Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.36% | — | Robfelty Collapsing ArchivesAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsing Archives collapsing-archives allows Blind SQL Injection.This issue affects Collapsing Archives: from n/a through <= 3.0.7. | |
| Aplazada | Media (5.5) | 0.80% | — | Unigroup Electronic Archives SystemAI | 8/3/2026 | 17/6/2026 | A vulnerability was identified in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). This issue affects some unknown processing of the file /System/Cms/downLoad. The manipulation of the argument path leads to path traversal. The attack can be initiated remotely. The exploit is publicly available and might… | |
| Analizada | Media (5.5) | 0.70% | — | Unigroup Electronic Archives System | 19/2/2026 | 17/6/2026 | A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted element is an unknown function of the file /Archive/ErecordManage/uploadFile.html. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be launched remotely. The… | |
| Analizada | Baja (2.1) | 0.70% | — | Unigroup Electronic Archives System | 18/2/2026 | 17/6/2026 | A vulnerability was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). The affected element is an unknown function of the file /Using/Subject/downLoad.html. Performing a manipulation of the argument path results in path traversal. The attack may be initiated remotely. The exploit has been made… | |
| Analizada | Baja (2.1) | 0.51% | — | Unigroup Electronic Archives System | 18/2/2026 | 17/6/2026 | A vulnerability has been found in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). Impacted is an unknown function of the file /mine/PublicReport/prinReport.html?token=java. Such manipulation of the argument comid leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 0.75% | — | Unigroup Electronic Archives System | 18/2/2026 | 17/6/2026 | A security flaw has been discovered in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is the function Download of the file /Search/Subject/downLoad. Performing a manipulation of the argument path results in path traversal. The attack is possible to be carried out… | |
| Aplazada | Alta (7.1) | 0.11% | — | Mg12 Wp-easyarchivesAI | 31/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in mg12 WP-EasyArchives wp-easyarchives allows Stored XSS.This issue affects WP-EasyArchives: from n/a through <= 3.1.2. | |
| Aplazada | Media (6) | 0.36% | — | ArchivesAI | 7/11/2025 | 17/6/2026 | archives is a Go library for extracting archives (tar, zip, etc.). Version 1.0.0 does not prevent a malicious user to feed a specially crafted archive to the library causing RCE, modification of files or other malignancies in the context of whatever the user is running this library as, through the program that imports… | |
| Aplazada | Media (6.5) | 0.20% | — | Syedbalkhi Compact ArchivesAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Compact Archives compact-archives allows Stored XSS.This issue affects Compact Archives: from n/a through <= 4.1.0. | |
| Analizada | Media (4.3) | 0.17% | — | Philipwalton Simple NAV Archives | 15/5/2025 | 17/6/2026 | The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Analizada | Crítica (9.8) | 0.64% | — | Keesiemeijer Custom Post Type Date Archives | 22/2/2025 | 17/6/2026 | The The Custom Post Type Date Archives plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.7.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.32% | — | Unigroup Electronic Archives SystemAI | 5/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). This affects an unknown part of the file /Logs/Annals/downLoad.html. The manipulation of the argument path leads to information disclosure. It is possible to initiate the attack remotely.… | |
| Aplazada | Media (5.3) | 0.42% | — | Unigroup Electronic Archives SystemAI | 5/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this issue is the function download of the file /collect/PortV4/downLoad.html. The manipulation of the argument path leads to information disclosure. The attack may be… | |
| Aplazada | Media (5.3) | 0.47% | — | Unigroup Electronic Archives SystemAI | 5/1/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is an unknown functionality of the file /setting/ClassFy/exampleDownload.html. The manipulation of the argument name leads to path traversal: '/../filedir'. The attack… | |
| Aplazada | Media (5.3) | 0.38% | — | Tsinghua Unigroup Electronic Archives Management SystemAI | 30/12/2024 | 17/6/2026 | A vulnerability was found in Tsinghua Unigroup Electronic Archives Management System 3.2.210802(62532). It has been classified as problematic. Affected is the function download of the file /Searchnew/Subject/download.html. The manipulation of the argument path leads to information disclosure. It is possible to launch… | |
| Analizada | Media (5.4) | 0.26% | — | Robfelty Collapsing Archives | 29/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Robert Felty Collapsing Archives allows Stored XSS.This issue affects Collapsing Archives: from n/a through 3.0.5. | |
| Aplazada | Media (5.9) | 0.44% | — | Archives Calendar WidgetAI | 14/5/2024 | 17/6/2026 | Administrator Cross Site Scripting (XSS) in Archives Calendar Widget <= 1.0.15 versions. | |
| Modificada | Crítica (9.8) | 1.3% | — | Democritus D8s-archives | 11/10/2022 | 17/6/2026 | The d8s-archives package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0. | |
| Modificada | Crítica (9.8) | 1.7% | — | D8s-archives Project D8s-archives | 19/9/2022 | 17/6/2026 | The d8s-archives for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0. | |
| Modificada | Alta (7.5) | 6.6% | — | Ligeo-archives Ligeo Basics | 17/3/2022 | 17/6/2026 | Ligeo Archives Ligeo Basics as of 02_01-2022 is vulnerable to Server Side Request Forgery (SSRF) which allows an attacker to read any documents via the download features. | |
| Modificada | Crítica (9.8) | 2.3% | — | Archivesunleashed Graphpass | 15/7/2019 | 17/6/2026 | borg-reducer c6d5240 is affected by: Buffer Overflow. The impact is: Possible code execution and denial of service. The component is: Output parameter within the executable. | |
| Modificada | Alta (7.5) | 4.4% | — | Canonical Ubuntu LinuxKDE Karchives | 2/8/2016 | 17/6/2026 | Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads. |