Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

286 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)12%💥 PoCCodehaus-plexus Plexus-archiverDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+125/7/201817/6/2026
plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
ModificadaAlta (7.5)43%—Canonical Ubuntu LinuxDebian LinuxPerl-archive-zip Project Perl-archive-zip29/6/201817/6/2026
perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use this flaw to write or overwrite arbitrary files in the context…
ModificadaAlta (7.5)7.3%—Canonical Ubuntu LinuxDebian LinuxPerlArchive\ \+57/6/201817/6/2026
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
ModificadaMedia (5.5)0.35%—Osisoft PI AF ClientOsisoft PI Buffer SubsystemOsisoft PI Data ArchiveOsisoft PI SDK3/4/201817/6/2026
OSIsoft PI System software (Applications using PI Asset Framework (AF) Client versions prior to PI AF Client 2016, Version 2.8.0; Applications using PI Software Development Kit (SDK) versions prior to PI SDK 2016, Version 1.4.6; PI Buffer Subsystem, versions prior to and including, Version 4.4; and PI Data Archive…
ModificadaAlta (7.8)0.34%—Osisoft PI Data Archive14/3/201817/6/2026
An Incorrect Default Permissions issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Insecure default configuration may allow escalation of privileges that gives the actor full control over the system.
ModificadaMedia (5.9)1.4%—Osisoft PI Data Archive14/3/201817/6/2026
An Improper Input Validation issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Unauthenticated users may use unvalidated custom requests to crash the server.
ModificadaAlta (7.5)2.1%—Osisoft PI Data Archive14/3/201817/6/2026
A Deserialization of Untrusted Data issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Unauthenticated users may modify deserialized data to send custom requests that crash the server.
ModificadaAlta (8.1)74%💥 ExploitJolokia Webarchive Agent14/3/201817/6/2026
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.
ModificadaMedia (6.5)2.0%—Libarchive17/9/201717/6/2026
libarchive 3.3.2 suffers from an out-of-bounds read within lha_read_data_none() in archive_read_support_format_lha.c when extracting a specially crafted lha archive, related to lha_crc16.
ModificadaAlta (7.5)3.4%—Libarchive17/9/201717/6/2026
read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers from an off-by-one error for UTF-16 names in RAR archives, leading to an out-of-bounds read in archive_read_format_rar_read_header.
ModificadaMedia (6.5)1.9%—Libarchive17/9/201717/6/2026
An out-of-bounds read flaw exists in parse_file_info in archive_read_support_format_iso9660.c in libarchive 3.3.2 when extracting a specially crafted iso9660 iso file, related to archive_read_format_iso9660_read_header.
ModificadaMedia (6.5)2.8%—LibarchiveDebian LinuxCanonical Ubuntu Linux6/9/201717/6/2026
libarchive 3.3.2 allows remote attackers to cause a denial of service (xml_data heap-based buffer over-read and application crash) via a crafted xar archive, related to the mishandling of empty strings in the atol8 function in archive_read_support_format_xar.c.
ModificadaMedia (5.9)2.1%—Osisoft PI Data Archive25/8/201717/6/2026
An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Network Manager using older protocol versions contains a flaw that could allow a malicious user to authenticate with a server and then cause PI Network Manager to behave in an undefined manner.
ModificadaAlta (7.4)2.0%—Osisoft PI Data Archive25/8/201717/6/2026
An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Data Archive has protocol flaws with the potential to expose change records in the clear and allow a malicious party to spoof a server within a collective.
ModificadaAlta (7.5)1.9%—Progress Mixlib-archive17/7/201717/6/2026
Chef Software's mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary files by using ".." in tar archive entries
ModificadaMedia (5.5)1.6%—Libarchive1/5/201717/6/2026
The archive_read_format_cab_read_header function in archive_read_support_format_cab.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
ModificadaMedia (5.5)1.7%—Libarchive1/5/201717/6/2026
The archive_le32dec function in archive_endian.h in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
ModificadaMedia (5.5)1.9%—Libarchive3/4/201717/6/2026
The archive_wstring_append_from_mbs function in archive_string.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive file.
ModificadaAlta (7.5)3.3%—LibarchiveOpensuse Leap15/2/201717/6/2026
The read_Header function in archive_read_support_format_7zip.c in libarchive 3.2.1 allows remote attackers to cause a denial of service (out-of-bounds read) via multiple EmptyStream attributes in a header in a 7zip archive.
ModificadaMedia (5.5)2.0%—LibarchiveOpensuse Leap15/2/201717/6/2026
The mtree bidder in libarchive 3.2.1 does not keep track of line sizes when extending the read-ahead, which allows remote attackers to cause a denial of service (crash) via a crafted file, which triggers an invalid read in the (1) detect_form or (2) bid_entry function in libarchive/archive_read_support_format_mtree.c.
ModificadaAlta (7.5)5.3%—LibarchiveOpensuse Leap15/2/201717/6/2026
Stack-based buffer overflow in the safe_fprintf function in tar/util.c in libarchive 3.2.1 allows remote attackers to cause a denial of service via a crafted non-printable multibyte character in a filename.
ModificadaAlta (7.5)4.7%—Archive-tar-minitarMinitar1/2/201717/6/2026
Directory traversal vulnerability in the minitar before 0.6 and archive-tar-minitar 0.5.2 gems for Ruby allows remote attackers to write to arbitrary files via a .. (dot dot) in a TAR archive entry.
ModificadaAlta (7.5)4.5%—Libarchive27/1/201717/6/2026
An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specially crafted archive.
ModificadaMedia (5.5)1.6%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUSRedhat Enterprise Linux Server+521/9/201617/6/2026
libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file.
ModificadaAlta (8.6)6.3%—Oracle LinuxLibarchive21/9/201617/6/2026
Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying filename lengths when writing an ISO9660 archive, which trigger a buffer overflow.
Orbitaley — Vulnerabilidades