Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

551 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)1.2%—Librenms9/9/201917/6/2026
An issue was discovered in LibreNMS through 1.47. Several of the scripts perform dynamic script inclusion via the include() function on user supplied input without sanitizing the values by calling basename() or a similar function. An attacker can leverage this to execute PHP code from the included file. Exploitation…
ModificadaCrítica (9.8)1.5%—Librenms9/9/201917/6/2026
An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.php and html/includes/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of user supplied input. Some parameters are filtered with mysqli_real_escape_string, which…
ModificadaCrítica (9.8)2.6%—LibreofficeOpensuse Leap6/9/201917/6/2026
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify that pre-installed scripts can be executed on various document script…
ModificadaAlta (7.8)1.8%—LibreofficeCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+26/9/201917/6/2026
LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of the LibreOffice install. Protection was…
ModificadaMedia (5.4)0.64%—Librenms28/8/201917/6/2026
LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Alert Template sections of the admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account.
ModificadaMedia (5.5)1.6%—Djvulibre Project DjvulibreDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+118/8/201917/6/2026
DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by crafting a corrupted JB2 image file that is mishandled in JB2Dict::JB2Codec::get_direct_context in libdjvu/JB2Image.h because of a missing zero-bytes check in libdjvu/GBitmap.h.
ModificadaMedia (5.5)1.8%—Djvulibre Project DjvulibreDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+118/8/201917/6/2026
In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM image file that is mishandled in libdjvu/GContainer.h.
ModificadaMedia (5.5)1.7%—Djvulibre Project DjvulibreDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+118/8/201917/6/2026
In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustion caused by a GBitmap::read_rle_raw infinite loop) by crafting a corrupted image file, related to libdjvu/DjVmDir.cpp and libdjvu/GBitmap.cpp.
ModificadaMedia (5.5)1.8%—Djvulibre Project DjvulibreDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+118/8/201917/6/2026
In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application crash in GStringRep::strdup in libdjvu/GString.cpp caused by a heap-based buffer over-read) by crafting a DJVU file.
ModificadaAlta (7.8)1.8%—Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraOpensuse Leap+115/8/201917/6/2026
LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of the LibreOffice install. Protection was…
ModificadaCrítica (9.8)78%💥 ExploitCanonical Ubuntu LinuxDebian LinuxFedoraproject FedoraOpensuse Leap+115/8/201917/6/2026
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. Protection was added, to address CVE-2019-9848, to block calling LibreLogo from document event script handers, e.g. mouse over.…
ModificadaCrítica (9.8)2.9%—Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraOpensuse Leap+115/8/201917/6/2026
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify that pre-installed scripts can be executed on various document script…
ModificadaMedia (4.3)2.6%💥 PoCLibreofficeCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux+117/7/201917/6/2026
LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where bullet graphics…
ModificadaCrítica (9.8)29%—LibreofficeCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux+117/7/201917/6/2026
LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also bundled with LibreLogo, a programmable turtle vector graphics script, which can be manipulated into executing arbitrary python commands. By…
ModificadaBaja (3.1)0.50%—LibreswanStrongswanXelerance OpenswanFedoraproject Fedora+112/6/201917/6/2026
The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.
ModificadaAlta (7.5)2.7%—Libreswan24/5/201917/6/2026
In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart. An attacker can trigger a NULL pointer dereference by initiating an IKEv2 IKE_SA_INIT exchange, followed by a bogus INFORMATIONAL exchange instead of the normallly expected IKE_AUTH exchange. This affects send_v2N_spi_response_from_state()…
ModificadaAlta (7.8)1.0%—Libreoffice9/5/201917/6/2026
A vulnerability in LibreOffice hyperlink processing allows an attacker to construct documents containing hyperlinks pointing to the location of an executable on the target users file system. If the hyperlink is activated by the victim the executable target is unconditionally launched. Under Windows and macOS when…
ModificadaCrítica (9.8)71%💥 ExploitLibrenms24/4/201917/6/2026
LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.php during creation of a new device, and then making a /ajax_output.php?id=capture&format=text&type=snmpwalk&hostname=localhost request that triggers…
ModificadaAlta (8.8)1.4%—Librenms28/3/201917/6/2026
LibreNMS through 1.47 allows SQL injection via the html/ajax_table.php sort[hostname] parameter, exploitable by authenticated users during a search.
ModificadaCrítica (9.8)22%💥 ExploitTeclib-edition Gestionnaire Libre DE Parc Informatique27/3/201917/6/2026
Teclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php.
ModificadaCrítica (9.8)2.5%—Teclib-edition Gestionnaire Libre DE Parc Informatique27/3/201917/6/2026
Teclib GLPI before 9.4.1.1 is affected by a PHP type juggling vulnerability allowing bypass of authentication. This occurs in Auth::checkPassword() (inc/auth.class.php).
ModificadaCrítica (9.8)67%💥 ExploitLibreoffice25/3/201917/6/2026
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file…
ModificadaAlta (7.5)2.8%—GNU LibredwgOpensuse Backports SLEOpensuse Leap14/3/201917/6/2026
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg.spec (earlier than CVE-2019-9776).
ModificadaAlta (7.5)2.8%—GNU LibredwgOpensuse Backports SLEOpensuse Leap14/3/201917/6/2026
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dwg_dxf_LTYPE at dwg.spec.
ModificadaAlta (7.5)2.8%—GNU LibredwgOpensuse Backports SLEOpensuse Leap14/3/201917/6/2026
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dxf_header_write at header_variables_dxf.spec.
Orbitaley — Vulnerabilidades