Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
551 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.5% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated by gen-dynapi.pl). | |
| Modificada | Alta (8.1) | 1.7% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c. | |
| Modificada | Alta (8.1) | 1.7% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c. | |
| Modificada | Alta (8.1) | 1.7% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c. | |
| Modificada | Media (6.5) | 1.5% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c. | |
| Modificada | Media (6.5) | 1.4% | — | GNU LibredwgOpensuse BackportsOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c. | |
| Modificada | Alta (8.8) | 1.8% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c. | |
| Modificada | Media (6.5) | 1.4% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_LWPOLYLINE_private in dwg.spec. | |
| Modificada | Alta (8.8) | 1.5% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c. | |
| Modificada | Media (6.5) | 1.4% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode_3dsolid in dwg.spec. | |
| Modificada | Media (6.5) | 1.4% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_HATCH_private in dwg.spec. | |
| Modificada | Alta (8.8) | 1.5% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c. | |
| Modificada | Alta (8.8) | 1.4% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c. | |
| Modificada | Media (6.5) | 1.4% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_SPLINE_private in dwg.spec. | |
| Modificada | Media (6.5) | 5.8% | — | LibreofficeDebian LinuxApache Openoffice | 20/12/2019 | 16/6/2026 | LibreOffice and OpenOffice automatically open embedded content | |
| Modificada | Alta (7.5) | 3.7% | — | Djvulibre Project DjvulibreDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+1 | 7/11/2019 | 17/6/2026 | DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp. | |
| Modificada | Alta (7.8) | 3.1% | — | Libreoffice | 27/9/2019 | 17/6/2026 | LibreOffice documents can contain macros. The execution of those macros is controlled by the document security settings, typically execution of macros are blocked by default. A URL decoding flaw existed in how the urls to the macros within the document were processed and categorized, resulting in the possibility to… | |
| Modificada | Alta (8.1) | 1.2% | — | Librenms | 9/9/2019 | 17/6/2026 | An issue was discovered in LibreNMS 1.50.1. A SQL injection flaw was identified in the ajax_rulesuggest.php file where the term parameter is used insecurely in a database query for showing columns of a table, as demonstrated by an ajax_rulesuggest.php?debug=1&term= request. | |
| Modificada | Alta (7.5) | 2.2% | — | Librenms | 9/9/2019 | 17/6/2026 | An issue was discovered in LibreNMS 1.50.1. An authenticated user can perform a directory traversal attack against the /pdf.php file with a partial filename in the report parameter, to cause local file inclusion resulting in code execution. | |
| Modificada | Alta (8.8) | 1.4% | — | Librenms | 9/9/2019 | 17/6/2026 | An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.php and includes/html/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of user supplied input. Some parameters are filtered with mysqli_real_escape_string, which is only… | |
| Modificada | Alta (8.8) | 1.3% | — | Librenms | 9/9/2019 | 17/6/2026 | An issue was discovered in LibreNMS through 1.47. It does not parameterize all user supplied input within database queries, resulting in SQL injection. An authenticated attacker can subvert these database queries to extract or manipulate data, as demonstrated by the graph.php sort parameter. | |
| Modificada | Media (6.1) | 0.82% | — | Librenms | 9/9/2019 | 17/6/2026 | An issue was discovered in LibreNMS through 1.47. Many of the scripts rely on the function mysqli_escape_real_string for filtering data. However, this is particularly ineffective when returning user supplied input in an HTML or a JavaScript context, resulting in unsafe data being injected into these contexts, leading… | |
| Modificada | Alta (7.2) | 81% | 💥 Exploit | Librenms | 9/9/2019 | 17/6/2026 | An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/device/collectd.inc.php where user supplied parameters are filtered with the mysqli_escape_real_string function. This function is not the appropriate function to sanitize command arguments as it does… | |
| Modificada | Crítica (9.1) | 1.6% | — | Librenms | 9/9/2019 | 17/6/2026 | An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not enforce an actual authentication check. Several of these scripts disclose information or expose functions that are of a sensitive nature and are not expected to be publicly accessible. | |
| Modificada | Media (5.3) | 1.2% | — | Librenms | 9/9/2019 | 17/6/2026 | An issue was discovered in LibreNMS through 1.47. Information disclosure can occur: an attacker can fingerprint the exact code version installed and disclose local file paths. |