Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
551 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.1% | — | Code-industry Master PDF EditorFoxitsoftware Foxit ReaderFoxitsoftware PhantompdfGonitro Nitro PRO+9 | 7/1/2021 | 17/6/2026 | The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature to add pages or annotations, Body Updates… | |
| Modificada | Alta (8.8) | 2.5% | — | Librehealth EHR | 1/9/2020 | 17/6/2026 | interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted image. | |
| Modificada | Alta (8) | 2.5% | — | Redhat LibrepoOpensuse Backports SLEOpensuse LeapFedoraproject Fedora | 30/8/2020 | 17/6/2026 | A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the targeted system via path traversal.… | |
| Modificada | Alta (8.8) | 1.9% | — | Librenms | 21/7/2020 | 17/6/2026 | An issue was discovered in LibreNMS before 1.65.1. It has insufficient access control for normal users because of "'guard' => 'admin'" instead of "'middleware' => ['can:admin']" in routes/web.php. | |
| Modificada | Media (6.5) | 2.2% | 💥 PoC | Librenms | 21/7/2020 | 17/6/2026 | In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST parameter to ajax_form.php. | |
| Modificada | Media (6.5) | 1.5% | — | GNU Libredwg | 17/7/2020 | 17/6/2026 | GNU LibreDWG before 0.11 allows NULL pointer dereferences via crafted input files. | |
| Modificada | Alta (8.1) | 1.2% | — | GNU Libredwg | 16/7/2020 | 17/6/2026 | An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in bit_write_TF in bits.c. | |
| Modificada | Crítica (9.8) | 1.9% | — | GNU Libredwg | 16/7/2020 | 17/6/2026 | An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_common_entity_handle_data in common_entity_handle_data.spec. | |
| Modificada | Alta (8.1) | 1.2% | — | GNU Libredwg | 16/7/2020 | 17/6/2026 | An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in dwg_encode_entity in common_entity_data.spec. | |
| Modificada | Alta (8.8) | 1.3% | — | GNU Libredwg | 16/7/2020 | 17/6/2026 | An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a stack overflow in bits.c, possibly related to bit_read_TF. | |
| Modificada | Media (6.5) | 1.0% | — | GNU Libredwg | 16/7/2020 | 17/6/2026 | An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to denial of service in bit_calc_CRC in bits.c, related to a for loop. | |
| Modificada | Alta (8.1) | 1.2% | — | GNU Libredwg | 16/7/2020 | 17/6/2026 | An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in decode_R13_R2000 in decode.c, a different vulnerability than CVE-2019-20011. | |
| Modificada | Alta (7.5) | 1.6% | — | GNU Libredwg | 16/7/2020 | 17/6/2026 | An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_LWPOLYLINE in dwg.spec. | |
| Modificada | Alta (8.8) | 2.0% | — | Librehealth EHR | 15/7/2020 | 17/6/2026 | LibreHealth EMR v2.0.0 is affected by a Local File Inclusion issue allowing arbitrary PHP to be included and executed within the EMR application. | |
| Modificada | Alta (8.8) | 0.64% | — | Librehealth EHR | 15/7/2020 | 17/6/2026 | LibreHealth EMR v2.0.0 is affected by systemic CSRF. | |
| Modificada | Media (4.3) | 0.95% | — | Librehealth EHR | 15/7/2020 | 17/6/2026 | LibreHealth EMR v2.0.0 is affected by SQL injection allowing low-privilege authenticated users to enumerate the database. | |
| Modificada | Crítica (9) | 1.3% | — | Librehealth EHR | 15/7/2020 | 17/6/2026 | LibreHealth EMR v2.0.0 is vulnerable to XSS that results in the ability to force arbitrary actions on behalf of other users including administrators. | |
| Modificada | Media (6.5) | 1.7% | — | LibreofficeOpensuse LeapFedoraproject Fedora | 8/6/2020 | 17/6/2026 | ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other… | |
| Modificada | Media (5.3) | 1.9% | — | LibreofficeFedoraproject FedoraOpensuse Leap | 8/6/2020 | 17/6/2026 | LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where remote graphic… | |
| Modificada | Media (5.3) | 1.3% | — | LibreofficeOpensuse Leap | 18/5/2020 | 17/6/2026 | If LibreOffice has an encrypted document open and crashes, that document is auto-saved encrypted. On restart, LibreOffice offers to restore the document and prompts for the password to decrypt it. If the recovery is successful, and if the file format of the recovered document was not LibreOffice's default ODF file… | |
| Modificada | Alta (7.5) | 3.6% | — | Libreswan | 12/5/2020 | 17/6/2026 | An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unauthenticated attacker could use this flaw to crash libreswan by sending specially-crafted IKEv1 Informational Exchange packets. The daemon respawns after the crash. | |
| Modificada | Crítica (9.8) | 1.4% | — | Janeczku Calibre-web | 4/5/2020 | 17/6/2026 | Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key. | |
| Modificada | Alta (8.8) | 0.63% | — | Abbott Freestyle Libre Firmware | 16/2/2020 | 17/6/2026 | Older generation Abbott FreeStyle Libre sensors allow remote attackers within close proximity to enable write access to memory via a specific NFC unlock command. NOTE: The vulnerability is not present in the FreeStyle Libre 14-day in the U.S (announced in August 2018) and FreeStyle Libre 2 outside the U.S (announced… | |
| Modificada | Alta (7.5) | 2.0% | — | Openbsd LibresslOpensuse | 23/1/2020 | 17/6/2026 | Memory leak in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (memory consumption) via a large number of ASN.1 object identifiers in X.509 certificates. | |
| Modificada | Crítica (9.8) | 3.5% | — | Openbsd LibresslOpensuse | 23/1/2020 | 17/6/2026 | Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (program crash) or possible execute arbitrary code via a crafted X.509 certificate, which triggers a stack-based buffer overflow. Note: this vulnerability exists because of an incorrect fix for… |