Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

151 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.2)0.74%—Lightning Network Daemon Project Lightning Network Daemon21/10/202017/6/2026
Prior to 0.11.0-beta, LND (Lightning Network Daemon) had a vulnerability in its invoice database. While claiming on-chain a received HTLC output, it didn't verify that the corresponding outgoing off-chain HTLC was already settled before releasing the preimage. In the case of a hash-and-amount collision with an…
ModificadaMedia (5.3)0.71%—Lightning Network Daemon Project Lightning Network Daemon21/10/202017/6/2026
Prior to 0.10.0-beta, LND (Lightning Network Daemon) would have accepted a counterparty high-S signature and broadcast tx-relay invalid local commitment/HTLC transactions. This can be exploited by any peer with an open channel regardless of the victim situation (e.g., routing node, payment-receiver, or…
ModificadaCrítica (9.8)2.6%—Daemonology Bsdiff16/9/202017/6/2026
A memory corruption vulnerability is present in bspatch as shipped in Colin Percival’s bsdiff tools version 4.3. Insufficient checks when handling external inputs allows an attacker to bypass the sanity checks in place and write out of a dynamically allocated buffer boundaries.
ModificadaMedia (6.5)0.60%—Intel Inet Wireless Daemon13/8/202017/6/2026
Improper buffer restrictions in the Intel(R) Wireless for Open Source before version 1.5 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
ModificadaAlta (8.1)0.69%—Intel Inet Wireless Daemon12/8/202017/6/2026
eapol.c in iNet wireless daemon (IWD) through 1.8 allows attackers to trigger a PTK reinstallation by retransmitting EAPOL Msg4/4.
ModificadaAlta (7.5)2.2%—Lightning Network Daemon31/1/202017/6/2026
Lightning Network Daemon (lnd) before 0.7 allows attackers to trigger loss of funds because of Incorrect Access Control.
ModificadaMedia (5.4)0.60%—Altn Mdaemon Email Server17/12/201917/6/2026
MDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message.
ModificadaAlta (7.5)1.7%—Freebsd Name Server Daemon1/11/201916/6/2026
FreeBSD NSD before 3.2.13 allows remote attackers to crash a NSD child server process (SIGSEGV) and cause a denial of service in the NSD server.
ModificadaMedia (6.5)1.4%—Eq-3 Cux-daemonEq-3 Ccu2 Firmware17/10/201917/6/2026
A Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to read sensitive files via a simple HTTP Request.
ModificadaAlta (8.8)20%—Eq-3 Cux-daemonEq-3 Ccu2 Firmware17/10/201917/6/2026
A Remote Code Execution (RCE) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to execute system commands as root remotely via a simple HTTP request.
ModificadaAlta (8.8)1.0%—Altn Mdaemon Webmail19/7/201917/6/2026
MDaemon Webmail (formerly WorldClient) has CSRF.
ModificadaAlta (7.5)1.3%—Altn Mdaemon Email Server16/7/201917/6/2026
MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and limits checks to 10 MB even with special configuration), which is arguably inconsistent with currently popular message sizes. This might interfere with risk management for malicious e-mail, if a…
ModificadaCrítica (9.8)2.0%—Nlnetlabs Name Server Daemon3/7/201917/6/2026
nsd-checkzone in NLnet Labs NSD 4.2.0 has a Stack-based Buffer Overflow in the dname_concatenate() function in dname.c.
ModificadaMedia (6.1)0.79%—Altn Mdaemon21/2/201917/6/2026
MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 2 of 2).
ModificadaMedia (6.1)0.79%—Altn Mdaemon21/2/201917/6/2026
MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 1 of 2).
ModificadaAlta (8.4)0.44%—Apcupsd APC UPS Daemon16/6/201717/6/2026
In Adam Kropelin adk0212 APC UPS Daemon through 3.14.14, the default installation of APCUPSD allows a local authenticated, but unprivileged, user to run arbitrary code with elevated privileges by replacing the service executable apcupsd.exe with a malicious executable that will run with SYSTEM privileges at startup.…
ModificadaMedia (4)1.9%—Litech Router Advertisement DaemonOpenstack Neutron15/1/201517/6/2026
The L3 agent in OpenStack Neutron 2014.2.x before 2014.2.2, when using radvd 2.0+, allows remote authenticated users to cause a denial of service (blocked router update processing) by creating eight routers and assigning an ipv6 non-provider subnet to each.
ModificadaBaja (2.1)0.37%—Mate-desktop Mate-settings-daemon30/5/201416/6/2026
The default configuration in mate-settings-daemon 1.5.3 allows local users to change the timezone for the system via a crafted D-Bus call.
ModificadaMedia (4.4)0.36%—Litech Router Advertisement Daemon27/4/201416/6/2026
The router advertisement daemon (radvd) before 1.8.2 does not properly handle errors in the privsep_init function, which causes the radvd daemon to run as root and has an unspecified impact.
ModificadaMedia (6.4)2.8%—Litech Router Advertisement Daemon27/4/201416/6/2026
Directory traversal vulnerability in device-linux.c in the router advertisement daemon (radvd) before 1.8.2 allows local users to overwrite arbitrary files, and remote attackers to overwrite certain files, via a .. (dot dot) in an interface name. NOTE: this can be leveraged with a symlink to overwrite arbitrary files.
ModificadaMedia (5)1.6%—Litech Router Advertisement Daemon17/2/201416/6/2026
The process_rs function in the router advertisement daemon (radvd) before 1.8.2, when UnicastOnly is enabled, allows remote attackers to cause a denial of service (temporary service hang) via a large number of ND_ROUTER_SOLICIT requests.
ModificadaAlta (7.5)1.6%—Litech Router Advertisement Daemon17/2/201416/6/2026
The process_ra function in the router advertisement daemon (radvd) before 1.8.2 allows remote attackers to cause a denial of service (stack-based buffer over-read and crash) via unspecified vectors.
ModificadaAlta (7.5)4.0%—Litech Router Advertisement Daemon17/2/201416/6/2026
Buffer overflow in the process_ra function in the router advertisement daemon (radvd) before 1.8.2 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a negative value in a label_len value.
ModificadaMedia (4.3)1.8%—Sebastian Heinlein AptdaemonCanonical Ubuntu Linux26/12/201216/6/2026
Aptdaemon 0.43 in Ubuntu 11.10 and 12.04 LTS uses short IDs when importing PPA GPG keys from a keyserver, which allows remote attackers to install arbitrary package repository GPG keys via a man-in-the-middle (MITM) attack.
ModificadaMedia (6.9)1.1%—Daemon-tools Daemon Tools7/9/201216/6/2026
Untrusted search path vulnerability in DAEMON Tools Lite 4.35.6.0091 and Pro Standard 4.36.0309.0160 allows local users to gain privileges via a Trojan horse mfc80loc.dll file in the current working directory, as demonstrated by a directory that contains a .mds file. NOTE: some of these details are obtained from third…