Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

151 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.9)0.36%—Gammu SMS DaemonAIDrupalAI2/9/202619/9/2026
Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
Pendiente de análisisMedia (5.9)0.36%—Gammu SMS DaemonAI2/9/202619/9/2026
Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
Pendiente de análisisMedia (5.9)0.36%—Gammu SMS DaemonAI2/9/202619/9/2026
Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
AplazadaMedia (6.9)0.44%—Musicpd Music Player DaemonAI28/5/202614/7/2026
Music Player Daemon (MPD) before version 0.24.11 contains a CRLF injection vulnerability in the xspf_char_data function within the XSPF playlist plugin that allows attackers to embed literal CR/LF bytes in URI fields by supplying a malicious XSPF playlist with XML numeric character references. Attackers can inject…
AplazadaMedia (6.9)0.48%—LibcurlAIMusicpd Music Player DaemonAI28/5/202614/7/2026
Music Player Daemon (MPD) before version 0.24.11 contains a server-side request forgery vulnerability in CurlInputPlugin where CURLOPT_FOLLOWLOCATION is set without CURLOPT_REDIR_PROTOCOLS_STR, allowing unauthenticated attackers to bypass the http/https scheme restriction by causing a malicious HTTP server to redirect…
AplazadaAlta (8.7)0.63%—Musicpd Music Player DaemonAI28/5/202614/7/2026
Music Player Daemon (MPD) before version 0.24.11 contains a path traversal vulnerability in LocalStorage::MapFSOrThrow and LocalStorage::MapUTF8 within the local storage plugin, where the on-disk path is constructed by joining the storage root with a user-supplied URI as plain strings without canonicalization,…
AplazadaAlta (8.8)0.68%—Musicpd Music Player DaemonAI28/5/202614/7/2026
Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be function in src/pcm/Pack.cxx that allows unauthenticated attackers to corrupt stack memory by triggering an off-by-one write in the PCM decoder plugin. Attackers can issue two MPD commands referencing…
AplazadaCrítica (9.1)2.6%—Perl Http DaemonAI27/5/202623/7/2026
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append. Untrusted input…
AnalizadaCrítica (9.3)0.96%⚠ Explotación activaDisc-soft Daemon Tools15/5/202617/6/2026
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc…
AnalizadaAlta (8.1)0.57%—Internet Routing Registry Daemon Project Internet Routing Registry Daemon6/3/202617/6/2026
Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version 4.4.5 and from version 4.5.0 to before version 4.5.1, an attacker can manipulate the HTTP Host header on a password reset or account creation request. The confirmation…
AplazadaAlta (7.1)0.24%—Altn Mdaemon Mail ServerAI5/11/202517/6/2026
MDaemon Mail Server 23.5.2 validates SPF, DKIM, and DMARC using the email enclosed in angle brackets (<>) in the From: header of SMTP DATA. An attacker can craft a From: header with multiple invisible Unicode thin spaces to display a spoofed sender while passing validation, allowing email spoofing even when…
AplazadaAlta (8.8)0.80%—System Security Services Daemon SssdAIMicrosoft Active DirectoryAIMIT KerberosAI9/10/202531/8/2026
A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. This fallback allows an attacker with…
AplazadaAlta (8.7)0.40%—Airlink DaemonAIDockerAI25/8/202517/6/2026
Airlink's Daemon interfaces with Docker and the Panel to provide secure access for controlling instances via the Panel. In version 1.0.0, an attacker with access to the affected container can create symbolic links inside the mounted directory (/app/data). Because the container bind-mounts an arbitrary host path, these…
AplazadaCrítica (9.3)0.92%—Arcane Software Vermillion FTP DaemonAI21/8/202516/6/2026
Arcane Software’s Vermillion FTP Daemon (vftpd) versions up to and including 1.31 contains a memory corruption vulnerability triggered by a malformed FTP PORT command. The flaw arises from an out-of-bounds array access during input parsing, allowing an attacker to manipulate stack memory and potentially execute…
AplazadaAlta (8.5)0.43%—Deepin Lastore-daemonAIDeepin LinuxAI23/7/202517/6/2026
A local privilege escalation vulnerability exists in lastore-daemon, the system package manager daemon used in Deepin Linux (developed by Wuhan Deepin Technology Co., Ltd.). In versions 0.9.53-1 (Deepin 15.5) and 0.9.66-1 (Deepin 15.7), the D-Bus configuration permits any user in the sudo group to invoke the…
AnalizadaMedia (5.3)0.64%—Mdaemon Email Server29/4/202517/6/2026
An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window, and access user data.
AplazadaMedia (5.3)0.67%—Avahi-daemonAI21/11/202429/6/2026
A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.
AplazadaMedia (5.3)0.56%—Avahi-daemonAI21/11/202429/6/2026
A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.
AnalizadaMedia (5.3)18%⚠ Explotación activaMdaemon15/11/202417/6/2026
An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window.
AnalizadaAlta (8.7)0.97%—Juniper Junos Containerized Routing Protocol Daemon11/10/202417/6/2026
An Improper Handling of Exceptional Conditions vulnerability in the rpd-server of Juniper Networks Junos OS and Junos OS Evolved within cRPD allows an unauthenticated network-based attacker sending crafted TCP traffic to the routing engine (RE) to cause a CPU-based Denial of Service (DoS). If specially crafted TCP…
AnalizadaMedia (5.4)0.13%—Flexlm License Daemons FOR Intel Fpga14/8/202417/6/2026
Insecure inherited permissions in some Flexlm License Daemons for Intel(R) FPGA software before version v11.19.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.5)0.15%—Canonical Ubuntu Advantage Desktop Daemon27/6/202417/6/2026
Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.
AplazadaCrítica (9.8)0.71%—Daemon PTY Limited Farcry CoreAI25/6/202417/6/2026
An arbitrary file upload vulnerability in /fileupload/upload.cfm in Daemon PTY Limited FarCry Core framework before 7.2.14 allows attackers to execute arbitrary code via uploading a crafted .cfm file.
AplazadaMedia (5.9)0.22%—Daemon PTY Limited Farcry CoreAI25/6/202417/6/2026
An issue in Daemon PTY Limited FarCry Core framework before 7.2.14 allows attackers to access sensitive information in the /facade directory.
AplazadaMedia (6.5)0.57%—Lightning Network Daemon LNDAI20/6/202417/6/2026
The Lightning Network Daemon (lnd) - is a complete implementation of a Lightning Network node. A parsing vulnerability in lnd's onion processing logic and lead to a DoS vector due to excessive memory allocation. The issue was patched in lnd v0.17.0. Users should update to a version > v0.17.0 to be protected. Users…