Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
551 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_B ../../src/bits.c:135. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_search_sentinel ../../src/bits.c:1985. | |
| Modificada | Media (6.5) | 0.92% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | An issue was discovered in GNU LibreDWG 0.10. Crafted input will lead to an memory leak in dwg_decode_eed ../../src/decode.c:3638. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_appinfo ../../src/decode.c:2842. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_preview ../../src/decode.c:3175. | |
| Modificada | Media (6.5) | 0.86% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A null pointer deference issue exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2337. | |
| Modificada | Media (6.5) | 0.86% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A null pointer deference issue exists in GNU LibreDWG 0.10 via get_bmp ../../programs/dwgbmp.c:164. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_classes ../../src/decode.c:2440. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2417. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulneraibility exists in GNU LibreDWG 0.10 via bit_calc_CRC ../../src/bits.c:2213. | |
| Modificada | Alta (7.8) | 0.89% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2379. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641via htmlescape ../../programs/escape.c:51. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:48. | |
| Modificada | Media (6.5) | 0.91% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A null pointer dereference issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:29. which causes a denial of service (application crash). | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heab based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:46. | |
| Modificada | Media (6.5) | 0.91% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A null pointer deference issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114, which causes a denial of service (application crash). | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlwescape ../../programs/escape.c:97. | |
| Modificada | Alta (7.8) | 0.81% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114. | |
| Modificada | Crítica (9.8) | 1.6% | — | Librewireless LS9 Firmware | 3/5/2021 | 17/6/2026 | An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a Authentication Bypass in the Web Interface. This interface does not properly restrict access to internal functionality. Despite presenting a password login page on first access, authentication is not required to access privileged… | |
| Modificada | Crítica (9.8) | 1.8% | — | Librewireless LS9 Firmware | 3/5/2021 | 17/6/2026 | An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is Unauthenticated Root ADB Access Over TCP. The LS9 web interface provides functionality to access ADB over TCP. This is not enabled by default, but can be enabled by sending a crafted request to a web management interface endpoint. Requests… | |
| Modificada | Alta (7.5) | 1.2% | — | Librewireless LS9 Firmware | 3/5/2021 | 17/6/2026 | An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service GETPASS Configuration Password Information Leak. The luci_service daemon running on port 7777 does not require authentication to return the device configuration password in cleartext when using the GETPASS command. As such, any… | |
| Modificada | Alta (7.5) | 1.1% | — | Librewireless LS9 Firmware | 3/5/2021 | 17/6/2026 | An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service Read_ NVRAM Direct Access Information Leak. The luci_service deamon running on port 7777 provides a sub-category of commands for which Read_ is prepended. Commands in this category are able to directly read the contents of the… | |
| Modificada | Alta (8.8) | 5.0% | — | Libreoffice | 3/5/2021 | 17/6/2026 | In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist can be circumvented by manipulating the link so it doesn't match the denylist but results in ShellExecute attempting to launch an executable type. | |
| Modificada | Alta (7.8) | 1.3% | — | Libretro Retroarch | 7/4/2021 | 9/7/2026 | The text-to-speech engine in libretro RetroArch for Windows 1.9.0 passes unsanitized input to PowerShell through platform_win32.c via the accessibility_speak_windows function, which allows attackers who have write access on filesystems that are used by RetroArch to execute code via command injection using specially a… | |
| Modificada | Alta (8.8) | 2.3% | — | Librenms | 8/2/2021 | 17/6/2026 | A second-order SQL injection issue in Widgets/TopDevicesController.php (aka the Top Devices dashboard widget) of LibreNMS before 21.1.0 allows remote authenticated attackers to execute arbitrary SQL commands via the sort_order parameter against the /ajax/form/widget-settings endpoint. |