Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
151 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.2) | 0.74% | — | Lightning Network Daemon Project Lightning Network Daemon | 21/10/2020 | 17/6/2026 | Prior to 0.11.0-beta, LND (Lightning Network Daemon) had a vulnerability in its invoice database. While claiming on-chain a received HTLC output, it didn't verify that the corresponding outgoing off-chain HTLC was already settled before releasing the preimage. In the case of a hash-and-amount collision with an… | |
| Modificada | Media (5.3) | 0.71% | — | Lightning Network Daemon Project Lightning Network Daemon | 21/10/2020 | 17/6/2026 | Prior to 0.10.0-beta, LND (Lightning Network Daemon) would have accepted a counterparty high-S signature and broadcast tx-relay invalid local commitment/HTLC transactions. This can be exploited by any peer with an open channel regardless of the victim situation (e.g., routing node, payment-receiver, or… | |
| Modificada | Crítica (9.8) | 2.6% | — | Daemonology Bsdiff | 16/9/2020 | 17/6/2026 | A memory corruption vulnerability is present in bspatch as shipped in Colin Percival’s bsdiff tools version 4.3. Insufficient checks when handling external inputs allows an attacker to bypass the sanity checks in place and write out of a dynamically allocated buffer boundaries. | |
| Modificada | Media (6.5) | 0.60% | — | Intel Inet Wireless Daemon | 13/8/2020 | 17/6/2026 | Improper buffer restrictions in the Intel(R) Wireless for Open Source before version 1.5 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Modificada | Alta (8.1) | 0.69% | — | Intel Inet Wireless Daemon | 12/8/2020 | 17/6/2026 | eapol.c in iNet wireless daemon (IWD) through 1.8 allows attackers to trigger a PTK reinstallation by retransmitting EAPOL Msg4/4. | |
| Modificada | Alta (7.5) | 2.2% | — | Lightning Network Daemon | 31/1/2020 | 17/6/2026 | Lightning Network Daemon (lnd) before 0.7 allows attackers to trigger loss of funds because of Incorrect Access Control. | |
| Modificada | Media (5.4) | 0.60% | — | Altn Mdaemon Email Server | 17/12/2019 | 17/6/2026 | MDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message. | |
| Modificada | Alta (7.5) | 1.7% | — | Freebsd Name Server Daemon | 1/11/2019 | 16/6/2026 | FreeBSD NSD before 3.2.13 allows remote attackers to crash a NSD child server process (SIGSEGV) and cause a denial of service in the NSD server. | |
| Modificada | Media (6.5) | 1.4% | — | Eq-3 Cux-daemonEq-3 Ccu2 Firmware | 17/10/2019 | 17/6/2026 | A Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to read sensitive files via a simple HTTP Request. | |
| Modificada | Alta (8.8) | 20% | — | Eq-3 Cux-daemonEq-3 Ccu2 Firmware | 17/10/2019 | 17/6/2026 | A Remote Code Execution (RCE) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to execute system commands as root remotely via a simple HTTP request. | |
| Modificada | Alta (8.8) | 1.0% | — | Altn Mdaemon Webmail | 19/7/2019 | 17/6/2026 | MDaemon Webmail (formerly WorldClient) has CSRF. | |
| Modificada | Alta (7.5) | 1.3% | — | Altn Mdaemon Email Server | 16/7/2019 | 17/6/2026 | MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and limits checks to 10 MB even with special configuration), which is arguably inconsistent with currently popular message sizes. This might interfere with risk management for malicious e-mail, if a… | |
| Modificada | Crítica (9.8) | 2.0% | — | Nlnetlabs Name Server Daemon | 3/7/2019 | 17/6/2026 | nsd-checkzone in NLnet Labs NSD 4.2.0 has a Stack-based Buffer Overflow in the dname_concatenate() function in dname.c. | |
| Modificada | Media (6.1) | 0.79% | — | Altn Mdaemon | 21/2/2019 | 17/6/2026 | MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 2 of 2). | |
| Modificada | Media (6.1) | 0.79% | — | Altn Mdaemon | 21/2/2019 | 17/6/2026 | MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 1 of 2). | |
| Modificada | Alta (8.4) | 0.44% | — | Apcupsd APC UPS Daemon | 16/6/2017 | 17/6/2026 | In Adam Kropelin adk0212 APC UPS Daemon through 3.14.14, the default installation of APCUPSD allows a local authenticated, but unprivileged, user to run arbitrary code with elevated privileges by replacing the service executable apcupsd.exe with a malicious executable that will run with SYSTEM privileges at startup.… | |
| Modificada | Media (4) | 1.9% | — | Litech Router Advertisement DaemonOpenstack Neutron | 15/1/2015 | 17/6/2026 | The L3 agent in OpenStack Neutron 2014.2.x before 2014.2.2, when using radvd 2.0+, allows remote authenticated users to cause a denial of service (blocked router update processing) by creating eight routers and assigning an ipv6 non-provider subnet to each. | |
| Modificada | Baja (2.1) | 0.37% | — | Mate-desktop Mate-settings-daemon | 30/5/2014 | 16/6/2026 | The default configuration in mate-settings-daemon 1.5.3 allows local users to change the timezone for the system via a crafted D-Bus call. | |
| Modificada | Media (4.4) | 0.36% | — | Litech Router Advertisement Daemon | 27/4/2014 | 16/6/2026 | The router advertisement daemon (radvd) before 1.8.2 does not properly handle errors in the privsep_init function, which causes the radvd daemon to run as root and has an unspecified impact. | |
| Modificada | Media (6.4) | 2.8% | — | Litech Router Advertisement Daemon | 27/4/2014 | 16/6/2026 | Directory traversal vulnerability in device-linux.c in the router advertisement daemon (radvd) before 1.8.2 allows local users to overwrite arbitrary files, and remote attackers to overwrite certain files, via a .. (dot dot) in an interface name. NOTE: this can be leveraged with a symlink to overwrite arbitrary files. | |
| Modificada | Media (5) | 1.6% | — | Litech Router Advertisement Daemon | 17/2/2014 | 16/6/2026 | The process_rs function in the router advertisement daemon (radvd) before 1.8.2, when UnicastOnly is enabled, allows remote attackers to cause a denial of service (temporary service hang) via a large number of ND_ROUTER_SOLICIT requests. | |
| Modificada | Alta (7.5) | 1.6% | — | Litech Router Advertisement Daemon | 17/2/2014 | 16/6/2026 | The process_ra function in the router advertisement daemon (radvd) before 1.8.2 allows remote attackers to cause a denial of service (stack-based buffer over-read and crash) via unspecified vectors. | |
| Modificada | Alta (7.5) | 4.0% | — | Litech Router Advertisement Daemon | 17/2/2014 | 16/6/2026 | Buffer overflow in the process_ra function in the router advertisement daemon (radvd) before 1.8.2 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a negative value in a label_len value. | |
| Modificada | Media (4.3) | 1.8% | — | Sebastian Heinlein AptdaemonCanonical Ubuntu Linux | 26/12/2012 | 16/6/2026 | Aptdaemon 0.43 in Ubuntu 11.10 and 12.04 LTS uses short IDs when importing PPA GPG keys from a keyserver, which allows remote attackers to install arbitrary package repository GPG keys via a man-in-the-middle (MITM) attack. | |
| Modificada | Media (6.9) | 1.1% | — | Daemon-tools Daemon Tools | 7/9/2012 | 16/6/2026 | Untrusted search path vulnerability in DAEMON Tools Lite 4.35.6.0091 and Pro Standard 4.36.0309.0160 allows local users to gain privileges via a Trojan horse mfc80loc.dll file in the current working directory, as demonstrated by a directory that contains a .mds file. NOTE: some of these details are obtained from third… |