Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.1)0.46%—Dearhive DearflipAI24/10/202417/6/2026
The PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer – DearFlip plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pdf_source' parameter in all versions up to, and including, 2.3.32 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
ModificadaAlta (7.8)0.55%—Libarchive10/10/202417/6/2026
execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.
AnalizadaAlta (7.8)0.51%—Libarchive10/10/202417/6/2026
execute_filter_audio in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.
AnalizadaMedia (6.5)0.35%—Wp-property-hive Propertyhive17/9/202417/6/2026
The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.19. This is due to missing or incorrect nonce validation on the 'save_account_details' function. This makes it possible for unauthenticated attackers to edit the name, email address, and password…
AnalizadaMedia (5.4)0.26%—Robfelty Collapsing Archives29/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Robert Felty Collapsing Archives allows Stored XSS.This issue affects Collapsing Archives: from n/a through 3.0.5.
ModificadaMedia (5.4)0.26%—Wp-property-hive Propertyhive8/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.13.
AnalizadaCrítica (9.1)0.97%—Libarchive8/6/202417/6/2026
Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled. This occurs in slurp_central_directory in archive_read_support_format_zip.c.
AplazadaAlta (7.1)0.28%—WP Hive Events Rich Snippets FOR GoogleAI17/5/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Hive Events Rich Snippets for Google allows Exploitation of Trusted Credentials.This issue affects Events Rich Snippets for Google: from n/a through 1.8.
AplazadaMedia (5.9)0.44%—Archives Calendar WidgetAI14/5/202417/6/2026
Administrator Cross Site Scripting (XSS) in Archives Calendar Widget <= 1.0.15 versions.
ModificadaMedia (5.4)0.33%—Wp-property-hive Propertyhive6/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.10.
AnalizadaMedia (6.6)1.1%—Apache Hive3/5/202417/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive. The vulnerability affects the Hive JDBC driver component and it can potentially lead to arbitrary code execution on the machine/endpoint that the JDBC driver (client) is running. The malicious user must have sufficient permissions…
ModificadaMedia (4.3)0.61%—Wp-property-hive Propertyhive2/5/202417/6/2026
The PropertyHive plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_key_date() function in all versions up to, and including, 2.0.12. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary posts
AplazadaMedia (5.7)0.23%—HiveosAI30/4/202417/6/2026
HiveOS through 0.6-102@191212 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: as of 2019-09-26, the vendor indicated that they would consider fixing this.
AplazadaBaja (3.3)0.15%—Macpaw THE UnarchiverAI29/4/202417/6/2026
MacPaw The Unarchiver before 4.3.6 contains vulnerability related to missing quarantine attributes for extracted items.
AplazadaMedia (5.9)0.36%—Twinpictures Annual ArchiveAI26/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twinpictures Annual Archive allows Stored XSS.This issue affects Annual Archive: from n/a through 1.6.0.
AplazadaMedia (6.1)0.82%💥 PoCArchive Tainacan CollectionAI16/4/202417/6/2026
The archive-tainacan-collection theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in version 2.7.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can…
ModificadaAlta (8.8)0.38%—Wp-property-hive Propertyhive11/4/202417/6/2026
Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.9.
AnalizadaAlta (7.8)85%—LibarchiveFedoraproject FedoraMicrosoft Windows 11 22h2Microsoft Windows 11 23h2+19/4/202417/6/2026
Libarchive Remote Code Execution Vulnerability
AnalizadaAlta (7.8)0.93%💥 PoCMholt ArchiverRedhat Advanced Cluster SecurityRedhat Openshift Container Platform6/4/202417/6/2026
A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.
ModificadaMedia (5.4)0.34%—Dearhive Dearflip27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DearHive DearFlip allows Stored XSS.This issue affects DearFlip: from n/a through 2.2.26.
ModificadaMedia (6.1)0.40%—Wp-property-hive Propertyhive27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Reflected XSS.This issue affects PropertyHive: from n/a through 2.0.8.
ModificadaMedia (6.5)0.32%—Wp-property-hive Propertyhive26/3/202417/6/2026
Missing Authorization vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.6.
AnalizadaAlta (7.8)0.25%—Snowflake Hive Metastore Connector15/3/202417/6/2026
The Snowflake Hive metastore connector provides an easy way to query Hive-managed data via Snowflake. Snowflake Hive MetaStore Connector has addressed a potential elevation of privilege vulnerability in a `helper script` for the Hive MetaStore Connector. A malicious insider without admin privileges could, in theory,…
ModificadaCrítica (9.8)0.52%—Wp-property-hive Propertyhive12/2/202417/6/2026
Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.5.
ModificadaMedia (5.4)0.44%—Dearhive PDF Flipbook, 3D Flipbook3/2/202417/6/2026
The PDF Flipbook, 3D Flipbook – DearFlip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via outline settings in all versions up to, and including, 2.2.26 due to insufficient input sanitization and output escaping on user supplied data. This makes it possible for authenticated attackers with…