Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.36%—Munsoft Easy Archive Recovery2/2/202417/6/2026
A vulnerability classified as problematic was found in Munsoft Easy Archive Recovery 2.0. This vulnerability affects unknown code of the component Registration Key Handler. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.…
ModificadaMedia (5.4)0.31%—Dearhive Dearpdf31/1/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DearHive PDF Viewer & 3D PDF Flipbook – DearPDF allows Stored XSS.This issue affects PDF Viewer & 3D PDF Flipbook – DearPDF: from n/a through 2.0.38.
ModificadaAlta (8.8)0.54%—Delhivery Logistics Courier27/1/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Delhivery Delhivery Logistics Courier.This issue affects Delhivery Logistics Courier: from n/a through 1.0.107.
ModificadaMedia (5.4)0.29%—Strangebee Thehive19/1/202417/6/2026
StrangeBee TheHive 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case reporting functionality. This feature allows an attacker to insert malicious JavaScript code inside the template or its variables, that will be executed in the context of the TheHive application when the HTML report is opened.
ModificadaMedia (5.4)0.29%—Strangebee Thehive19/1/202417/6/2026
StrangeBee TheHive 5.1.0 to 5.1.9 and 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case attachment functionality which enables an attacker to upload a malicious HTML file with Javascript code that will be executed in the context of the The Hive application using a specific URL. The vulnerability…
ModificadaMedia (6.5)0.51%—Qstar Archive Storage Manager13/1/202417/6/2026
An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily disable the SMB service on a victim's Qstar instance by executing a specific command in a link.
ModificadaAlta (7.5)0.55%—Qstar Archive Storage Manager13/1/202417/6/2026
An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensitive SMB settings on the QStar Server.
ModificadaMedia (5.4)0.35%—Qstar Archive Storage Manager13/1/202417/6/2026
An authenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link.
ModificadaMedia (6.1)0.41%—Qstar Archive Storage Manager13/1/202417/6/2026
An unauthenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link.
ModificadaAlta (8.8)1.5%—Qstar Archive Storage Manager13/1/202417/6/2026
An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily execute commands.
ModificadaAlta (7.5)0.65%—Qstar Archive Storage Manager13/1/202417/6/2026
Incorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to obtain system backups and other sensitive information from the QStar Server.
ModificadaMedia (6.1)0.38%—Qstar Archive Storage Manager13/1/202417/6/2026
QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based reflected XSS vulnerability within the component qnme-ajax?method=tree_table.
ModificadaAlta (8.8)0.32%—Qstar Archive Storage Manager13/1/202417/6/2026
QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based Reflected Cross Site Scripting (XSS) vulnerability within the component qnme-ajax?method=tree_level.
ModificadaMedia (5.3)0.50%—Qstar Archive Storage Manager13/1/202417/6/2026
An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0 allows attackers to disclose the SMB Log contents via executing a crafted command.
ModificadaMedia (5.4)0.39%—Twinpictures Annual Archive14/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twinpictures Annual Archive allows Stored XSS.This issue affects Annual Archive: from n/a through 1.6.0.
ModificadaMedia (6.1)0.29%—Ericteubert Archivist - Custom Archive Templates27/10/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.5 versions.
ModificadaMedia (5.4)0.41%—Osmansorkar Ajax Archive Calendar25/10/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Osmansorkar Ajax Archive Calendar plugin <= 2.6.7 versions.
ModificadaMedia (5.4)0.68%—Archivebox19/10/20237/7/2026
ArchiveBox is an open source self-hosted web archiving system. Any users who are using the `wget` extractor and view the content it outputs. The impact is potentially severe if you are logged in to the ArchiveBox admin site in the same browser session and view an archived malicious page designed to target your…
ModificadaCrítica (9.8)0.93%—Strangebee CortexStrangebee Thehive11/9/202317/6/2026
An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Active Directory authentication mechanism.
ModificadaAlta (7.8)0.37%—Archive Project Archive30/8/202317/6/2026
An issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file.
ModificadaAlta (7.8)0.35%—Archive Project Archive30/8/202317/6/2026
An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.
ModificadaMedia (5.5)0.37%—Ziparchive Project Ziparchive30/8/202317/6/2026
An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file.
ModificadaMedia (6.1)0.46%—Perfopsone Mailarchiver30/8/202317/6/2026
The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute…
ModificadaCrítica (9.8)2.5%💥 PoCCodehaus-plexus Plexus-archiver25/7/202317/6/2026
Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified `Archiver`/`UnArchiver` API. Prior to version 4.8.0, using AbstractUnArchiver for extracting an archive might lead to an arbitrary file creation and possibly remote code execution. When extracting…
ModificadaAlta (8.8)1.6%—Apache-airflow-providers-apache-hive13/7/202317/6/2026
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider. Patching on top of CVE-2023-35797 Before 6.1.2 the proxy_user option can also inject semicolon. This issue affects Apache Airflow Apache Hive Provider: before 6.1.2. It is recommended updating provider version to…
Orbitaley — Vulnerabilidades