM-Based XSS.This issue affects Archive Page: from n/a through <= 1.0.2. | |
| Analizada | Media (4.8) | 0.34% | — | Libarchive | 24/2/2025 | 17/6/2026 | A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The… | |
| Analizada | Crítica (9.8) | 0.64% | — | Keesiemeijer Custom Post Type Date Archives | 22/2/2025 | 17/6/2026 | The The Custom Post Type Date Archives plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.7.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for… | |
| Aplazada | Media (4) | 0.25% | — | LibarchiveAI | 16/2/2025 | 17/6/2026 | libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname. | |
| Analizada | Media (5.4) | 0.16% | — | Wp-property-hive Houzez Property Feed | 12/2/2025 | 17/6/2026 | The Houzez Property Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.21. This is due to missing or incorrect nonce validation on the "deleteexport" action. This makes it possible for unauthenticated attackers to delete property feed exports via a forged… | |
| Aplazada | Media (6.4) | 0.33% | — | Ehive Objects Image GridAI | 31/1/2025 | 17/6/2026 | The eHive Objects Image Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ehive_objects_image_grid' shortcode in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Media (5.5) | 0.29% | — | Apache Hive | 28/1/2025 | 17/6/2026 | Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set explicitly. Any unauthorized user having access to the directory can read the sensitive information written into this file. Users are recommended to upgrade to version… |