Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
551 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.93% | — | Librenms | 20/11/2022 | 17/6/2026 | Deserialization of Untrusted Data in GitHub repository librenms/librenms prior to 22.10.0. | |
| Modificada | Media (6.1) | 0.49% | — | Librenms | 20/11/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. | |
| Modificada | Media (6.3) | 5.7% | — | LibreofficeDebian LinuxFedoraproject Fedora | 11/10/2022 | 17/6/2026 | LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice links using that scheme could be constructed to call internal macros with arbitrary… | |
| Modificada | Media (5.4) | 0.70% | — | Librenms | 17/9/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.9.0. | |
| Modificada | Media (6.5) | 0.79% | — | WP Libre Form Project WP Libre Form | 6/9/2022 | 17/6/2026 | Unauthenticated Sensitive Information Disclosure vulnerability in WP Libre Form 2 plugin <= 2.0.8 at WordPress allows attackers to list and delete submissions. Affects only versions from 2.0.0 to 2.0.8. | |
| Modificada | Media (6.1) | 0.50% | — | Librenms | 30/8/2022 | 17/6/2026 | LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component oxidized-cfg-check.inc.php. | |
| Modificada | Media (6.1) | 0.50% | — | Librenms | 30/8/2022 | 17/6/2026 | LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component print-customoid.php. | |
| Modificada | Crítica (9.8) | 1.0% | — | GNU Libredwg | 18/8/2022 | 17/6/2026 | LibreDWG v0.12.4.4608 & commit f2dea29 was discovered to contain a heap use-after-free via bit_copy_chain. | |
| Modificada | Alta (8.8) | 1.4% | — | LibreofficeDebian Linux | 25/7/2022 | 17/6/2026 | LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where master key was poorly encoded resulting in weakening its entropy from 128 to 43 bits making the… | |
| Modificada | Alta (7.5) | 1.1% | — | LibreofficeDebian Linux | 25/7/2022 | 17/6/2026 | LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required initialization vector for encryption was always the same which weakens the security… | |
| Modificada | Alta (7.5) | 1.2% | — | Libreoffice | 25/7/2022 | 17/6/2026 | An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a macro was signed by a trusted author was done by only matching the serial number and issuer string of the used certificate with that of a trusted certificate. This is not sufficient to verify that the macro was actually… | |
| Modificada | Alta (7.8) | 0.75% | — | GNU Libredwg | 23/6/2022 | 17/6/2026 | LibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copy_bytes at decode_r2007.c. | |
| Modificada | Alta (7.8) | 0.75% | — | GNU Libredwg | 23/6/2022 | 17/6/2026 | LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c. | |
| Modificada | Alta (7.8) | 0.75% | — | GNU Libredwg | 23/6/2022 | 17/6/2026 | LibreDWG v0.12.4.4608 was discovered to contain a heap-buffer-overflow via the function decode_preR13_section_hdr at decode_r11.c. | |
| Modificada | Alta (7.8) | 0.75% | — | GNU Libredwg | 23/6/2022 | 17/6/2026 | LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function dwg_add_object at decode.c. | |
| Modificada | Alta (7.8) | 0.79% | — | GNU Libredwg | 23/6/2022 | 17/6/2026 | LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function dwg_add_handleref at dwg.c. | |
| Modificada | Alta (7.8) | 0.75% | — | GNU Libredwg | 23/6/2022 | 17/6/2026 | LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c. | |
| Modificada | Alta (7.8) | 0.79% | — | GNU Libredwg | 23/6/2022 | 17/6/2026 | LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function decode_preR13_section at decode_r11.c. | |
| Modificada | Alta (7.5) | 1.1% | — | GNU Libredwg | 23/6/2022 | 17/6/2026 | There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *' failed at dwg2dxf: decode.c:5801 in libredwg v0.12.4.4608. | |
| Modificada | Alta (8.8) | 2.0% | — | Librehealth EHR | 9/6/2022 | 17/6/2026 | LibreHealth EHR Base 2.0.0 allows incorrect interface/super/manage_site_files.php access. | |
| Modificada | Media (6.1) | 0.92% | — | Librehealth EHR | 8/6/2022 | 17/6/2026 | LibreHealth EHR Base 2.0.0 allows interface/main/finder/finder_navigation.php patient XSS. | |
| Modificada | Media (6.1) | 0.97% | — | Librehealth EHR | 7/6/2022 | 17/6/2026 | LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS. | |
| Modificada | Media (6.1) | 1.0% | — | Librehealth EHR | 6/6/2022 | 17/6/2026 | LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php action XSS. | |
| Modificada | Media (6.1) | 0.97% | — | Librehealth EHR | 6/6/2022 | 17/6/2026 | LibreHealth EHR Base 2.0.0 allows interface/orders/patient_match_dialog.php key XSS. | |
| Modificada | Media (6.1) | 0.97% | — | Librehealth EHR | 6/6/2022 | 17/6/2026 | Cross Site scripting (XSS) vulnerability inLibreHealth EHR Base 2.0.0 via interface/usergroup/usergroup_admin_add.php Username. |