Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2819→ sin cambios respecto a la semana anterior
Críticas / altas1469▲ 239 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.17% | — | Zjonsson Node-unzipperAI | 27/7/2026 | 27/7/2026 | A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Extract of the file lib/extract.js. This manipulation causes path traversal. The attack requires local access. The exploit has been publicly disclosed and may be utilized. The project was informed of… | |
| Aplazada | Media (6.2) | 0.12% | — | PyzipperAI | 17/7/2026 | 17/7/2026 | pyzipper is a replacement for Python's zipfile that can read and write AES encrypted zip files. Prior to 0.4.0, a Python operator precedence bug in pyzipper/zipfile_aes.py caused the AE-2 format to never be automatically selected during encryption, causing encrypted entries to be written in AE-1 format and exposing… | |
| Aplazada | Media (4.9) | 0.36% | — | BFG Tools Extension ZipperAI | 14/2/2026 | 17/6/2026 | The BFG Tools – Extension Zipper plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.7. This is due to insufficient input validation on the user-supplied `first_file` parameter in the `zip()` function. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.5) | 0.24% | — | Zipperapp MY Teditor | 5/2/2026 | 5/7/2026 | A path traversal in My Text Editor v1.6.2 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage. | |
| Analizada | Media (5.1) | 0.28% | — | Zippy Zstore | 13/1/2026 | 17/6/2026 | Zstore, now referred to as Zippy CRM, 6.5.4 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts through unvalidated input parameters. Attackers can submit crafted payloads in manual insertion points to execute arbitrary JavaScript code in victim's browser context. | |
| Aplazada | Crítica (9.1) | 0.47% | — | Gesundheit-bewegt ZippyAI | 22/10/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy zippy allows Using Malicious Files.This issue affects Zippy: from n/a through <= 1.7.0. | |
| Aplazada | Media (5.3) | 0.59% | — | Gesundheit-bewegt ZippyAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Gesundheit Bewegt GmbH Zippy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zippy: from n/a through 1.6.2. | |
| Analizada | Media (5.3) | 0.77% | — | Rems Zipped Folder Manager APP | 26/8/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Zipped Folder Manager App 1.0. This affects an unknown part of the file /endpoint/add-folder.php. The manipulation of the argument folder leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been… | |
| Aplazada | Media (6.2) | 0.24% | — | Jaraco ZippAICpythonAI | 9/7/2024 | 17/6/2026 | A Denial of Service (DoS) vulnerability exists in the jaraco/zipp library, affecting all versions prior to 3.19.1. The vulnerability is triggered when processing a specially crafted zip file that leads to an infinite loop. This issue also impacts the zipfile module of CPython, as features from the third-party zipp… | |
| Modificada | Media (6.5) | 0.60% | — | Upunzipper Project Upunzipper | 10/6/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ravidhu Dissanayake Upunzipper allows Path Traversal, File Manipulation.This issue affects Upunzipper: from n/a through 1.0.0. | |
| Modificada | Alta (8.8) | 0.61% | — | Gesundheit-bewegt Zippy | 21/3/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.9. | |
| Modificada | Media (4.3) | 0.52% | — | Nextcloud Zipper | 18/1/2024 | 17/6/2026 | Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected versions users can download "view-only" files by zipping the complete folder. It is recommended that the Files ZIP app is upgraded to 1.2.1, 1.4.1, or 1.5.0. Users unable to upgrade should disable the… | |
| Modificada | Alta (8.8) | 0.48% | — | Gesundheit-bewegt Zippy | 28/12/2023 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.5. | |
| Modificada | Media (6.5) | 0.72% | — | Gesundheit-bewegt Zippy | 30/11/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.1. | |
| Modificada | Media (6.1) | 0.47% | — | Zippy Zstore | 13/2/2023 | 17/6/2026 | Zstore v6.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /index.php. | |
| Modificada | Media (5.5) | 11% | — | Unzipper Project Unzipper | 25/7/2018 | 17/6/2026 | unzipper npm library before 0.8.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'. | |
| Modificada | Media (5.8) | 1.5% | — | R-company Unzipper | 18/3/2014 | 17/6/2026 | Directory traversal vulnerability in the R-Company Unzipper application 1.0.1 and earlier for Android allows remote attackers to overwrite or create arbitrary files via a crafted filename. | |
| Modificada | Baja (2.1) | 0.56% | — | Zippyyum Subway Ordering FOR California | 12/12/2013 | 17/6/2026 | The ZippyYum Subway CA Kiosk app 3.4 for iOS uses cleartext storage in SQLite cache databases, which allows attackers to obtain sensitive information by reading data elements, as demonstrated by password elements. | |
| Modificada | Alta (9.3) | 4.8% | — | Bitberry Software Bitzipper | 22/4/2013 | 16/6/2026 | BitZipper 2013 before Update 1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ZIP archive. | |
| Modificada | Alta (9.3) | 4.3% | — | VIMZipplugin.vim | 21/2/2009 | 16/6/2026 | The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (exclamation point) shell metacharacter in (1) the filename of a ZIP archive and possibly (2) the filename of the first file in a ZIP archive, which is not properly handled by… | |
| Modificada | Media (5) | 2.0% | — | Bitberry Software Bitzipper | 22/5/2006 | 16/6/2026 | Directory traversal vulnerability in BitZipper 4.1.2 SR-1 and earlier allows remote attackers to create files in arbitrary directories via a .. (dot dot) in the filename of a file that is stored in a (1) RAR (.rar), (2) TAR (.tar), (3) ZIP (.zip), (4) GZ (.gz), or (5) JAR (.jar) archive. | |
| Modificada | Media (5.1) | 1.7% | — | Mcafee AntivirusAIPowerzipAIWinzipAIRarlab WinrarAI+1 | 14/10/2005 | 16/6/2026 | Multiple interpretation error in unspecified versions of McAfee Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are… | |
| Modificada | Media (5.1) | 1.7% | — | UNA AntivirusAIPowerzipAIWinzipAIRarlab WinrarAI+1 | 14/10/2005 | 16/6/2026 | Multiple interpretation error in unspecified versions of UNA Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected… | |
| Modificada | Media (5.1) | 1.7% | — | PowzipAIWinzipAIPanda AntivirusAIRarlab WinrarAI+1 | 14/10/2005 | 16/6/2026 | Multiple interpretation error in unspecified versions of Panda Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are… | |
| Modificada | Media (5.1) | 1.7% | — | ClamavAIRarlab WinrarAIPowerzio PowerzipAIPkware WinzipAI+1 | 14/10/2005 | 16/6/2026 | Multiple interpretation error in unspecified versions of ClamAV Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are… |