Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 77 respecto a la semana anterior
Críticas / altas1446▲ 303 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.45% | — | ArcherysecAI | 16/9/2026 | 24/9/2026 | ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to retrieve complete web vulnerability data including titles, severities, statuses,… | |
| Modificada | Alta (7.5) | 0.37% | — | Archerydms Archery | 16/11/2023 | 17/6/2026 | Archery v1.10.0 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications. | |
| Modificada | Media (6.5) | 0.84% | — | Archerydms Archery | 19/4/2023 | 17/6/2026 | Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. User input coming from the `variable_name` and `variable_value` parameter value in the `sql/instance.py` `param_edit` endpoint is passed to a… | |
| Modificada | Media (6.5) | 0.83% | — | Archerydms Archery | 19/4/2023 | 17/6/2026 | Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. User input coming from the `db_name` in the `sql/data_dictionary.py` `table_list` endpoint is passed to the methods that follow in a given SQL… | |
| Modificada | Media (6.5) | 0.84% | — | Archerydms Archery | 19/4/2023 | 17/6/2026 | Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. Affected versions are subject to SQL injection in the `data_dictionary.py` `table_info`. User input coming from the `db_name` in and the… | |
| Modificada | Media (6.5) | 0.83% | — | Archerydms Archery | 19/4/2023 | 17/6/2026 | Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. Affected versions are subject to SQL injection in the `optimize_sqltuningadvisor` method of `sql_optimize.py`. User input coming from the… | |
| Modificada | Media (6.5) | 0.83% | — | Archerydms Archery | 19/4/2023 | 17/6/2026 | Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases.Affected versions are subject to SQL injection in the `explain` method in `sql_optimize.py`. User input coming from the `db_name` parameter… | |
| Modificada | Media (6.5) | 0.83% | — | Archerydms Archery | 19/4/2023 | 17/6/2026 | Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. Affected versions are subject to SQL injection in the `sql_api/api_workflow.py` endpoint `ExecuteCheck` which passes unfiltered input to the… | |
| Modificada | Media (6.5) | 0.83% | — | Archerydms Archery | 19/4/2023 | 17/6/2026 | Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. Affected versions are subject to multiple SQL injections in the `sql_api/api_workflow.py` endpoint `ExecuteCheck`. User input coming from the… | |
| Modificada | Media (6.5) | 0.83% | — | Archerydms Archery | 19/4/2023 | 17/6/2026 | Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. Affected versions are subject to SQL injection in the `sql/instance.py` endpoint's `describe` method. In several cases, user input coming from… | |
| Modificada | Crítica (9.8) | 1.1% | — | Archerydms Archery | 13/9/2022 | 17/6/2026 | Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the kill_session interface. The project has released an update, please upgrade to v1.9.0 and above. | |
| Modificada | Crítica (9.8) | 1.2% | — | Archerydms Archery | 13/9/2022 | 17/6/2026 | Archery v1.8.3 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_time and stop_time parameters in the my2sql interface. | |
| Modificada | Crítica (9.8) | 1.1% | — | Archerydms Archery | 13/9/2022 | 17/6/2026 | Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the create_kill_session interface. | |
| Modificada | Crítica (9.8) | 1.1% | — | Archerydms Archery | 13/9/2022 | 17/6/2026 | Archery v1.7.5 to v1.8.5 was discovered to contain a SQL injection vulnerability via the where parameter at /archive/apply. | |
| Modificada | Crítica (9.8) | 1.1% | — | Archerydms Archery | 13/9/2022 | 17/6/2026 | Archery v1.7.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the checksum parameter in the report module. | |
| Modificada | Crítica (9.8) | 1.1% | — | Archerydms Archery | 13/9/2022 | 17/6/2026 | Archery v1.4.5 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_file, end_file, start_time, and stop_time parameters in the binlog2sql interface. | |
| Modificada | Media (5.4) | 0.92% | — | Archerysec Archery | 26/12/2019 | 17/6/2026 | In Archery before 1.3, inserting an XSS payload into a project name (either by creating a new project or editing an existing one) will result in stored XSS on the vulnerability-scan scheduling page. | |
| Modificada | Media (6.8) | 9.5% | — | Lispeltuut COM Archeryscores | 4/5/2010 | 16/6/2026 | Directory traversal vulnerability in archeryscores.php in the Archery Scores (com_archeryscores) component 1.0.6 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. |