Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
551 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.26% | — | LibrenmsAI | 1/9/2026 | 8/9/2026 | LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabilities in VRF display pages where mplsVpnVrfDescription, vrf_name, and mplsVpnVrfRouteDistinguisher fields from SNMP polling are rendered without sanitization. Attackers controlling a monitored network device can inject arbitrary JavaScript through… | |
| Aplazada | Alta (8.7) | 0.86% | — | LibrenmsAI | 1/9/2026 | 8/9/2026 | LibreNMS versions before 26.5.0 contain a remote code execution vulnerability in the AboutController where the snmpget configuration parameter is passed to shell_exec() without proper validation. An authenticated administrator can modify the snmpget configuration to point to a malicious executable file and trigger… | |
| Aplazada | Crítica (9.2) | 0.38% | — | LibrenmsAIOxidizedAI | 1/9/2026 | 8/9/2026 | LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized integration URL (oxidized.url) into the device showconfig page without applying htmlspecialchars(). An administrator who points the Oxidized URL at an attacker-controlled server (SSRF) can… | |
| Aplazada | Media (4.8) | 0.25% | — | LibrenmsAI | 1/9/2026 | 8/9/2026 | LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr.<graphtype> configuration settings, which are echoed verbatim without HTML escaping in includes/html/pages/graphs.inc.php. An administrator can store a malicious HTML payload that executes in the browser of any… | |
| Aplazada | Media (6.5) | 0.42% | — | Libreoffice-convertAI | 27/8/2026 | 9/9/2026 | libreoffice-convert is a Node.js module for converting office documents to different formats. Prior to 1.8.2, index.js uses the caller-controlled options.fileName value in path.join(tempDir.name, fileName) without reducing it to a base name. A filename containing ../ can escape the temporary directory because… | |
| Aplazada | Alta (8.6) | 1.6% | — | LibrenmsAI | 26/8/2026 | 9/9/2026 | LibreNMS is a network monitoring system. In versions from 21.6.0 up to 26.5.0, the Signal alert transport is vulnerable to command injection because the signal-cli path and the Recipient field of an alert transport entry are insufficiently escaped before being passed to an exec call. An authenticated administrator can… | |
| Aplazada | Media (5.4) | 0.24% | — | LibrenmsAI | 26/8/2026 | 9/9/2026 | LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable to reflected cross-site scripting through the user-supplied instance and vmid GET parameters, which are reflected into the page title without adequate encoding. The parameters are placed into the… | |
| Aplazada | Alta (8.8) | 0.46% | — | LibrenmsAI | 26/8/2026 | 3/9/2026 | An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the address parameter in the /ajax_table.php API endpoint. | |
| Aplazada | Alta (8.8) | 0.34% | — | LibrenmsAI | 26/8/2026 | 3/9/2026 | An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the sort parameter in the /ajax_table.php API endpoint. This affects address-search.inc.php, alertlog.inc.php, arp-search.inc.php,… | |
| Aplazada | Alta (8.8) | 1.1% | — | LibrenmsAI | 26/8/2026 | 3/9/2026 | An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the /graph.php API endpoint. | |
| Aplazada | Alta (8.6) | 0.54% | — | LibrenmsAI | 26/8/2026 | 9/9/2026 | LibreNMS’s Virtualization Discovery module is vulnerable to command line injection. An authenticated admin user can execute arbitrary code on the host server. | |
| Aplazada | Crítica (9.3) | 0.52% | — | LibreAI | 18/8/2026 | 18/9/2026 | libre is a generic library for real-time communications with asynchronous input and output support. Prior to 4.8.1, the websock_decode() function in src/websock/websock.c contains an integer overflow when validating a masked WebSocket frame that uses the 64-bit extended length encoding. The expression 4 + hdr->len can… | |
| Aplazada | Alta (7.5) | 0.44% | — | Calibre-ebook CalibreAI | 11/8/2026 | 9/9/2026 | calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{library_id}/{book_id}/{fmt} in src/calibre/srv/books.py omits needs_db_write=True, causing Router.dispatch() to skip ctx.check_for_write_access() before update_annotations() passes attacker-controlled JSON… | |
| Aplazada | Alta (8.5) | 0.20% | — | Calibre-ebook CalibreAI | 11/8/2026 | 9/9/2026 | calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or similar file through program: and a nested template() call whose formatter does not inherit allow_python_templates=False, allowing a nested python: template to reach… | |
| Pendiente de análisis | Alta (8.2) | 0.27% | — | OpensslAIGoogle BoringsslAICryptography.io CryptographyAIOpenbsd LibresslAI | 3/8/2026 | 10/9/2026 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the… | |
| Pendiente de análisis | Media (6.8) | 0.25% | — | Gnome LibrestAI | 22/7/2026 | 1/9/2026 | A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random… | |
| Aplazada | Baja (1.9) | 0.18% | — | GNU LibredwgAI | 13/7/2026 | 13/7/2026 | A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035. This impacts the function decompress_R2004_section of the file src/decode.c of the component R2004 Section Decompression. Executing a manipulation can lead to heap-based buffer overflow. The attack requires local access. The exploit has been publicly… | |
| Aplazada | Alta (7.5) | 1.5% | 💥 Exploit | LibreofficeAIThecodingmachine GotenbergAI | 10/7/2026 | 13/7/2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.34.0, Gotenberg's /forms/libreoffice/convert endpoint allows a specially crafted document to cause LibreOffice to automatically retrieve external HTTP(S) resources and local file resources during document conversion, enabling blind SSRF and limited… | |
| Pendiente de análisis | Alta (8.6) | 1.0% | 💥 PoC | LibrebookingAI | 9/7/2026 | 30/7/2026 | LibreBooking's email template editor save action passes the submitted template name directly into the destination file path, allowing a remote attacker with administrator credentials to write an arbitrary file outside the template directory and execute code. Fixed in 5.1.0. | |
| Aplazada | Baja (1.9) | 0.17% | — | GNU LibredwgAI | 9/7/2026 | 9/7/2026 | A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_next_entity of the file src/dwg.c of the component DWG File Handler. Performing a manipulation of the argument next_obj results in null pointer dereference. The attack must be initiated from a local position. The exploit… | |
| Aplazada | Baja (1.9) | 0.18% | — | GNU LibredwgAI | 9/7/2026 | 9/7/2026 | A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affected element is the function dwg_bmp of the file src/dwg.c of the component BMP Image Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be… | |
| Aplazada | Alta (8.5) | 0.20% | — | Calibre-ebook CalibreAI | 7/7/2026 | 18/8/2026 | calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when its metadata is read by calibre, including through Add books or Edit books, by embedding a custom column definition with a python: template in calibre:user_metadata that is passed unsanitized to… | |
| Aplazada | Media (4.6) | 0.19% | — | Actual-app CLIAIMicrosoft ExcelAILibreoffice CalcAIGoogle SheetsAI | 7/7/2026 | 8/7/2026 | Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in packages/cli/src/output.ts used whenever the global --format csv option is passed, whose escapeCsv helper only handles RFC 4180 delimiter, quote, and newline escaping and does not neutralize standard… | |
| Analizada | Media (5.9) | 0.35% | — | Libreswan | 2/7/2026 | 9/7/2026 | Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the IKEv2 AUTH payload was encoded using RSASSA-PKCS1-v1_5 (RFC 8017). A remote attacker can use a variation on the Bleichenbacher attack to forge the AUTH payload when small… | |
| Analizada | Media (5.9) | 0.39% | — | Libreswan | 2/7/2026 | 9/7/2026 | Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authentication hash when the SIG payload of an IKEv1 packet was encoded using PKCS #1 RSA Encryption as per RFC 2313. A remote attacker can use a variation on the Bleichenbacher attack to forge the SIG… |