Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
754 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.7) | 0.26% | — | IBM Common Cryptographic Architecture | 11/3/2025 | 17/6/2026 | IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an attacker to obtain sensitive information due to a timing attack during certain RSA operations. | |
| Analizada | Media (6.5) | 0.44% | — | IBM Common Cryptographic Architecture | 11/3/2025 | 17/6/2026 | IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow a remote attacker to obtain sensitive information during the creation of ECDSA signatures to perform a timing-based attack. | |
| Modificada | Media (5.4) | 0.24% | — | Searchiq | 5/3/2025 | 17/6/2026 | The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including, 4.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Alta (7.8) | 0.37% | — | Libarchive | 2/3/2025 | 17/6/2026 | list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale. | |
| Aplazada | Media (6.5) | 0.27% | — | Alobaidi Archive PageAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alobaidi Archive Page archive-page allows DOM-Based XSS.This issue affects Archive Page: from n/a through <= 1.0.2. | |
| Analizada | Media (4.8) | 0.34% | — | Libarchive | 24/2/2025 | 17/6/2026 | A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The… | |
| Analizada | Crítica (9.8) | 0.64% | — | Keesiemeijer Custom Post Type Date Archives | 22/2/2025 | 17/6/2026 | The The Custom Post Type Date Archives plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.7.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for… | |
| Aplazada | Media (4) | 0.25% | — | LibarchiveAI | 16/2/2025 | 17/6/2026 | libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname. | |
| Analizada | Alta (7.8) | 0.17% | — | ARM 5TH GEN GPU Architecture Kernel DriverARM Valhall GPU Kernel Driver | 3/2/2025 | 17/6/2026 | Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to make improper GPU processing operations to gain access to already freed memory.This issue affects Valhall GPU Kernel Driver: from r48p0 through r49p1, from… | |
| Analizada | Media (6.1) | 0.15% | — | ARM 5TH GEN GPU Architecture Kernel DriverARM Bifrost GPU Kernel DriverARM Valhall GPU Kernel Driver | 3/2/2025 | 17/6/2026 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a non-privileged user process to make valid GPU memory processing operations, including via WebGL or WebGPU, to cause… | |
| Aplazada | Media (6.4) | 0.34% | — | Automatically Hierarchic Categories IN MenuAI | 30/1/2025 | 17/6/2026 | The Automatically Hierarchic Categories in Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autocategorymenu' shortcode in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (5.5) | 0.56% | 💥 PoC | Rarlab RAR Extractor - UnarchiverAIRarlab RAR Extractor - Unarchiver PROAI | 21/1/2025 | 17/6/2026 | An issue in RAR Extractor - Unarchiver Free and Pro v.6.4.0 allows local attackers to inject arbitrary code potentially leading to remote control and unauthorized access to sensitive user data via the exploit_combined.dylib component on MacOS. | |
| Aplazada | Media (6.4) | 0.33% | — | SearchieAI | 9/1/2025 | 17/6/2026 | The Searchie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sio_embed_media' shortcode in all versions up to, and including, 1.17.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.32% | — | Unigroup Electronic Archives SystemAI | 5/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). This affects an unknown part of the file /Logs/Annals/downLoad.html. The manipulation of the argument path leads to information disclosure. It is possible to initiate the attack remotely.… | |
| Aplazada | Media (5.3) | 0.42% | — | Unigroup Electronic Archives SystemAI | 5/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this issue is the function download of the file /collect/PortV4/downLoad.html. The manipulation of the argument path leads to information disclosure. The attack may be… | |
| Aplazada | Media (5.3) | 0.47% | — | Unigroup Electronic Archives SystemAI | 5/1/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is an unknown functionality of the file /setting/ClassFy/exampleDownload.html. The manipulation of the argument name leads to path traversal: '/../filedir'. The attack… | |
| Modificada | Media (4.3) | 0.17% | — | Searchiq | 31/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SearchIQ SearchIQ searchiq.This issue affects SearchIQ: from n/a through <= 4.6. | |
| Aplazada | Media (5.3) | 0.38% | — | Tsinghua Unigroup Electronic Archives Management SystemAI | 30/12/2024 | 17/6/2026 | A vulnerability was found in Tsinghua Unigroup Electronic Archives Management System 3.2.210802(62532). It has been classified as problematic. Affected is the function download of the file /Searchnew/Subject/download.html. The manipulation of the argument path leads to information disclosure. It is possible to launch… | |
| Aplazada | Alta (8.8) | 2.1% | 💥 PoC | Python-libarchiveAI | 12/12/2024 | 17/6/2026 | python-libarchive through 4.2.1 allows directory traversal (to create files) in extract in zip.py for ZipFile.extractall and ZipFile.extract. | |
| Analizada | Alta (8.8) | 0.79% | — | GFI Archiver | 12/12/2024 | 17/6/2026 | GFI Archiver Store Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is required to exploit this vulnerability. The specific flaw exists within the Store Service,… | |
| Analizada | Crítica (9.8) | 1.4% | — | GFI Archiver | 12/12/2024 | 17/6/2026 | GFI Archiver Telerik Web UI Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability. The specific flaw exists within the product installer. The issue results from… | |
| Analizada | Alta (8.8) | 0.79% | — | GFI Archiver | 12/12/2024 | 17/6/2026 | GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is required to exploit this vulnerability. The specific flaw exists within the Core Service,… | |
| Modificada | Media (5.3) | 0.42% | — | Searchiq | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in SearchIQ SearchIQ searchiq allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SearchIQ: from n/a through <= 4.4. | |
| Analizada | Media (5.4) | 0.30% | — | Searchiq | 4/12/2024 | 17/6/2026 | The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including, 4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.36% | — | Vadim Bogaiskov BG Patriarchia BUAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vadim Bogaiskov Bg Patriarchia BU bg-patriarchia-bu allows DOM-Based XSS.This issue affects Bg Patriarchia BU: from n/a through <= 2.2.3. |