Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 1.3% | — | Apache Hive | 28/1/2025 | 17/6/2026 | Use of Arrays.equals() in LlapSignerImpl in Apache Hive to compare message signatures allows attacker to forge a valid signature for an arbitrary message byte by byte. The attacker should be an authorized user of the product to perform this attack. Users are recommended to upgrade to version 4.0.0, which fixes this… | |
| Aplazada | Media (5.5) | 0.56% | 💥 PoC | Rarlab RAR Extractor - UnarchiverAIRarlab RAR Extractor - Unarchiver PROAI | 21/1/2025 | 17/6/2026 | An issue in RAR Extractor - Unarchiver Free and Pro v.6.4.0 allows local attackers to inject arbitrary code potentially leading to remote control and unauthorized access to sensitive user data via the exploit_combined.dylib component on MacOS. | |
| Aplazada | Alta (8.7) | 0.55% | — | Cloudera Jdbc Connector FOR HiveAICloudera Jdbc Connector FOR ImpalaAI | 16/1/2025 | 17/6/2026 | A JNDI injection issue was discovered in Cloudera JDBC Connector for Hive before 2.6.26 and JDBC Connector for Impala before 2.6.35. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This could lead… | |
| Aplazada | Media (6.5) | 0.28% | — | Zartis Hirehive JOB PluginAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zartis HireHive Job Plugin zartis-job-plugin allows Stored XSS.This issue affects HireHive Job Plugin: from n/a through <= 2.9.0. | |
| Aplazada | Alta (7.2) | 0.71% | — | Aerohive Aos-8AIAerohive Aos-10AI | 14/1/2025 | 17/6/2026 | An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated user to leverage parameter injection to overwrite arbitrary system files. | |
| Analizada | Media (6.1) | 0.62% | 💥 Exploit | Wp-property-hive Propertyhive | 8/1/2025 | 17/6/2026 | The Property Hive WordPress plugin before 2.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Media (4.3) | 0.35% | — | Dearhive Social Media Share Buttons MasshareAI | 7/1/2025 | 17/6/2026 | Missing Authorization vulnerability in DearHive Social Media Share Buttons | MashShare.This issue affects Social Media Share Buttons | MashShare: from n/a through 4.0.47. | |
| Aplazada | Media (4.3) | 0.29% | — | Hive SupportAI | 7/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Hive Support Hive Support hive-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hive Support: from n/a through <= 1.1.6. | |
| Aplazada | Media (5.3) | 0.32% | — | Unigroup Electronic Archives SystemAI | 5/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). This affects an unknown part of the file /Logs/Annals/downLoad.html. The manipulation of the argument path leads to information disclosure. It is possible to initiate the attack remotely.… | |
| Aplazada | Media (5.3) | 0.42% | — | Unigroup Electronic Archives SystemAI | 5/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this issue is the function download of the file /collect/PortV4/downLoad.html. The manipulation of the argument path leads to information disclosure. The attack may be… | |
| Aplazada | Media (5.3) | 0.47% | — | Unigroup Electronic Archives SystemAI | 5/1/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is an unknown functionality of the file /setting/ClassFy/exampleDownload.html. The manipulation of the argument name leads to path traversal: '/../filedir'. The attack… | |
| Aplazada | Alta (8.8) | 0.49% | — | Redhat Openshift DedicatedAIRedhat HiveAI | 31/12/2024 | 17/6/2026 | A flaw was found in the Hive ClusterDeployments resource in OpenShift Dedicated. In certain conditions, this issue may allow a developer account on a Hive-enabled cluster to obtain cluster-admin privileges by executing arbitrary commands on the hive/hive-controllers pod. | |
| Aplazada | Media (5.3) | 0.38% | — | Tsinghua Unigroup Electronic Archives Management SystemAI | 30/12/2024 | 17/6/2026 | A vulnerability was found in Tsinghua Unigroup Electronic Archives Management System 3.2.210802(62532). It has been classified as problematic. Affected is the function download of the file /Searchnew/Subject/download.html. The manipulation of the argument path leads to information disclosure. It is possible to launch… | |
| Analizada | Media (5.9) | 1.6% | — | Apache HiveApache Spark | 23/12/2024 | 17/6/2026 | Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signature helps prevent malicious actors from modifying the cookie value, which can lead to security vulnerabilities and exploitation. Apache Hive’s service component… | |
| Aplazada | Media (4.3) | 0.24% | — | Hive SupportAI | 13/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Hive Support Hive Support hive-support allows Cross Site Request Forgery.This issue affects Hive Support: from n/a through <= 1.1.2. | |
| Aplazada | Alta (8.5) | 0.50% | — | Hive SupportAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hive Support Hive Support hive-support allows SQL Injection.This issue affects Hive Support: from n/a through <= 1.1.2. | |
| Aplazada | Media (6.4) | 0.31% | — | Propertyhive Stamp Duty CalculatorAI | 13/12/2024 | 17/6/2026 | The Property Hive Stamp Duty Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stamp_duty_calculator_scotland' shortcode in all versions up to, and including, 1.0.22 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Alta (8.8) | 2.1% | 💥 PoC | Python-libarchiveAI | 12/12/2024 | 17/6/2026 | python-libarchive through 4.2.1 allows directory traversal (to create files) in extract in zip.py for ZipFile.extractall and ZipFile.extract. | |
| Analizada | Alta (8.8) | 0.79% | — | GFI Archiver | 12/12/2024 | 17/6/2026 | GFI Archiver Store Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is required to exploit this vulnerability. The specific flaw exists within the Store Service,… | |
| Analizada | Crítica (9.8) | 1.4% | — | GFI Archiver | 12/12/2024 | 17/6/2026 | GFI Archiver Telerik Web UI Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability. The specific flaw exists within the product installer. The issue results from… | |
| Analizada | Alta (8.8) | 0.79% | — | GFI Archiver | 12/12/2024 | 17/6/2026 | GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is required to exploit this vulnerability. The specific flaw exists within the Core Service,… | |
| Analizada | Alta (8.3) | 1.6% | — | Apache Hive | 5/12/2024 | 17/6/2026 | Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is unsafe and can lead to Remote Code Execution (RCE) since it allows the deserialization of arbitrary data. In real deployments, the vulnerability can be exploited only by… | |
| Aplazada | Crítica (9.9) | 0.49% | — | Hive SupportAI | 14/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Hive Support Hive Support hive-support allows Upload a Web Shell to a Web Server.This issue affects Hive Support: from n/a through <= 1.1.1. | |
| Analizada | Media (5.9) | 0.19% | — | Google Safearchive | 4/11/2024 | 17/6/2026 | There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction containing symbolic links. We recommend upgrading past commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc | |
| Analizada | Media (4.3) | 0.39% | — | Wp-property-hive Propertyhive | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in PropertyHive PropertyHive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through 2.0.9. |