Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
151 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.32% | — | Gnome Settings DaemonAILinux KernelAI | 16/6/2024 | 17/6/2026 | Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate attacker to access some unintended Linux kernel USB functionality, such as USB device-specific kernel modules and filesystem… | |
| Modificada | Alta (7.5) | 0.94% | — | Intel Inet Wireless DaemonFedoraproject Fedora | 3/3/2024 | 17/6/2026 | p2putil.c in iNet wireless daemon (IWD) through 2.15 allows attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact because of initialization issues in situations where parsing of advertised service information fails. | |
| Modificada | Alta (7.5) | 1.1% | — | Intel Inet Wireless Daemon | 22/2/2024 | 17/6/2026 | The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows attackers to gain unauthorized access to a protected Wi-Fi network. An attacker can complete the EAPOL handshake by skipping Msg2/4 and instead sending Msg4/4 with an all-zero key. | |
| Modificada | Media (4.8) | 0.36% | — | Mdaemon Securitygateway | 31/12/2023 | 17/6/2026 | MDaemon SecurityGateway through 9.0.3 allows XSS via a crafted Message Content Filtering rule. This might allow domain administrators to conduct attacks against global administrators. | |
| Modificada | Media (5.3) | 0.57% | — | Classic Lockss Daemon | 15/12/2023 | 17/6/2026 | lockss-daemon (aka Classic LOCKSS Daemon) before 1.77.3 performs post-Unicode normalization, which may allow bypass of intended access restrictions, such as when U+1FEF is converted to a backtick. | |
| Modificada | Alta (7.5) | 0.91% | — | Covesa Dlt-daemon | 17/10/2023 | 17/6/2026 | Connected Vehicle Systems Alliance (COVESA) up to v2.18.8 was discovered to contain a buffer overflow via the component /shared/dlt_common.c. | |
| Modificada | Alta (7.5) | 1.2% | — | Covesa Dlt-daemon | 27/2/2023 | 17/6/2026 | An issue was discovered in the Connected Vehicle Systems Alliance (COVESA; formerly GENIVI) dlt-daemon through 2.18.8. Dynamic memory is not released after it is allocated in dlt-control-common.c. | |
| Analizada | Alta (7.5) | 1.2% | — | Musicpd Music Player Daemon | 26/2/2023 | 17/6/2026 | In MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Drain call in certain situations involving truncated files. Eventually there is an assertion failure in libmpdclient because libqtappfw passes in a NULL pointer. | |
| Modificada | Alta (7.5) | 0.93% | — | Musicpd Music Player Daemon | 10/1/2023 | 17/6/2026 | An issue in MPD (Music Player Daemon) v0.23.10 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Modificada | Media (6.5) | 1.1% | — | Btcd Project BtcdLightning Network Daemon Project Lightning Network Daemon | 17/11/2022 | 17/6/2026 | Lightning Network Daemon (lnd) is an implementation of a lightning bitcoin overlay network node. All lnd nodes before version `v0.15.4` are vulnerable to a block parsing bug that can cause a node to enter a degraded state once encountered. In this degraded state, nodes can continue to make payments and forward HTLCs,… | |
| Modificada | Media (5.3) | 0.92% | — | Domain Name Relay Daemon Project Domain Name Relay Daemon | 15/8/2022 | 17/6/2026 | Misinterpretation of special domain name characters in DNRD (aka Domain Name Relay Daemon) 2.20.3 leads to cache poisoning because domain names and their associated IP addresses are cached in their misinterpreted form. | |
| Modificada | Alta (7.5) | 1.00% | — | Domain Name Relay Daemon Project Domain Name Relay Daemon | 15/8/2022 | 17/6/2026 | DNRD (aka Domain Name Relay Daemon) 2.20.3 forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This leads to disabling of DNSSEC protection provided by upstream resolvers. | |
| Modificada | Media (5.4) | 0.49% | — | Altn Mdaemon | 11/5/2022 | 17/6/2026 | An Authenticated Reflected Cross-site scripting at BCC Parameter was discovered in MDaemon before 22.0.0 . | |
| Modificada | Media (5.4) | 0.49% | — | Altn Mdaemon | 11/5/2022 | 17/6/2026 | An Authenticated Reflected Cross-site scripting at CC Parameter was discovered in MDaemon before 22.0.0 . | |
| Modificada | Alta (7.5) | 1.4% | — | Internet Routing Registry Daemon Project Internet Routing Registry Daemon | 31/3/2022 | 17/6/2026 | Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. IRRd did not always filter password hashes in query responses relating to `mntner` objects and database exports. This may have allowed adversaries to retrieve some of these hashes, perform a brute-force… | |
| Modificada | Alta (8.6) | 1.9% | — | Lightning Network Daemon Project Lightning Network Daemon | 4/10/2021 | 17/6/2026 | Lightning Labs lnd before 0.13.3-beta allows loss of funds because of dust HTLC exposure. | |
| Modificada | Crítica (9.8) | 1.2% | — | Disc-soft Daemon Tools | 17/8/2021 | 17/6/2026 | A memory corruption vulnerability exists in the ISO Parsing functionality of Disc Soft Ltd Deamon Tools Pro 8.3.0.0767. A specially crafted malformed file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Alta (7.2) | 2.7% | — | Altn Mdaemon | 14/4/2021 | 17/6/2026 | An issue was discovered in MDaemon before 20.0.4. Administrators can use Remote Administration to exploit an Arbitrary File Write vulnerability. An attacker is able to create new files in any location of the filesystem, or he may be able to modify existing files. This vulnerability may directly lead to Remote Code… | |
| Modificada | Alta (8.8) | 1.6% | — | Altn Mdaemon | 14/4/2021 | 17/6/2026 | An issue was discovered in MDaemon before 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient). It can be exploited via an email message. It allows an attacker to perform any action with the privileges of the attacked user. | |
| Modificada | Alta (8.8) | 0.65% | — | Altn Mdaemon | 14/4/2021 | 17/6/2026 | An issue was discovered in MDaemon before 20.0.4. Remote Administration allows an attacker to perform a fixation of the anti-CSRF token. In order to exploit this issue, the user has to click on a malicious URL provided by the attacker and successfully authenticate into the application. Having the value of the… | |
| Modificada | Media (6.1) | 0.93% | — | Altn Mdaemon | 14/4/2021 | 17/6/2026 | An issue was discovered in MDaemon before 20.0.4. There is Reflected XSS in Webmail (aka WorldClient). It can be exploited via a GET request. It allows performing any action with the privileges of the attacked user. | |
| Modificada | Media (5.4) | 3.2% | — | Altn Mdaemon Webmail | 3/2/2021 | 17/6/2026 | Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to executes code and perform a XSS attack while opening a contact list. | |
| Modificada | Media (5.4) | 3.8% | — | Altn Mdaemon Webmail | 3/2/2021 | 17/6/2026 | Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipient side while forwarding an email to perform potentially malicious activities. | |
| Modificada | Media (5.5) | 0.49% | — | Nlnetlabs Name Server DaemonNlnetlabs UnboundDebian Linux | 7/12/2020 | 17/6/2026 | NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that would allow for a local symlink attack. When writing the PID file, Unbound and NSD create the file if it is not there, or open an existing file for writing. In case the file… | |
| Modificada | Baja (3.3) | 0.49% | — | Aptdaemon Project Aptdaemon | 31/10/2020 | 17/6/2026 | There is no input validation on the Locale property in an apt transaction. An unprivileged user can supply a full path to a writable directory, which lets aptd read a file as root. Having a symlink in place results in an error message if the file exists, and no error otherwise. This way an unprivileged user can check… |