Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

151 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.32%—Gnome Settings DaemonAILinux KernelAI16/6/202417/6/2026
Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate attacker to access some unintended Linux kernel USB functionality, such as USB device-specific kernel modules and filesystem…
ModificadaAlta (7.5)0.94%—Intel Inet Wireless DaemonFedoraproject Fedora3/3/202417/6/2026
p2putil.c in iNet wireless daemon (IWD) through 2.15 allows attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact because of initialization issues in situations where parsing of advertised service information fails.
ModificadaAlta (7.5)1.1%—Intel Inet Wireless Daemon22/2/202417/6/2026
The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows attackers to gain unauthorized access to a protected Wi-Fi network. An attacker can complete the EAPOL handshake by skipping Msg2/4 and instead sending Msg4/4 with an all-zero key.
ModificadaMedia (4.8)0.36%—Mdaemon Securitygateway31/12/202317/6/2026
MDaemon SecurityGateway through 9.0.3 allows XSS via a crafted Message Content Filtering rule. This might allow domain administrators to conduct attacks against global administrators.
ModificadaMedia (5.3)0.57%—Classic Lockss Daemon15/12/202317/6/2026
lockss-daemon (aka Classic LOCKSS Daemon) before 1.77.3 performs post-Unicode normalization, which may allow bypass of intended access restrictions, such as when U+1FEF is converted to a backtick.
ModificadaAlta (7.5)0.91%—Covesa Dlt-daemon17/10/202317/6/2026
Connected Vehicle Systems Alliance (COVESA) up to v2.18.8 was discovered to contain a buffer overflow via the component /shared/dlt_common.c.
ModificadaAlta (7.5)1.2%—Covesa Dlt-daemon27/2/202317/6/2026
An issue was discovered in the Connected Vehicle Systems Alliance (COVESA; formerly GENIVI) dlt-daemon through 2.18.8. Dynamic memory is not released after it is allocated in dlt-control-common.c.
AnalizadaAlta (7.5)1.2%—Musicpd Music Player Daemon26/2/202317/6/2026
In MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Drain call in certain situations involving truncated files. Eventually there is an assertion failure in libmpdclient because libqtappfw passes in a NULL pointer.
ModificadaAlta (7.5)0.93%—Musicpd Music Player Daemon10/1/202317/6/2026
An issue in MPD (Music Player Daemon) v0.23.10 allows attackers to cause a Denial of Service (DoS) via a crafted input.
ModificadaMedia (6.5)1.1%—Btcd Project BtcdLightning Network Daemon Project Lightning Network Daemon17/11/202217/6/2026
Lightning Network Daemon (lnd) is an implementation of a lightning bitcoin overlay network node. All lnd nodes before version `v0.15.4` are vulnerable to a block parsing bug that can cause a node to enter a degraded state once encountered. In this degraded state, nodes can continue to make payments and forward HTLCs,…
ModificadaMedia (5.3)0.92%—Domain Name Relay Daemon Project Domain Name Relay Daemon15/8/202217/6/2026
Misinterpretation of special domain name characters in DNRD (aka Domain Name Relay Daemon) 2.20.3 leads to cache poisoning because domain names and their associated IP addresses are cached in their misinterpreted form.
ModificadaAlta (7.5)1.00%—Domain Name Relay Daemon Project Domain Name Relay Daemon15/8/202217/6/2026
DNRD (aka Domain Name Relay Daemon) 2.20.3 forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This leads to disabling of DNSSEC protection provided by upstream resolvers.
ModificadaMedia (5.4)0.49%—Altn Mdaemon11/5/202217/6/2026
An Authenticated Reflected Cross-site scripting at BCC Parameter was discovered in MDaemon before 22.0.0 .
ModificadaMedia (5.4)0.49%—Altn Mdaemon11/5/202217/6/2026
An Authenticated Reflected Cross-site scripting at CC Parameter was discovered in MDaemon before 22.0.0 .
ModificadaAlta (7.5)1.4%—Internet Routing Registry Daemon Project Internet Routing Registry Daemon31/3/202217/6/2026
Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. IRRd did not always filter password hashes in query responses relating to `mntner` objects and database exports. This may have allowed adversaries to retrieve some of these hashes, perform a brute-force…
ModificadaAlta (8.6)1.9%—Lightning Network Daemon Project Lightning Network Daemon4/10/202117/6/2026
Lightning Labs lnd before 0.13.3-beta allows loss of funds because of dust HTLC exposure.
ModificadaCrítica (9.8)1.2%—Disc-soft Daemon Tools17/8/202117/6/2026
A memory corruption vulnerability exists in the ISO Parsing functionality of Disc Soft Ltd Deamon Tools Pro 8.3.0.0767. A specially crafted malformed file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaAlta (7.2)2.7%—Altn Mdaemon14/4/202117/6/2026
An issue was discovered in MDaemon before 20.0.4. Administrators can use Remote Administration to exploit an Arbitrary File Write vulnerability. An attacker is able to create new files in any location of the filesystem, or he may be able to modify existing files. This vulnerability may directly lead to Remote Code…
ModificadaAlta (8.8)1.6%—Altn Mdaemon14/4/202117/6/2026
An issue was discovered in MDaemon before 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient). It can be exploited via an email message. It allows an attacker to perform any action with the privileges of the attacked user.
ModificadaAlta (8.8)0.65%—Altn Mdaemon14/4/202117/6/2026
An issue was discovered in MDaemon before 20.0.4. Remote Administration allows an attacker to perform a fixation of the anti-CSRF token. In order to exploit this issue, the user has to click on a malicious URL provided by the attacker and successfully authenticate into the application. Having the value of the…
ModificadaMedia (6.1)0.93%—Altn Mdaemon14/4/202117/6/2026
An issue was discovered in MDaemon before 20.0.4. There is Reflected XSS in Webmail (aka WorldClient). It can be exploited via a GET request. It allows performing any action with the privileges of the attacked user.
ModificadaMedia (5.4)3.2%—Altn Mdaemon Webmail3/2/202117/6/2026
Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to executes code and perform a XSS attack while opening a contact list.
ModificadaMedia (5.4)3.8%—Altn Mdaemon Webmail3/2/202117/6/2026
Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipient side while forwarding an email to perform potentially malicious activities.
ModificadaMedia (5.5)0.49%—Nlnetlabs Name Server DaemonNlnetlabs UnboundDebian Linux7/12/202017/6/2026
NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that would allow for a local symlink attack. When writing the PID file, Unbound and NSD create the file if it is not there, or open an existing file for writing. In case the file…
ModificadaBaja (3.3)0.49%—Aptdaemon Project Aptdaemon31/10/202017/6/2026
There is no input validation on the Locale property in an apt transaction. An unprivileged user can supply a full path to a writable directory, which lets aptd read a file as root. Having a symlink in place results in an error message if the file exists, and no error otherwise. This way an unprivileged user can check…