Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
551 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 65% | — | LibreofficeFedoraproject FedoraRedhat Enterprise Linux | 10/7/2023 | 17/6/2026 | A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker. | |
| Modificada | Media (5.5) | 0.32% | — | Librecad | 28/6/2023 | 17/6/2026 | A Buffer Overflow vulnerability in importshp plugin in LibreCAD 2.2.0 allows attackers to obtain sensitive information via a crafted DBF file. | |
| Analizada | Alta (8.8) | 0.92% | — | GNU Libredwg | 23/6/2023 | 17/6/2026 | LibreDWG v0.11 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_write_TF at bits.c. | |
| Modificada | Alta (8.8) | 0.70% | — | GNU Libredwg | 23/6/2023 | 17/6/2026 | LibreDWG v0.12.5 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c. | |
| Modificada | Alta (8.8) | 0.92% | — | GNU Libredwg | 23/6/2023 | 17/6/2026 | LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_utf8_to_TU at bits.c. | |
| Analizada | Alta (8.8) | 0.92% | — | GNU Libredwg | 23/6/2023 | 17/6/2026 | LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_wcs2nlen at bits.c. | |
| Modificada | Crítica (9.8) | 0.94% | — | Openbsd LibresslOpenbsd | 16/6/2023 | 17/6/2026 | A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected. | |
| Modificada | Alta (7.5) | 1.2% | — | Libreswan | 29/5/2023 | 17/6/2026 | pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode packets. The earliest affected version is 3.28. | |
| Modificada | Media (5.3) | 2.2% | 💥 PoC | LibreofficeDebian Linux | 25/5/2023 | 17/6/2026 | Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of LibreOffice documents that used "floating frames" linked to external files, would load the contents of… | |
| Modificada | Alta (7.8) | 0.30% | — | LibreofficeDebian Linux | 25/5/2023 | 17/6/2026 | Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spreadsheet document that will cause an array index underflow when loaded. In the affected versions of LibreOffice certain malformed spreadsheet formulas, such as… | |
| Modificada | Alta (7.5) | 1.6% | — | LibreswanRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux Server AUS+1 | 17/5/2023 | 17/6/2026 | A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder… | |
| Modificada | Crítica (9.8) | 0.75% | — | Janeczku Calibre-web | 15/4/2023 | 17/6/2026 | Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20. | |
| Modificada | Crítica (9.8) | 0.77% | — | Janeczku Calibre-web | 15/4/2023 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20. | |
| Modificada | Crítica (9.8) | 0.57% | — | Openbsd LibresslOpenbsd | 15/4/2023 | 17/6/2026 | x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate chain is sometimes discarded. | |
| Modificada | Media (5.3) | 0.36% | — | Openbsd LibresslOpenbsd | 12/4/2023 | 17/6/2026 | An issue was discovered in x509/x509_verify.c in LibreSSL before 3.6.1, and in OpenBSD before 7.2 errata 001. x509_verify_ctx_add_chain does not store errors that occur during leaf certificate verification, and therefore an incorrect error is returned. This behavior occurs when there is an installed verification… | |
| Modificada | Alta (8.8) | 0.81% | — | GNU Libredwg | 1/3/2023 | 17/6/2026 | A heap-based buffer overflow vulnerability exits in GNU LibreDWG v0.12.5 via the bit_read_RC function at bits.c. | |
| Modificada | Media (6.5) | 1.6% | — | LibreswanDebian Linux | 21/2/2023 | 17/6/2026 | Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorrect selector length. | |
| Modificada | Crítica (9.8) | 0.72% | — | Librephotos Project Librephotos | 10/1/2023 | 17/6/2026 | api/views/user.py in LibrePhotos before e19e539 has incorrect access control. | |
| Modificada | Alta (7.8) | 0.31% | — | GNU Libredwg | 30/11/2022 | 17/6/2026 | LibreDWG v0.12.4.4643 was discovered to contain a heap buffer overflow via the function decode_preR13_section_hdr at decode_r11.c. | |
| Modificada | Crítica (9.8) | 0.65% | — | Librenms | 20/11/2022 | 17/6/2026 | Insufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0. | |
| Modificada | Media (4.8) | 93% | — | Librenms | 20/11/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0. | |
| Modificada | Media (5.4) | 36% | — | Librenms | 20/11/2022 | 17/6/2026 | A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Moreover, the username is not properly sanitized in the admin user overview. This enables an XSS attack that enables an attacker with a low privilege user to execute arbitrary JavaScript in the context… | |
| Modificada | Media (5.4) | 94% | — | Librenms | 20/11/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. | |
| Modificada | Media (5.4) | 94% | — | Librenms | 20/11/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. | |
| Modificada | Media (6.1) | 0.56% | — | Librenms | 20/11/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0. |