Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
551 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.37% | — | Janeczku Calibre-web | 15/11/2024 | 17/6/2026 | A vulnerability in janeczku/calibre-web allows unauthorized users to view the names of private shelves belonging to other users. This issue occurs in the file shelf.py at line 221, where the name of the shelf is exposed in an error message when a user attempts to remove a book from a shelf they do not own. This… | |
| Aplazada | Alta (7.8) | 0.46% | — | LibreswanAINetworkmanagerAINetworkmanager-libreswanAI | 22/10/2024 | 26/6/2026 | A flaw was found in the libreswan client plugin for NetworkManager (NetkworkManager-libreswan), where it fails to properly sanitize the VPN configuration from the local unprivileged user. In this configuration, composed by a key-value format, the plugin fails to escape special characters, leading the application to… | |
| Modificada | Media (4.6) | 0.41% | — | Librenms | 1/10/2024 | 17/6/2026 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Stored Cross-Site Scripting (XSS) can be achieved by uploading a new Background for a Custom Map. Users with "admin" role can set background for a custom map, this allow the upload of SVG file that can contain XSS payload which will trigger on… | |
| Analizada | Media (5.4) | 0.53% | — | Librenms | 1/10/2024 | 17/6/2026 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Device Dependencies" feature allows authenticated users to inject arbitrary JavaScript through the device name ("hostname" parameter). This vulnerability can lead to the execution of… | |
| Analizada | Baja (2.4) | 0.48% | — | Librenms | 1/10/2024 | 17/6/2026 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Self Cross-Site Scripting (Self-XSS) vulnerability in the "Alert Templates" feature allows users to inject arbitrary JavaScript into the alert template's name. This script executes immediately upon submission but does not persist after a… | |
| Analizada | Media (5.4) | 30% | — | Librenms | 1/10/2024 | 17/6/2026 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Rules" feature allows authenticated users to inject arbitrary JavaScript through the "Title" field. This vulnerability can lead to the execution of malicious code in the context… | |
| Analizada | Media (4.8) | 0.54% | — | Librenms | 1/10/2024 | 17/6/2026 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can create a Device Groups, the application did not properly sanitize the user input in the Device Groups name, when user see the detail of the Device Group, if java script code is inside the name of the Device Groups, its… | |
| Analizada | Media (5.4) | 0.63% | — | Librenms | 1/10/2024 | 17/6/2026 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Transports" feature allows authenticated users to inject arbitrary JavaScript through the "Details" section (which contains multiple fields depending on which transport is… | |
| Modificada | Alta (7.8) | 0.20% | — | Libreoffice | 17/9/2024 | 17/6/2026 | Improper Digital Signature Invalidation vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows Signature forgery vulnerability in LibreOfficeThis issue affects LibreOffice: from 24.2 before < 24.2.5. | |
| Aplazada | Alta (8.2) | 0.23% | — | LibreofficeAICollabora OnlineAI | 23/8/2024 | 17/6/2026 | Collabora Online is a collaborative online office suite based on LibreOffice. In affected versions of Collabora Online, https connections from coolwsd to other hosts may incompletely verify the remote host's certificate's against the full chain of trust. This vulnerability is fixed in Collabora Online 24.04.4.3,… | |
| Analizada | Alta (7.1) | 14% | — | Calibre-ebook Calibre | 6/8/2024 | 17/6/2026 | Unsanitized user-input in Calibre <= 7.15.0 allow users with permissions to perform full-text searches to achieve SQL injection on the SQLite database. | |
| Analizada | Media (6.1) | 26% | 💥 Exploit | Calibre-ebook Calibre | 6/8/2024 | 17/6/2026 | Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting. | |
| Aplazada | Crítica (9.8) | 84% | 💥 Exploit | Calibre-ebook CalibreAI | 6/8/2024 | 17/6/2026 | Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution. | |
| Analizada | Alta (7.5) | 62% | 💥 Exploit | Calibre-ebook Calibre | 6/8/2024 | 17/6/2026 | Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read. | |
| Analizada | Alta (7.8) | 0.24% | — | Libreoffice | 5/8/2024 | 17/6/2026 | Certificate Validation user interface in LibreOffice allows potential vulnerability. Signed macros are scripts that have been digitally signed by the developer using a cryptographic signature. When a document with a signed macro is opened a warning is displayed by LibreOffice before the macro is executed. Previously… | |
| Modificada | Crítica (9.8) | 0.67% | — | Librechat | 22/7/2024 | 17/6/2026 | LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images. | |
| Modificada | Crítica (9.8) | 0.36% | — | Librechat | 22/7/2024 | 17/6/2026 | LibreChat through 0.7.4-rc1 has incorrect access control for message updates. | |
| Analizada | Media (5.4) | 23% | 💥 PoC | Janeczku Calibre-web | 19/7/2024 | 17/6/2026 | In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. The vulnerability arises from the way the clean_string function handles HTML sanitization. | |
| Analizada | Crítica (10) | 0.43% | — | Libreoffice | 25/6/2024 | 17/6/2026 | Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verification LibreOfficeKit can be used for accessing LibreOffice functionality through C/C++. Typically this is used by third party components to reuse LibreOffice as a library to convert, view or otherwise… | |
| Analizada | Media (6.5) | 1.0% | — | LibreofficeFedoraproject FedoraDebian Linux | 14/5/2024 | 17/6/2026 | Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted. | |
| Aplazada | Media (6.1) | 0.52% | — | Librespeed SpeedtestAI | 1/5/2024 | 17/6/2026 | librespeed/speedtest is an open source, self-hosted speed test for HTML5. In affected versions missing neutralization of the ISP information in a speedtest result leads to stored Cross-site scripting in the JSON API. The `processedString` field in the `ispinfo` parameter is missing neutralization. It is stored when a… | |
| Analizada | Alta (7.2) | 20% | — | Librenms | 22/4/2024 | 17/6/2026 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Versions prior to 24.4.0 are vulnerable to SQL injection. The `order` parameter is obtained from `$request`. After performing a string check, the value is directly incorporated into an SQL statement and concatenated, resulting in a SQL… | |
| Analizada | Media (5.4) | 34% | — | Librenms | 22/4/2024 | 17/6/2026 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to version 24.4.0, there is improper sanitization on the `Service` template name, which can lead to stored Cross-site Scripting. Version 24.4.0 fixes this vulnerability. | |
| Analizada | Alta (8.8) | 19% | — | Librenms | 22/4/2024 | 17/6/2026 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A SQL injection vulnerability in POST /search/search=packages in LibreNMS prior to version 24.4.0 allows a user with global read privileges to execute SQL commands via the package parameter. With this vulnerability, an attacker can exploit a… | |
| Analizada | Media (6.5) | 0.79% | — | Libreswan | 11/4/2024 | 17/6/2026 | The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan's default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected. |