Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

551 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.93%—Librenms20/11/202217/6/2026
Deserialization of Untrusted Data in GitHub repository librenms/librenms prior to 22.10.0.
ModificadaMedia (6.1)0.49%—Librenms20/11/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.
ModificadaMedia (6.3)5.7%—LibreofficeDebian LinuxFedoraproject Fedora11/10/202217/6/2026
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice links using that scheme could be constructed to call internal macros with arbitrary…
ModificadaMedia (5.4)0.70%—Librenms17/9/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.9.0.
ModificadaMedia (6.5)0.79%—WP Libre Form Project WP Libre Form6/9/202217/6/2026
Unauthenticated Sensitive Information Disclosure vulnerability in WP Libre Form 2 plugin <= 2.0.8 at WordPress allows attackers to list and delete submissions. Affects only versions from 2.0.0 to 2.0.8.
ModificadaMedia (6.1)0.50%—Librenms30/8/202217/6/2026
LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component oxidized-cfg-check.inc.php.
ModificadaMedia (6.1)0.50%—Librenms30/8/202217/6/2026
LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component print-customoid.php.
ModificadaCrítica (9.8)1.0%—GNU Libredwg18/8/202217/6/2026
LibreDWG v0.12.4.4608 & commit f2dea29 was discovered to contain a heap use-after-free via bit_copy_chain.
ModificadaAlta (8.8)1.4%—LibreofficeDebian Linux25/7/202217/6/2026
LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where master key was poorly encoded resulting in weakening its entropy from 128 to 43 bits making the…
ModificadaAlta (7.5)1.1%—LibreofficeDebian Linux25/7/202217/6/2026
LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required initialization vector for encryption was always the same which weakens the security…
ModificadaAlta (7.5)1.2%—Libreoffice25/7/202217/6/2026
An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a macro was signed by a trusted author was done by only matching the serial number and issuer string of the used certificate with that of a trusted certificate. This is not sufficient to verify that the macro was actually…
ModificadaAlta (7.8)0.75%—GNU Libredwg23/6/202217/6/2026
LibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copy_bytes at decode_r2007.c.
ModificadaAlta (7.8)0.75%—GNU Libredwg23/6/202217/6/2026
LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c.
ModificadaAlta (7.8)0.75%—GNU Libredwg23/6/202217/6/2026
LibreDWG v0.12.4.4608 was discovered to contain a heap-buffer-overflow via the function decode_preR13_section_hdr at decode_r11.c.
ModificadaAlta (7.8)0.75%—GNU Libredwg23/6/202217/6/2026
LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function dwg_add_object at decode.c.
ModificadaAlta (7.8)0.79%—GNU Libredwg23/6/202217/6/2026
LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function dwg_add_handleref at dwg.c.
ModificadaAlta (7.8)0.75%—GNU Libredwg23/6/202217/6/2026
LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c.
ModificadaAlta (7.8)0.79%—GNU Libredwg23/6/202217/6/2026
LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function decode_preR13_section at decode_r11.c.
ModificadaAlta (7.5)1.1%—GNU Libredwg23/6/202217/6/2026
There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *' failed at dwg2dxf: decode.c:5801 in libredwg v0.12.4.4608.
ModificadaAlta (8.8)2.0%—Librehealth EHR9/6/202217/6/2026
LibreHealth EHR Base 2.0.0 allows incorrect interface/super/manage_site_files.php access.
ModificadaMedia (6.1)0.92%—Librehealth EHR8/6/202217/6/2026
LibreHealth EHR Base 2.0.0 allows interface/main/finder/finder_navigation.php patient XSS.
ModificadaMedia (6.1)0.97%—Librehealth EHR7/6/202217/6/2026
LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS.
ModificadaMedia (6.1)1.0%—Librehealth EHR6/6/202217/6/2026
LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php action XSS.
ModificadaMedia (6.1)0.97%—Librehealth EHR6/6/202217/6/2026
LibreHealth EHR Base 2.0.0 allows interface/orders/patient_match_dialog.php key XSS.
ModificadaMedia (6.1)0.97%—Librehealth EHR6/6/202217/6/2026
Cross Site scripting (XSS) vulnerability inLibreHealth EHR Base 2.0.0 via interface/usergroup/usergroup_admin_add.php Username.