Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
551 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.73% | — | LibreofficeDebian Linux | 11/10/2021 | 17/6/2026 | LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally… | |
| Modificada | Media (5.4) | 0.55% | — | Janeczku Calibre-web | 4/10/2021 | 17/6/2026 | In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access to edit the metadata information, can inject JavaScript payload in the description field. When a victim tries to open the file, XSS will be triggered. | |
| Modificada | Media (5.5) | 0.65% | — | Openbsd Libressl | 24/9/2021 | 17/6/2026 | x509_constraints_parse_mailbox in lib/libcrypto/x509/x509_constraints.c in LibreSSL through 3.4.0 has a stack-based buffer over-read. When the input exceeds DOMAIN_PART_MAX_LEN, the buffer lacks '\0' termination. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 20/9/2021 | 17/6/2026 | An issue was discovered in libredwg through v0.10.1.3751. bit_wcs2nlen() in bits.c has a heap-based buffer overflow. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 20/9/2021 | 17/6/2026 | An issue was discovered in libredwg through v0.10.1.3751. dwg_free_MATERIAL_private() in dwg.spec has a double free. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 20/9/2021 | 17/6/2026 | An issue was discovered in libredwg through v0.10.1.3751. appinfo_private() in decode.c has a heap-based buffer overflow. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 20/9/2021 | 17/6/2026 | An issue was discovered in libredwg through v0.10.1.3751. bit_read_fixed() in bits.c has a heap-based buffer overflow. | |
| Modificada | Media (6.5) | 0.86% | — | GNU Libredwg | 20/9/2021 | 17/6/2026 | An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function check_POLYLINE_handles() located in decode.c. It allows an attacker to cause Denial of Service. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 20/9/2021 | 17/6/2026 | An issue was discovered in libredwg through v0.10.1.3751. bit_wcs2len() in bits.c has a heap-based buffer overflow. | |
| Modificada | Media (6.5) | 0.87% | — | GNU Libredwg | 20/9/2021 | 17/6/2026 | An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function bit_read_BB() located in bits.c. It allows an attacker to cause Denial of Service. | |
| Modificada | Media (5.4) | 0.78% | — | Librenms | 8/9/2021 | 17/6/2026 | In LibreNMS < 21.3.0, a stored XSS vulnerability was identified in the API Access page due to insufficient sanitization of the $api->description variable. As a result, arbitrary Javascript code can get executed. | |
| Modificada | Alta (8.8) | 1.3% | — | GNU Libredwg | 1/7/2021 | 17/6/2026 | GNU LibreDWG 0.12.3.4163 through 0.12.3.4191 has a double-free in bit_chain_free (called from dwg_encode_MTEXT and dwg_encode_add_object). | |
| Modificada | Alta (7.1) | 0.88% | — | Openbsd Libressl | 1/7/2021 | 17/6/2026 | LibreSSL 2.9.1 through 3.2.1 has an out-of-bounds read in asn1_item_print_ctx (called from asn1_template_print_ctx). | |
| Modificada | Alta (7.1) | 0.88% | — | Openbsd Libressl | 1/7/2021 | 17/6/2026 | LibreSSL 2.9.1 through 3.2.1 has a heap-based buffer over-read in do_print_ex (called from asn1_item_print_ctx and ASN1_item_print). | |
| Modificada | Media (5.5) | 1.0% | — | Djvulibre Project DjvulibreDebian LinuxFedoraproject Fedora | 30/6/2021 | 17/6/2026 | An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to crash and segmentation fault. This flaw affects DjVuLibre versions prior to 3.5.28. | |
| Modificada | Alta (7.8) | 0.91% | — | Djvulibre Project DjvulibreDebian Linux | 24/6/2021 | 17/6/2026 | A flaw was found in djvulibre-3.5.28 and earlier. A Stack overflow in function DJVU::DjVuDocument::get_djvu_file() via crafted djvu file may lead to application crash and other consequences. | |
| Modificada | Alta (7.8) | 0.96% | — | Djvulibre Project DjvulibreDebian Linux | 24/6/2021 | 17/6/2026 | A flaw was found in djvulibre-3.5.28 and earlier. A heap buffer overflow in function DJVU::GBitmap::decode() via crafted djvu file may lead to application crash and other consequences. | |
| Modificada | Alta (7.8) | 0.89% | — | Djvulibre Project DjvulibreDebian Linux | 24/6/2021 | 17/6/2026 | A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds read in function DJVU::DataPool::has_data() via crafted djvu file may lead to application crash and other consequences. | |
| Modificada | Alta (7.8) | 0.84% | — | Djvulibre Project DjvulibreDebian Linux | 24/6/2021 | 17/6/2026 | A flaw was found in djvulibre-3.5.28 and earlier. An integer overflow in function render() in tools/ddjvu via crafted djvu file may lead to application crash and other consequences. | |
| Modificada | Alta (7.8) | 0.84% | — | Djvulibre Project DjvulibreDebian Linux | 24/6/2021 | 17/6/2026 | A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds write in function DJVU::filter_bv() via crafted djvu file may lead to application crash and other consequences. | |
| Modificada | Media (5.5) | 0.63% | — | GNU Libredwg | 18/5/2021 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the read_system_page function at libredwg-0.10.1/src/decode_r2007.c:666:5, which causes a denial of service by submitting a dwg file. | |
| Modificada | Alta (8.8) | 1.5% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | GNU LibreDWG 0.10 is affected by: memcpy-param-overlap. The impact is: execute arbitrary code (remote). The component is: read_2004_section_header ../../src/decode.c:2580. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_RC ../../src/bits.c:318. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_revhistory ../../src/decode.c:3051. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_handles ../../src/decode.c:2637. |