Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.17% | — | Peerigon Unzip-crxAIPeerigon Unzip-crx-3AI | 25/8/2026 | 28/9/2026 | A flaw has been found in peerigon unzip-crx and unzip-crx-3 up to 0.2.0. This affects the function unzip of the file dist/index.js of the component Archive Extraction. Executing a manipulation of the argument destination can lead to path traversal. The attack can only be executed locally. The exploit has been… | |
| Aplazada | Baja (1.9) | 0.17% | — | Zjonsson Node-unzipperAI | 27/7/2026 | 27/7/2026 | A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Extract of the file lib/extract.js. This manipulation causes path traversal. The attack requires local access. The exploit has been publicly disclosed and may be utilized. The project was informed of… | |
| Aplazada | Alta (7.5) | 0.61% | — | Perl IO Uncompress UnzipAI | 27/5/2026 | 24/7/2026 | IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration. Extracting a named… | |
| Aplazada | Media (5.5) | 0.13% | — | Perl IO Uncompress UnzipAI | 27/5/2026 | 24/7/2026 | IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date. _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range… | |
| Aplazada | Crítica (9.8) | 0.41% | — | Archive Unzip BurstAIInfozipAI | 12/6/2025 | 17/6/2026 | Archive::Unzip::Burst from 0.01 through 0.09 for Perl contains a bundled InfoZip library that is affected by several vulnerabilities. The bundled library is affected by CVE-2014-8139, CVE-2014-8140 and CVE-2014-8141. | |
| Aplazada | Alta (8.8) | 0.47% | — | Unzip BOTAI | 2/12/2024 | 17/6/2026 | unzip-bot is a Telegram bot to extract various types of archives. Users could exploit unsanitized inputs to inject malicious commands that are executed through subprocess.Popen with shell=True. Attackers can exploit this vulnerability using a crafted archive name, password, or video name. This vulnerability is fixed… | |
| Modificada | Media (6.5) | 0.60% | — | Upunzipper Project Upunzipper | 10/6/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ravidhu Dissanayake Upunzipper allows Path Traversal, File Manipulation.This issue affects Upunzipper: from n/a through 1.0.0. | |
| Modificada | Crítica (9.1) | 1.3% | — | Unzip Project Unzip | 27/12/2022 | 17/6/2026 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | |
| Modificada | Crítica (9.1) | 1.2% | — | Go-unzip Project Go-unzip | 27/12/2022 | 17/6/2026 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | |
| Modificada | Baja (3.3) | 0.62% | — | Unzip Project UnzipFedoraproject FedoraRedhat Enterprise Linux | 24/8/2022 | 17/6/2026 | A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution. | |
| Modificada | Media (5.5) | 2.1% | — | Unzip Project UnzipRedhat Enterprise LinuxFedoraproject FedoraApple MAC OS X+2 | 9/2/2022 | 17/6/2026 | A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution. | |
| Modificada | Media (5.5) | 2.4% | — | Unzip Project UnzipRedhat Enterprise LinuxFedoraproject FedoraDebian Linux | 9/2/2022 | 17/6/2026 | A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution. | |
| Modificada | Alta (7.8) | 7.4% | — | Unzip Project UnzipRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server EUS+2 | 31/1/2020 | 17/6/2026 | Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command. | |
| Modificada | Alta (7.8) | 7.4% | — | Unzip Project UnzipRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+3 | 31/1/2020 | 17/6/2026 | Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command. | |
| Modificada | Alta (7.8) | 7.4% | — | Unzip Project UnzipRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+3 | 31/1/2020 | 17/6/2026 | Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command. | |
| Modificada | Baja (3.3) | 0.50% | — | Unzip Project UnzipDebian Linux | 4/7/2019 | 17/6/2026 | Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container, leading to denial of service (resource consumption), aka a "better zip bomb" issue. | |
| Modificada | Media (5.5) | 2.6% | — | Unzip Project Unzip | 16/10/2018 | 17/6/2026 | Info-ZIP UnZip 6.0 has a buffer overflow in list.c, when a ZIP archive has a crafted relationship between the compressed-size value and the uncompressed-size value, because a buffer size is 10 and is supposed to be 12. | |
| Modificada | Media (5.5) | 11% | — | Unzipper Project Unzipper | 25/7/2018 | 17/6/2026 | unzipper npm library before 0.8.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'. | |
| Modificada | Alta (7.8) | 30% | — | Unzip Project Unzip | 9/2/2018 | 17/6/2026 | A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to possibly achieve code execution. | |
| Modificada | Crítica (9.1) | 1.4% | — | Info-zip Unzip | 9/2/2018 | 17/6/2026 | An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive memory. | |
| Modificada | Crítica (9.1) | 1.7% | — | Info-zip Unzip | 9/2/2018 | 17/6/2026 | An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive memory. | |
| Modificada | Alta (7.8) | 1.3% | — | Info-zip Unzip | 9/2/2018 | 17/6/2026 | A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service or to possibly achieve code execution. | |
| Modificada | Alta (7.8) | 1.3% | — | Info-zip Unzip | 9/2/2018 | 17/6/2026 | A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service or to possibly achieve code execution. | |
| Modificada | Media (4) | 1.8% | — | Unzip Project Unzip | 18/1/2017 | 17/6/2026 | Buffer overflow in the zi_short function in zipinfo.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via a large compression method value in the central directory file header. | |
| Modificada | Media (4) | 1.5% | — | Unzip Project Unzip | 18/1/2017 | 17/6/2026 | Buffer overflow in the list_files function in list.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via vectors related to the compression method. |