Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

551 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.5%—GNU LibredwgOpensuse Backports SLEOpensuse Leap8/1/202017/6/2026
GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated by gen-dynapi.pl).
ModificadaAlta (8.1)1.7%—GNU LibredwgOpensuse Backports SLEOpensuse Leap8/1/202017/6/2026
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.
ModificadaAlta (8.1)1.7%—GNU LibredwgOpensuse Backports SLEOpensuse Leap8/1/202017/6/2026
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.
ModificadaAlta (8.1)1.7%—GNU LibredwgOpensuse Backports SLEOpensuse Leap8/1/202017/6/2026
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c.
ModificadaMedia (6.5)1.5%—GNU LibredwgOpensuse Backports SLEOpensuse Leap8/1/202017/6/2026
GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c.
ModificadaMedia (6.5)1.4%—GNU LibredwgOpensuse BackportsOpensuse Leap8/1/202017/6/2026
GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c.
ModificadaAlta (8.8)1.8%—GNU LibredwgOpensuse Backports SLEOpensuse Leap8/1/202017/6/2026
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.
ModificadaMedia (6.5)1.4%—GNU LibredwgOpensuse Backports SLEOpensuse Leap27/12/201917/6/2026
An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_LWPOLYLINE_private in dwg.spec.
ModificadaAlta (8.8)1.5%—GNU LibredwgOpensuse Backports SLEOpensuse Leap27/12/201917/6/2026
An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.
ModificadaMedia (6.5)1.4%—GNU LibredwgOpensuse Backports SLEOpensuse Leap27/12/201917/6/2026
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode_3dsolid in dwg.spec.
ModificadaMedia (6.5)1.4%—GNU LibredwgOpensuse Backports SLEOpensuse Leap27/12/201917/6/2026
An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_HATCH_private in dwg.spec.
ModificadaAlta (8.8)1.5%—GNU LibredwgOpensuse Backports SLEOpensuse Leap27/12/201917/6/2026
An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c.
ModificadaAlta (8.8)1.4%—GNU LibredwgOpensuse Backports SLEOpensuse Leap27/12/201917/6/2026
An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c.
ModificadaMedia (6.5)1.4%—GNU LibredwgOpensuse Backports SLEOpensuse Leap27/12/201917/6/2026
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_SPLINE_private in dwg.spec.
ModificadaMedia (6.5)5.8%—LibreofficeDebian LinuxApache Openoffice20/12/201916/6/2026
LibreOffice and OpenOffice automatically open embedded content
ModificadaAlta (7.5)3.7%—Djvulibre Project DjvulibreDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+17/11/201917/6/2026
DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp.
ModificadaAlta (7.8)3.1%—Libreoffice27/9/201917/6/2026
LibreOffice documents can contain macros. The execution of those macros is controlled by the document security settings, typically execution of macros are blocked by default. A URL decoding flaw existed in how the urls to the macros within the document were processed and categorized, resulting in the possibility to…
ModificadaAlta (8.1)1.2%—Librenms9/9/201917/6/2026
An issue was discovered in LibreNMS 1.50.1. A SQL injection flaw was identified in the ajax_rulesuggest.php file where the term parameter is used insecurely in a database query for showing columns of a table, as demonstrated by an ajax_rulesuggest.php?debug=1&term= request.
ModificadaAlta (7.5)2.2%—Librenms9/9/201917/6/2026
An issue was discovered in LibreNMS 1.50.1. An authenticated user can perform a directory traversal attack against the /pdf.php file with a partial filename in the report parameter, to cause local file inclusion resulting in code execution.
ModificadaAlta (8.8)1.4%—Librenms9/9/201917/6/2026
An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.php and includes/html/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of user supplied input. Some parameters are filtered with mysqli_real_escape_string, which is only…
ModificadaAlta (8.8)1.3%—Librenms9/9/201917/6/2026
An issue was discovered in LibreNMS through 1.47. It does not parameterize all user supplied input within database queries, resulting in SQL injection. An authenticated attacker can subvert these database queries to extract or manipulate data, as demonstrated by the graph.php sort parameter.
ModificadaMedia (6.1)0.82%—Librenms9/9/201917/6/2026
An issue was discovered in LibreNMS through 1.47. Many of the scripts rely on the function mysqli_escape_real_string for filtering data. However, this is particularly ineffective when returning user supplied input in an HTML or a JavaScript context, resulting in unsafe data being injected into these contexts, leading…
ModificadaAlta (7.2)81%💥 ExploitLibrenms9/9/201917/6/2026
An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/device/collectd.inc.php where user supplied parameters are filtered with the mysqli_escape_real_string function. This function is not the appropriate function to sanitize command arguments as it does…
ModificadaCrítica (9.1)1.6%—Librenms9/9/201917/6/2026
An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not enforce an actual authentication check. Several of these scripts disclose information or expose functions that are of a sensitive nature and are not expected to be publicly accessible.
ModificadaMedia (5.3)1.2%—Librenms9/9/201917/6/2026
An issue was discovered in LibreNMS through 1.47. Information disclosure can occur: an attacker can fingerprint the exact code version installed and disclose local file paths.