Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 48 respecto a la semana anterior
Críticas / altas1479▲ 371 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.17% | — | Zjonsson Node-unzipperAI | 27/7/2026 | 27/7/2026 | A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Extract of the file lib/extract.js. This manipulation causes path traversal. The attack requires local access. The exploit has been publicly disclosed and may be utilized. The project was informed of… | |
| Aplazada | Media (6.2) | 0.12% | — | PyzipperAI | 17/7/2026 | 17/7/2026 | pyzipper is a replacement for Python's zipfile that can read and write AES encrypted zip files. Prior to 0.4.0, a Python operator precedence bug in pyzipper/zipfile_aes.py caused the AE-2 format to never be automatically selected during encryption, causing encrypted entries to be written in AE-1 format and exposing… | |
| Aplazada | Media (4.9) | 0.36% | — | BFG Tools Extension ZipperAI | 14/2/2026 | 17/6/2026 | The BFG Tools – Extension Zipper plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.7. This is due to insufficient input validation on the user-supplied `first_file` parameter in the `zip()` function. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.5) | 0.24% | — | Zipperapp MY Teditor | 5/2/2026 | 5/7/2026 | A path traversal in My Text Editor v1.6.2 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage. | |
| Modificada | Media (6.5) | 0.60% | — | Upunzipper Project Upunzipper | 10/6/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ravidhu Dissanayake Upunzipper allows Path Traversal, File Manipulation.This issue affects Upunzipper: from n/a through 1.0.0. | |
| Modificada | Media (4.3) | 0.52% | — | Nextcloud Zipper | 18/1/2024 | 17/6/2026 | Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected versions users can download "view-only" files by zipping the complete folder. It is recommended that the Files ZIP app is upgraded to 1.2.1, 1.4.1, or 1.5.0. Users unable to upgrade should disable the… | |
| Modificada | Media (5.5) | 11% | — | Unzipper Project Unzipper | 25/7/2018 | 17/6/2026 | unzipper npm library before 0.8.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'. | |
| Modificada | Media (5.8) | 1.5% | — | R-company Unzipper | 18/3/2014 | 17/6/2026 | Directory traversal vulnerability in the R-Company Unzipper application 1.0.1 and earlier for Android allows remote attackers to overwrite or create arbitrary files via a crafted filename. | |
| Modificada | Alta (9.3) | 4.8% | — | Bitberry Software Bitzipper | 22/4/2013 | 16/6/2026 | BitZipper 2013 before Update 1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ZIP archive. | |
| Modificada | Media (5) | 2.0% | — | Bitberry Software Bitzipper | 22/5/2006 | 16/6/2026 | Directory traversal vulnerability in BitZipper 4.1.2 SR-1 and earlier allows remote attackers to create files in arbitrary directories via a .. (dot dot) in the filename of a file that is stored in a (1) RAR (.rar), (2) TAR (.tar), (3) ZIP (.zip), (4) GZ (.gz), or (5) JAR (.jar) archive. | |
| Modificada | Media (5.1) | 1.7% | — | ClamavAIRarlab WinrarAIPowerzio PowerzipAIPkware WinzipAI+1 | 14/10/2005 | 16/6/2026 | Multiple interpretation error in unspecified versions of ClamAV Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are… | |
| Modificada | Media (5.1) | 1.7% | — | UNA AntivirusAIPowerzipAIWinzipAIRarlab WinrarAI+1 | 14/10/2005 | 16/6/2026 | Multiple interpretation error in unspecified versions of UNA Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected… | |
| Modificada | Media (5.1) | 1.7% | — | Mcafee AntivirusAIPowerzipAIWinzipAIRarlab WinrarAI+1 | 14/10/2005 | 16/6/2026 | Multiple interpretation error in unspecified versions of McAfee Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are… | |
| Modificada | Media (5.1) | 1.7% | — | PowzipAIWinzipAIPanda AntivirusAIRarlab WinrarAI+1 | 14/10/2005 | 16/6/2026 | Multiple interpretation error in unspecified versions of Panda Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are… |