Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
551 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.94% | — | LibreswanAI | 11/3/2024 | 17/6/2026 | The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secret) and the connection cannot find a matching configured secret. When such a connection is automatically added on startup using the auto=… | |
| Modificada | Alta (7.5) | 0.54% | — | GNU Libredwg | 2/1/2024 | 17/6/2026 | Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c. | |
| Modificada | Alta (8.8) | 0.77% | — | LibreofficeFedoraproject FedoraDebian Linux | 11/12/2023 | 17/6/2026 | Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user. | |
| Modificada | Alta (8.8) | 1.0% | — | LibreofficeFedoraproject FedoraDebian Linux | 11/12/2023 | 17/6/2026 | Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker to run arbitrary gstreamer… | |
| Modificada | Media (6.1) | 0.56% | — | Librespeed Speedtest | 3/12/2023 | 17/6/2026 | A vulnerability was found in librespeed speedtest up to 5.2.4. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file results/stats.php. The manipulation of the argument id leads to cross site scripting. The attack can be launched remotely. Upgrading to version… | |
| Modificada | Media (4.3) | 0.69% | — | Librenms | 17/11/2023 | 17/6/2026 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. In affected versions of LibreNMS when a user accesses their device dashboard, one request is sent to `graph.php` to access graphs generated on the particular… | |
| Modificada | Alta (7.5) | 0.60% | — | Librenms | 17/11/2023 | 17/6/2026 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. In affected versions the login method has no rate limit. An attacker may be able to leverage this vulnerability to gain access to user accounts. This issue has been… | |
| Modificada | Media (5.4) | 0.56% | — | Librenms | 17/11/2023 | 17/6/2026 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. Affected versions are subject to a cross site scripting (XSS) vulnerability in the device group popups. This issue has been addressed in commit `faf66035ea` which… | |
| Modificada | Alta (7.5) | 1.3% | — | Calibre-ebook Calibre | 22/10/2023 | 17/6/2026 | link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by default, add resources outside of the document root. | |
| Modificada | Media (6.5) | 22% | — | Librenms | 16/10/2023 | 17/6/2026 | SQL Injection in GitHub repository librenms/librenms prior to 23.10.0. | |
| Modificada | Media (6.1) | 0.64% | — | Librenms | 19/9/2023 | 17/6/2026 | Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.1. | |
| Modificada | Media (5.4) | 0.66% | — | Librenms | 15/9/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 23.9.0. | |
| Modificada | Media (5.4) | 0.66% | — | Librenms | 15/9/2023 | 17/6/2026 | Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0. | |
| Modificada | Media (5.4) | 0.69% | — | Librenms | 15/9/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 23.9.0. | |
| Modificada | Media (5.4) | 0.69% | — | Librenms | 15/9/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.9.0. | |
| Modificada | Media (6.1) | 0.67% | — | Librenms | 15/9/2023 | 17/6/2026 | Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0. | |
| Modificada | Media (5.4) | 0.53% | — | Librenms | 15/9/2023 | 17/6/2026 | Code Injection in GitHub repository librenms/librenms prior to 23.9.0. | |
| Modificada | Alta (7.5) | 0.97% | — | Ahwx Librey | 4/9/2023 | 17/6/2026 | LibreY is a fork of LibreX, a framework-less and javascript-free privacy respecting meta search engine. LibreY is subject to a Server-Side Request Forgery (SSRF) vulnerability in the `engines/google/text.php` and `engines/duckduckgo/text.php` files in versions before commit be59098abd119cda70b15bf3faac596dfd39a744.… | |
| Modificada | Crítica (9.1) | 0.95% | — | Ahwx Librey | 4/9/2023 | 17/6/2026 | LibreY is a fork of LibreX, a framework-less and javascript-free privacy respecting meta search engine. LibreY is subject to a Server-Side Request Forgery (SSRF) vulnerability in the `image_proxy.php` file of LibreY before commit 8f9b9803f231e2954e5b49987a532d28fe50a627. This vulnerability allows remote attackers to… | |
| Modificada | Media (6.5) | 0.81% | — | Libreswan | 25/8/2023 | 17/6/2026 | An issue was discovered in Libreswan 3.x and 4.x before 4.12. When an IKEv1 ISAKMP SA Informational Exchange packet contains a Delete/Notify payload followed by further Notifies that act on the ISAKMP SA, such as a duplicated Delete/Notify message, a NULL pointer dereference on the deleted state causes the pluto… | |
| Modificada | Media (6.5) | 0.81% | — | Libreswan | 25/8/2023 | 17/6/2026 | An issue was discovered in Libreswan before 4.12. When an IKEv1 Quick Mode connection configured with ID_IPV4_ADDR or ID_IPV6_ADDR receives an IDcr payload with ID_FQDN, a NULL pointer dereference causes a crash and restart of the pluto daemon. NOTE: the earliest affected version is 4.6. | |
| Modificada | Media (6.5) | 0.81% | — | Libreswan | 25/8/2023 | 17/6/2026 | An issue was discovered in Libreswan before 4.12. When an IKEv2 Child SA REKEY packet contains an invalid IPsec protocol ID number of 0 or 1, an error notify INVALID_SPI is sent back. The notify payload's protocol ID is copied from the incoming packet, but the code that verifies outgoing packets fails an assertion… | |
| Modificada | Media (6.5) | 1.0% | — | Djvulibre Project Djvulibre | 22/8/2023 | 17/6/2026 | An issue was discovered IW44EncodeCodec.cpp in djvulibre 3.5.28 in allows attackers to cause a denial of service via divide by zero. | |
| Modificada | Media (6.5) | 1.0% | — | Djvulibre Project Djvulibre | 22/8/2023 | 17/6/2026 | An issue was discovered IW44Image.cpp in djvulibre 3.5.28 in allows attackers to cause a denial of service via divide by zero. | |
| Modificada | Media (5.4) | 70% | — | Librenms | 15/8/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.8.0. |