Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
551 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.85% | — | Janeczku Calibre-web | 28/1/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in Pypi calibreweb prior to 0.6.16. | |
| Modificada | Media (5.5) | 0.90% | — | LibrecadFedoraproject FedoraDebian Linux | 25/1/2022 | 17/6/2026 | In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the application using a crafted DXF document. | |
| Modificada | Alta (7.8) | 1.9% | — | LibrecadFedoraproject FedoraDebian Linux | 25/1/2022 | 17/6/2026 | A buffer overflow vulnerability in CDataList of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document. | |
| Modificada | Alta (8.8) | 6.6% | — | LibrecadFedoraproject FedoraDebian Linux | 25/1/2022 | 17/6/2026 | A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document. | |
| Modificada | Alta (8.8) | 0.55% | — | Janeczku Calibre-web | 17/1/2022 | 17/6/2026 | calibre-web is vulnerable to Cross-Site Request Forgery (CSRF) | |
| Modificada | Crítica (9.8) | 1.4% | — | Janeczku Calibre-web | 17/1/2022 | 17/6/2026 | calibre-web is vulnerable to Business Logic Errors | |
| Modificada | Media (5.4) | 0.81% | — | Janeczku Calibre-web | 16/1/2022 | 17/6/2026 | calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Alta (7.5) | 2.5% | — | LibreswanFedoraproject FedoraDebian Linux | 15/1/2022 | 17/6/2026 | Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6. | |
| Modificada | Media (6.5) | 0.89% | — | GNU Libredwg | 1/1/2022 | 17/6/2026 | LibreDWG 0.12.4.4313 through 0.12.4.4367 has an out-of-bounds write in dwg_free_BLOCK_private (called from dwg_free_BLOCK and dwg_free_object). | |
| Modificada | Alta (7.5) | 5.2% | — | Calibre-ebook CalibreFedoraproject Fedora | 7/12/2021 | 17/6/2026 | calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in ebooks/conversion/preprocess.py. | |
| Modificada | Crítica (9.8) | 1.5% | — | Librenms | 3/12/2021 | 17/6/2026 | Librenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php. | |
| Modificada | Crítica (9.8) | 1.4% | — | GNU Libredwg | 2/12/2021 | 17/6/2026 | LibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13. | |
| Modificada | Alta (7.5) | 1.2% | — | GNU Libredwg | 2/12/2021 | 17/6/2026 | LibreDWG v0.12.3 was discovered to contain a NULL pointer dereference via out_dxfb.c. | |
| Modificada | Crítica (9.8) | 1.2% | — | Libretime HV | 1/12/2021 | 17/6/2026 | libretime hv3.0.0-alpha.10 is affected by a path manipulation vulnerability in /blob/master/legacy/application/modules/rest/controllers/ShowImageController.php through the rename function. | |
| Modificada | Media (6.1) | 0.65% | — | Librenms | 1/12/2021 | 17/6/2026 | Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/forms/poller-groups.inc.php. | |
| Modificada | Media (6.1) | 0.65% | — | Librenms | 1/12/2021 | 17/6/2026 | Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/common/alert-log.inc.php. | |
| Modificada | Alta (8.8) | 2.6% | — | Librecad LibdxfrwDebian LinuxFedoraproject Fedora | 19/11/2021 | 17/6/2026 | A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 2.5% | — | Librecad LibdxfrwDebian LinuxFedoraproject Fedora | 19/11/2021 | 17/6/2026 | A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dxf file can lead to a use-after-free vulnerability. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 2.8% | — | Librecad LibdxfrwFedoraproject FedoraDebian Linux | 19/11/2021 | 17/6/2026 | A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 0.53% | — | Janeczku Calibre-web | 16/11/2021 | 17/6/2026 | In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an attacker can create a new user role with admin privileges and attacker-controlled credentials, allowing them to take over the application. | |
| Modificada | Media (6.1) | 0.65% | — | Librenms | 3/11/2021 | 17/6/2026 | LibreNMS through 21.10.2 allows XSS via a widget title. | |
| Modificada | Alta (8.1) | 1.5% | — | Calibre-ebook Calibre | 27/10/2021 | 16/6/2026 | Race condition issues were found in Calibre at devices/linux_mount_helper.c allowing unprivileged users the ability to mount any device to anywhere. | |
| Modificada | Crítica (9.8) | 2.3% | — | Calibre-ebook Calibre | 27/10/2021 | 16/6/2026 | A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root. | |
| Modificada | Crítica (9.8) | 2.3% | — | Calibre-ebook Calibre | 27/10/2021 | 16/6/2026 | Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges. | |
| Modificada | Alta (7.5) | 0.71% | — | LibreofficeDebian Linux | 12/10/2021 | 17/6/2026 | LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to modify a digitally… |