Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.46% | — | Dearhive DearflipAI | 24/10/2024 | 17/6/2026 | The PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer – DearFlip plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pdf_source' parameter in all versions up to, and including, 2.3.32 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Modificada | Alta (7.8) | 0.55% | — | Libarchive | 10/10/2024 | 17/6/2026 | execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst. | |
| Analizada | Alta (7.8) | 0.51% | — | Libarchive | 10/10/2024 | 17/6/2026 | execute_filter_audio in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst. | |
| Analizada | Media (6.5) | 0.35% | — | Wp-property-hive Propertyhive | 17/9/2024 | 17/6/2026 | The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.19. This is due to missing or incorrect nonce validation on the 'save_account_details' function. This makes it possible for unauthenticated attackers to edit the name, email address, and password… | |
| Analizada | Media (5.4) | 0.26% | — | Robfelty Collapsing Archives | 29/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Robert Felty Collapsing Archives allows Stored XSS.This issue affects Collapsing Archives: from n/a through 3.0.5. | |
| Modificada | Media (5.4) | 0.26% | — | Wp-property-hive Propertyhive | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.13. | |
| Analizada | Crítica (9.1) | 0.97% | — | Libarchive | 8/6/2024 | 17/6/2026 | Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled. This occurs in slurp_central_directory in archive_read_support_format_zip.c. | |
| Aplazada | Alta (7.1) | 0.28% | — | WP Hive Events Rich Snippets FOR GoogleAI | 17/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Hive Events Rich Snippets for Google allows Exploitation of Trusted Credentials.This issue affects Events Rich Snippets for Google: from n/a through 1.8. | |
| Aplazada | Media (5.9) | 0.44% | — | Archives Calendar WidgetAI | 14/5/2024 | 17/6/2026 | Administrator Cross Site Scripting (XSS) in Archives Calendar Widget <= 1.0.15 versions. | |
| Modificada | Media (5.4) | 0.33% | — | Wp-property-hive Propertyhive | 6/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.10. | |
| Analizada | Media (6.6) | 1.1% | — | Apache Hive | 3/5/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive. The vulnerability affects the Hive JDBC driver component and it can potentially lead to arbitrary code execution on the machine/endpoint that the JDBC driver (client) is running. The malicious user must have sufficient permissions… | |
| Modificada | Media (4.3) | 0.61% | — | Wp-property-hive Propertyhive | 2/5/2024 | 17/6/2026 | The PropertyHive plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_key_date() function in all versions up to, and including, 2.0.12. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary posts | |
| Aplazada | Media (5.7) | 0.23% | — | HiveosAI | 30/4/2024 | 17/6/2026 | HiveOS through 0.6-102@191212 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: as of 2019-09-26, the vendor indicated that they would consider fixing this. | |
| Aplazada | Baja (3.3) | 0.15% | — | Macpaw THE UnarchiverAI | 29/4/2024 | 17/6/2026 | MacPaw The Unarchiver before 4.3.6 contains vulnerability related to missing quarantine attributes for extracted items. | |
| Aplazada | Media (5.9) | 0.36% | — | Twinpictures Annual ArchiveAI | 26/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twinpictures Annual Archive allows Stored XSS.This issue affects Annual Archive: from n/a through 1.6.0. | |
| Aplazada | Media (6.1) | 0.82% | 💥 PoC | Archive Tainacan CollectionAI | 16/4/2024 | 17/6/2026 | The archive-tainacan-collection theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in version 2.7.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can… | |
| Modificada | Alta (8.8) | 0.38% | — | Wp-property-hive Propertyhive | 11/4/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.9. | |
| Analizada | Alta (7.8) | 85% | — | LibarchiveFedoraproject FedoraMicrosoft Windows 11 22h2Microsoft Windows 11 23h2+1 | 9/4/2024 | 17/6/2026 | Libarchive Remote Code Execution Vulnerability | |
| Analizada | Alta (7.8) | 0.93% | 💥 PoC | Mholt ArchiverRedhat Advanced Cluster SecurityRedhat Openshift Container Platform | 6/4/2024 | 17/6/2026 | A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library. | |
| Modificada | Media (5.4) | 0.34% | — | Dearhive Dearflip | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DearHive DearFlip allows Stored XSS.This issue affects DearFlip: from n/a through 2.2.26. | |
| Modificada | Media (6.1) | 0.40% | — | Wp-property-hive Propertyhive | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Reflected XSS.This issue affects PropertyHive: from n/a through 2.0.8. | |
| Modificada | Media (6.5) | 0.32% | — | Wp-property-hive Propertyhive | 26/3/2024 | 17/6/2026 | Missing Authorization vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.6. | |
| Analizada | Alta (7.8) | 0.25% | — | Snowflake Hive Metastore Connector | 15/3/2024 | 17/6/2026 | The Snowflake Hive metastore connector provides an easy way to query Hive-managed data via Snowflake. Snowflake Hive MetaStore Connector has addressed a potential elevation of privilege vulnerability in a `helper script` for the Hive MetaStore Connector. A malicious insider without admin privileges could, in theory,… | |
| Modificada | Crítica (9.8) | 0.52% | — | Wp-property-hive Propertyhive | 12/2/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.5. | |
| Modificada | Media (5.4) | 0.44% | — | Dearhive PDF Flipbook, 3D Flipbook | 3/2/2024 | 17/6/2026 | The PDF Flipbook, 3D Flipbook – DearFlip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via outline settings in all versions up to, and including, 2.2.26 due to insufficient input sanitization and output escaping on user supplied data. This makes it possible for authenticated attackers with… |