Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

116 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.36%—CompressAI29/9/202630/9/2026
compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with a uvarint-encoded repeat value exceeding MaxInt64. When Dict.Encode() is subsequently called, the…
En análisisCrítica (9.1)0.81%—Xhmikosr DecompressAI28/9/202630/9/2026
The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a crafted archive containing chained symlink entries so that a…
Pendiente de análisisAlta (7.5)0.61%—CompressionAINodejs Node.jsAIExpressjs ExpressAI11/9/202616/9/2026
compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never destroyed, so each aborted compressed response leaks its native zlib memory. A remote…
AplazadaAlta (8.2)0.39%—Wpcompress WP CompressAI3/9/20263/9/2026
Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.
Pendiente de análisisAlta (7.8)1.0%—RpmuncompressAI2/9/20263/9/2026
A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings.…
AplazadaCrítica (10)0.86%—Wpcompress WP CompressAI18/8/202620/8/2026
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
AplazadaMedia (6.5)0.24%—Wpcompress WP CompressAI16/8/202620/8/2026
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.10.09. This is due to missing or incorrect nonce validation on the (top-level template code) function. This makes it possible for unauthenticated attackers…
AplazadaAlta (8.4)0.40%—Fujitsu Research OnecompressionAI12/8/202624/9/2026
Fujitsu Research's OneCompression library before 1.2.1 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unconditionally calls torch.load with weights_only=False, invoking…
AnalizadaMedia (4.8)0.10%—Intel Neural Compressor11/8/202631/8/2026
Improper input validation for some Intel(R) Neural Compressor software before version v3.7 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may…
AnalizadaMedia (5.4)0.16%—Intel Neural Compressor11/8/202628/9/2026
Protection mechanism failure for some Intel(R) Neural Compressor software before version v3.6 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may…
AplazadaMedia (6.1)0.25%—Wpcompress WP CompressAI23/7/202623/7/2026
The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP Compress WordPress plugin before 7.10.04's…
Pendiente de análisisCrítica (9.1)0.75%—Xhmikosr DecompressAI14/7/202615/7/2026
The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created…
AnalizadaAlta (7.5)0.66%—Decompress Project Decompress9/7/202613/7/2026
decompress before 4.2.2 allows arbitrary symlink creation during archive extraction. When processing symlink entries (type === 'symlink'), the x.linkname field from the archive is passed directly to fs.symlink() without validation (index.js line 121). The preventWritingThroughSymlink check on line 98 only applies to…
AnalizadaMedia (6.2)0.38%—Decompress Project Decompress9/7/202613/7/2026
decompress before 4.2.2 contains an improper path containment check that enables directory traversal and arbitrary file write. The safeMakeDir function (index.js line 29) and the extraction path validation (index.js line 106) use String.indexOf() to verify the resolved path is within the output directory:…
AnalizadaMedia (5.5)0.30%—Decompress Project Decompress9/7/202613/7/2026
decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and file corruption. When processing hardlink entries (type === 'link'), the x.linkname field from the archive is passed directly to fs.link() without validation (index.js line 113). An attacker can…
AnalizadaMedia (4.3)0.29%—Rapid7 Insightconnect Compression25/6/202629/6/2026
Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file paths via crafted filename input. The impact is limited to file corruption as content cannot be controlled by the attacker.
Pendiente de análisisMedia (5.6)0.52%—DecompressAI5/6/20267/9/2026
All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archive containing two entries with the same path - the first being a symlink to an arbitrary target and the second being a regular file - the file content is written through the…
AplazadaAlta (7.3)0.50%—Perl IO CompressAI27/5/20265/8/2026
IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A…
AplazadaAlta (7.3)0.41%—Perl IO CompressAI27/5/202624/7/2026
IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID. When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to…
AplazadaAlta (7.5)0.61%—Perl IO Uncompress UnzipAI27/5/202624/7/2026
IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration. Extracting a named…
AplazadaMedia (5.5)0.13%—Perl IO Uncompress UnzipAI27/5/202624/7/2026
IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date. _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range…
AnalizadaMedia (6.5)0.35%—Adamhathcock Sharpcompress26/5/202624/7/2026
SharpCompress is a fully managed C# library to deal with many compression types and formats. In 0.47.4 and earlier, a path traversal vulnerability in IArchive.WriteToDirectory() allows a malicious archive to create directories outside the intended extraction root. For TAR archives, this can be escalated to arbitrary…
Pendiente de análisisAlta (7.8)0.20%—Lymphatus Caesium-image-compressorAI4/5/202617/6/2026
An issue in Lymphatus caesium-image-compressor All versions up to and including commit 02da2c6 allows a local attacker to execute arbitrary code via the shutdownMachine and putMachineToSleep functions in PostCompressionActions.cpp
AnalizadaAlta (7.8)0.22%—Node-modules Compressing21/4/202617/6/2026
Compressing is a compressing and uncompressing lib for node. Prior to 2.1.1 and 1.10.5, the patch for CVE-2026-24884 relies on a purely logical string validation within the isPathWithinParent utility. This check verifies if a resolved path string starts with the destination directory string but fails to account for…
AnalizadaCrítica (9.8)0.79%—Pmqs Compress\5/3/202617/6/2026
Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib. Compress::Raw::Zlib includes a copy of the zlib library. Compress::Raw::Zlib version 2.220 includes zlib 1.3.2, which addresses findings fron the 7ASecurity audit of zlib. The includes fixs for CVE-2026-27171.