Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

551 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.85%—Janeczku Calibre-web28/1/202217/6/2026
Cross-site Scripting (XSS) - Reflected in Pypi calibreweb prior to 0.6.16.
ModificadaMedia (5.5)0.90%—LibrecadFedoraproject FedoraDebian Linux25/1/202217/6/2026
In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the application using a crafted DXF document.
ModificadaAlta (7.8)1.9%—LibrecadFedoraproject FedoraDebian Linux25/1/202217/6/2026
A buffer overflow vulnerability in CDataList of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.
ModificadaAlta (8.8)6.6%—LibrecadFedoraproject FedoraDebian Linux25/1/202217/6/2026
A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.
ModificadaAlta (8.8)0.55%—Janeczku Calibre-web17/1/202217/6/2026
calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)
ModificadaCrítica (9.8)1.4%—Janeczku Calibre-web17/1/202217/6/2026
calibre-web is vulnerable to Business Logic Errors
ModificadaMedia (5.4)0.81%—Janeczku Calibre-web16/1/202217/6/2026
calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaAlta (7.5)2.5%—LibreswanFedoraproject FedoraDebian Linux15/1/202217/6/2026
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.
ModificadaMedia (6.5)0.89%—GNU Libredwg1/1/202217/6/2026
LibreDWG 0.12.4.4313 through 0.12.4.4367 has an out-of-bounds write in dwg_free_BLOCK_private (called from dwg_free_BLOCK and dwg_free_object).
ModificadaAlta (7.5)5.2%—Calibre-ebook CalibreFedoraproject Fedora7/12/202117/6/2026
calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in ebooks/conversion/preprocess.py.
ModificadaCrítica (9.8)1.5%—Librenms3/12/202117/6/2026
Librenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php.
ModificadaCrítica (9.8)1.4%—GNU Libredwg2/12/202117/6/2026
LibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13.
ModificadaAlta (7.5)1.2%—GNU Libredwg2/12/202117/6/2026
LibreDWG v0.12.3 was discovered to contain a NULL pointer dereference via out_dxfb.c.
ModificadaCrítica (9.8)1.2%—Libretime HV1/12/202117/6/2026
libretime hv3.0.0-alpha.10 is affected by a path manipulation vulnerability in /blob/master/legacy/application/modules/rest/controllers/ShowImageController.php through the rename function.
ModificadaMedia (6.1)0.65%—Librenms1/12/202117/6/2026
Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/forms/poller-groups.inc.php.
ModificadaMedia (6.1)0.65%—Librenms1/12/202117/6/2026
Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/common/alert-log.inc.php.
ModificadaAlta (8.8)2.6%—Librecad LibdxfrwDebian LinuxFedoraproject Fedora19/11/202117/6/2026
A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaAlta (8.8)2.5%—Librecad LibdxfrwDebian LinuxFedoraproject Fedora19/11/202117/6/2026
A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dxf file can lead to a use-after-free vulnerability. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaAlta (8.8)2.8%—Librecad LibdxfrwFedoraproject FedoraDebian Linux19/11/202117/6/2026
A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaAlta (8.8)0.53%—Janeczku Calibre-web16/11/202117/6/2026
In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an attacker can create a new user role with admin privileges and attacker-controlled credentials, allowing them to take over the application.
ModificadaMedia (6.1)0.65%—Librenms3/11/202117/6/2026
LibreNMS through 21.10.2 allows XSS via a widget title.
ModificadaAlta (8.1)1.5%—Calibre-ebook Calibre27/10/202116/6/2026
Race condition issues were found in Calibre at devices/linux_mount_helper.c allowing unprivileged users the ability to mount any device to anywhere.
ModificadaCrítica (9.8)2.3%—Calibre-ebook Calibre27/10/202116/6/2026
A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root.
ModificadaCrítica (9.8)2.3%—Calibre-ebook Calibre27/10/202116/6/2026
Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges.
ModificadaAlta (7.5)0.71%—LibreofficeDebian Linux12/10/202117/6/2026
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to modify a digitally…