Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
551 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 13% | — | Librenms | 18/8/2025 | 17/6/2026 | librenms is a community-based GPL-licensed network monitoring system. A stored Cross-Site Scripting (XSS) vulnerability exists in LibreNMS (<= 25.6.0) in the Alert Template creation feature. This allows a user with the admin role to inject malicious JavaScript, which will be executed when the template is rendered,… | |
| Analizada | Alta (7.5) | 0.45% | — | Librechat | 5/8/2025 | 17/6/2026 | LibreChat is a ChatGPT clone with additional features. In versions 0.0.6 through 0.7.7-rc1, an exposed testing endpoint allows reading arbitrary chats directly from the Meilisearch engine. The endpoint /api/search/test allows for direct access to stored chats in the Meilisearch engine without proper access control.… | |
| Aplazada | Crítica (9.3) | 1.8% | 💥 Exploit | LibrettocmsAI | 4/8/2025 | 16/6/2026 | An unauthenticated arbitrary file upload vulnerability exists in LibrettoCMS version 1.1.7 (and possibly earlier) contains an unauthenticated arbitrary file upload vulnerability in its File Manager plugin. The upload handler located at adm/ui/js/ckeditor/plugins/pgrfilemanager/php/upload.php fails to properly validate… | |
| Analizada | Media (5.9) | 2.8% | 💥 PoC | Gelbphoenix AutocaliwebJaneczku Calibre-web | 24/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection.This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. | |
| Aplazada | Alta (8.7) | 0.84% | 💥 PoC | Calibre WEBAIGelbphoenix AutocaliwebAI | 24/7/2025 | 17/6/2026 | ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb:… | |
| Analizada | Alta (7.5) | 1.1% | — | Librenms | 22/7/2025 | 17/6/2026 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. LibreNMS versions 25.6.0 and below contain an architectural vulnerability in the ajax_form.php endpoint that permits Remote File Inclusion based on user-controlled… | |
| Aplazada | Alta (8.4) | 0.88% | 💥 PoC | DjvulibreAI | 3/7/2025 | 17/6/2026 | DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing documents and images. Prior to version 3.5.29, the MMRDecoder::scanruns method is affected by an OOB-write vulnerability, because it does not check that the xr pointer stays within the bounds of the allocated buffer. This can lead to… | |
| Analizada | Baja (2.1) | 12% | — | Librenms | 17/5/2025 | 17/6/2026 | LibreNMS is PHP/MySQL/SNMP based network monitoring software. LibreNMS v25.4.0 and prior suffers from a Stored Cross-Site Scripting (XSS) Vulnerability in the `group name` parameter of the `http://localhost/poller/groups` form. This vulnerability allows attackers to inject malicious scripts into web pages viewed by… | |
| Modificada | Baja (2.4) | 0.12% | — | Libreoffice | 27/4/2025 | 17/6/2026 | Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid This issue affects… | |
| Analizada | Media (5.2) | 0.14% | — | Libreoffice | 21/3/2025 | 17/6/2026 | An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to self sign an ODF document, with a signature untrusted by the target, then modify it to change the signature algorithm to an invalid (or unknown to LibreOffice) algorithm and LibreOffice would incorrectly present such a signature… | |
| Analizada | Media (5.3) | 0.50% | — | Librechat | 20/3/2025 | 17/6/2026 | A vulnerability in danny-avila/librechat prior to version 0.7.6 allows for logs debug injection. The parameters sessionId, fileId, userId, and file_id in the /code/download/:sessionId/:fileId and /download/:userId/:file_id APIs are not validated or filtered, leading to potential log injection attacks. This can cause… | |
| Analizada | Media (6.5) | 0.87% | — | Librechat | 20/3/2025 | 17/6/2026 | An unhandled exception in the danny-avila/librechat repository, version git 600d217, can cause the server to crash, leading to a full denial of service. This issue occurs when certain API endpoints receive malformed input, resulting in an uncaught exception. Although a valid JWT is required to exploit this… | |
| Modificada | Alta (7.5) | 0.92% | — | Librechat | 20/3/2025 | 17/6/2026 | A vulnerability in danny-avila/librechat version git a1647d7 allows an unauthenticated attacker to cause a denial of service by sending a crafted payload to the server. The middleware `checkBan` is not surrounded by a try-catch block, and an unhandled exception will cause the server to crash. This issue is fixed in… | |
| Modificada | Alta (7.5) | 0.53% | — | Librechat | 20/3/2025 | 17/6/2026 | In danny-avila/librechat version git 0c2a583, there is an improper input validation vulnerability. The application uses multer middleware for handling multipart file uploads. When using in-memory storage (the default setting for multer), there is no limit on the upload file size. This can lead to a server crash due to… | |
| Analizada | Alta (8.8) | 1.8% | — | Librechat | 20/3/2025 | 17/6/2026 | A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to improper sanitization of file paths by the multer middleware. This can lead to arbitrary file write and potentially remote code execution. The issue is fixed in version 0.7.6. | |
| Analizada | Alta (7.5) | 0.92% | — | Librechat | 20/3/2025 | 17/6/2026 | An unhandled exception in danny-avila/librechat version 3c94ff2 can lead to a server crash. The issue occurs when the fs module throws an exception while handling file uploads. An unauthenticated user can trigger this exception by sending a specially crafted request, causing the server to crash. The vulnerability is… | |
| Modificada | Media (5.3) | 0.55% | — | Librechat | 20/3/2025 | 17/6/2026 | An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue occurs because the endpoint does not verify whether the provided prompt ID belongs to the current user. | |
| Modificada | Media (6.5) | 0.37% | — | Librechat | 20/3/2025 | 17/6/2026 | An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpoint does not verify whether the provided attachment ID belongs to the current user, allowing any authenticated user to delete attachments of other users. | |
| Modificada | Media (5.4) | 0.35% | — | Librechat | 20/3/2025 | 17/6/2026 | In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and create prompts without being granted permission by the admin. This can break application logic and permissions, allowing unauthorized actions. | |
| Modificada | Crítica (9.1) | 0.99% | — | Librechat | 20/3/2025 | 17/6/2026 | An arbitrary file deletion vulnerability exists in danny-avila/librechat version v0.7.5-rc2, specifically within the /api/files endpoint. This vulnerability arises from improper input validation, allowing path traversal techniques to delete arbitrary files on the server. Attackers can exploit this to bypass security… | |
| Analizada | Media (4.6) | 0.38% | — | Librechat | 20/3/2025 | 17/6/2026 | In danny-avila/librechat version v0.7.5-rc2, a vulnerability exists in the preset creation functionality where a user can manipulate the user ID field through mass assignment. This allows an attacker to inject a different user ID into the preset object, causing the preset to appear in the UI of another user. The… | |
| Analizada | Alta (7.2) | 0.30% | — | LibreofficeDebian Linux | 4/3/2025 | 17/6/2026 | LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL… | |
| Analizada | Alta (7.2) | 0.33% | — | Libreoffice | 25/2/2025 | 17/6/2026 | Improper Input Validation vulnerability in The Document Foundation LibreOffice allows Windows Executable hyperlink targets to be executed unconditionally on activation.This issue affects LibreOffice: from 24.8 before < 24.8.5. | |
| Analizada | Media (6.1) | 0.41% | — | Librenms | 16/1/2025 | 17/6/2026 | librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to Cross-site Scripting (XSS) on the parameters:`/addhost` -> param: community. Librenms versions up to 24.10.1 allow remote attackers to inject malicious scripts. When a user views or interacts with the page displaying… | |
| Analizada | Media (5.4) | 31% | — | Librenms | 16/1/2025 | 17/6/2026 | librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the parameter: `ajax_form.php` -> param: state. Librenms versions up to 24.10.1 allow remote attackers to inject malicious scripts. When a user views or interacts with the page displaying the data,… |