Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

551 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.8%—GNU LibredwgOpensuse Backports SLEOpensuse Leap14/3/201917/6/2026
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg.spec (later than CVE-2019-9779).
ModificadaCrítica (9.1)3.0%—GNU LibredwgOpensuse Backports SLEOpensuse Leap14/3/201917/6/2026
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function dwg_dxf_BLOCK_CONTROL at dwg.spec.
ModificadaCrítica (9.1)3.0%—GNU LibredwgOpensuse Backports SLEOpensuse Leap14/3/201917/6/2026
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function bit_read_B at bits.c.
ModificadaAlta (7.5)2.9%—GNU LibredwgOpensuse Backports SLEOpensuse Leap14/3/201917/6/2026
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for the z dimension.
ModificadaAlta (7.5)2.8%—GNU LibredwgOpensuse Backports SLEOpensuse Leap14/3/201917/6/2026
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LEADER at dwg.spec.
ModificadaAlta (7.5)2.8%—GNU LibredwgOpensuse Backports SLEOpensuse Leap14/3/201917/6/2026
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function bit_convert_TU at bits.c.
ModificadaAlta (7.5)2.9%—GNU LibredwgOpensuse Backports SLEOpensuse Leap14/3/201917/6/2026
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for the y dimension.
ModificadaAlta (8.8)3.1%—Librehealth EHR20/12/201817/6/2026
LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This attack appear to be exploitable via Uploading a PHP file with image MIME type.
ModificadaAlta (7.8)1.5%—Librecad8/11/201817/6/2026
LibreCAD 2.1.3 allows remote attackers to cause a denial of service (0x89C04589 write access violation and application crash) or possibly have unspecified other impact via a crafted file.
ModificadaMedia (6.1)1.6%—Librenms18/10/201817/6/2026
Persistent Cross-Site Scripting (XSS) issues in LibreNMS before 1.44 allow remote attackers to inject arbitrary web script or HTML via the dashboard_name parameter in the /ajax_form.php resource, related to html/includes/forms/add-dashboard.inc.php, html/includes/forms/delete-dashboard.inc.php, and…
ModificadaAlta (8.8)1.5%—Librehealth EHR20/8/201817/6/2026
LibreHealthIO lh-ehr version REL-2.0.0 contains a SQL Injection vulnerability in Show Groups Popup SQL query functions that can result in Ability to perform malicious database queries. This attack appear to be exploitable via User controlled parameters.
ModificadaAlta (8.8)2.8%—Librehealth EHR20/8/201817/6/2026
LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write in letter.php (2) vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code execution. This attack appear to be exploitable via User controlled input.
ModificadaAlta (8.8)2.8%—Librehealth EHR20/8/201817/6/2026
LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code execution. This attack appear to be exploitable via User controlled parameters.
ModificadaAlta (7.1)1.5%—Librehealth EHR20/8/201817/6/2026
LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Deletion vulnerability in Import template that can result in Denial of service. This attack appear to be exploitable via User controlled parameter.
ModificadaAlta (8.8)3.3%—Librehealth EHR20/8/201817/6/2026
LibreHealthIO LH-EHR version REL-2.0.0 contains an Authenticated Unrestricted File Write vulnerability in Import template that can result in write files with malicious content and may lead to remote code execution.
ModificadaMedia (6.5)1.4%—Librehealth EHR20/8/201817/6/2026
LibreHealthIO lh-ehr version <REL-2.0.0 contains an Authenticated Local File Disclosure vulnerability in Importing of templates allows local file disclosure that can result in Disclosure of sensitive files on the server. This attack appear to be exploitable via User controlled variable in import templates function.
ModificadaCrítica (9.8)2.2%—Libreoffice5/8/201817/6/2026
The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles the realpath function in certain environments such as FreeBSD libc, which might allow attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact if LibreOffice…
ModificadaMedia (6.5)1.1%—GNU Libredwg23/7/201817/6/2026
dwg_decode_eed in decode.c in GNU LibreDWG before 0.6 leads to a double free (in dwg_free_eed in free.c) because it does not properly manage the obj->eed value after a free occurs.
ModificadaMedia (6.5)1.4%—GNU Libredwg20/7/201817/6/2026
dwg_obj_block_control_get_block_headers in dwg_api.c in GNU LibreDWG 0.5.1048 allows remote attackers to cause a denial of service (NULL pointer dereference and SEGV) via a crafted dwg file.
ModificadaMedia (6.5)1.1%—GNU Libredwg20/7/201817/6/2026
get_first_owned_object in dwg.c in GNU LibreDWG 0.5.1036 allows remote attackers to cause a denial of service (SEGV).
ModificadaMedia (4.7)0.32%—Openbsd Libressl15/6/201817/6/2026
LibreSSL before 2.6.5 and 2.7.x before 2.7.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover a key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
ModificadaAlta (7.5)78%💥 ExploitLibreofficeApache OpenofficeDebian LinuxRedhat Enterprise Linux Desktop+31/5/201817/6/2026
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.
ModificadaAlta (7.8)2.1%—Debian LinuxLibreofficeRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+216/4/201817/6/2026
The SwCTBWrapper::Read function in sw/source/filter/ww8/ww8toolbar.cxx in LibreOffice before 5.4.6.1 and 6.x before 6.0.2.1 does not validate a customizations index, which allows remote attackers to cause a denial of service (heap-based buffer overflow with write access) or possibly have unspecified other impact via a…
ModificadaAlta (7.8)1.9%—LibreofficeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+216/4/201817/6/2026
sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrect integer data type in the StgSmallStrm class, which allows remote attackers to cause a denial of service (use-after-free with write access) or possibly have unspecified other impact via a crafted document that uses the…
ModificadaAlta (7.4)1.0%💥 PoCOpenbsd Libressl24/3/201817/6/2026
The int_x509_param_set_hosts function in lib/libcrypto/x509/x509_vpm.c in LibreSSL 2.7.0 before 2.7.1 does not support a certain special case of a zero name length, which causes silent omission of hostname verification, and consequently allows man-in-the-middle attackers to spoof servers and obtain sensitive…