Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
551 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.14% | 💥 PoC | Libreoffice CalcAI | 5/10/2026 | 6/10/2026 | LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has… | |
| Aplazada | Media (6.7) | 0.12% | — | LibreofficeAI | 5/10/2026 | 6/10/2026 | URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-12426 did not cover every place a document can supply a URL. XForms instance data and… | |
| Aplazada | Media (6.7) | 0.11% | — | LibreofficeAI | 5/10/2026 | 6/10/2026 | LibreOffice can link to audio and video files from a document, and on Linux it plays them with GStreamer. A linked media file could be an HLS playlist that made GStreamer read the local files and remote URLs it listed while the document loaded, and their contents could end up in the document. In fixed versions… | |
| Aplazada | Media (6.7) | 0.12% | — | Libreoffice CalcAI | 5/10/2026 | 6/10/2026 | LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A link of the sql type could name a folder of local text files as a database, so opening a document could read a local text file into the sheet. In fixed versions only the csv, html and xml data providers are… | |
| Aplazada | Media (6.7) | 0.11% | — | Libreoffice CalcAI | 5/10/2026 | 6/10/2026 | LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document. Such a link was fetched while the document loaded, so opening a document could read a local file into the sheet, or make a request to a host of the document's choosing. In fixed versions external data links… | |
| Aplazada | Media (6.8) | 0.16% | — | Libreoffice CalcAI | 5/10/2026 | 6/10/2026 | LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an embedded Firebird database that wrote a file to any location the user could write to. In fixed versions an embedded Firebird database can open or create files only… | |
| Aplazada | Media (5.4) | 0.17% | — | LibreofficeAI | 22/9/2026 | 22/9/2026 | LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an image that uses a colour palette. The palette index held in the image data was used without being checked against the number of entries the palette has, so an index past the last entry read memory… | |
| Aplazada | Media (5.4) | 0.19% | — | LibreofficeAI | 22/9/2026 | 22/9/2026 | LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents. A stack buffer overflow existed in that conversion. The converted operators were written into a fixed size buffer with no check that they still fit, so a glyph… | |
| Aplazada | Media (5.4) | 0.17% | — | LibreofficeAI | 22/9/2026 | 22/9/2026 | LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a glyph declaring more hints than the array can hold wrote past its end. In fixed versions the hint count is checked against… | |
| Aplazada | Media (5.4) | 0.17% | — | Libreoffice DrawAI | 22/9/2026 | 22/9/2026 | LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the object's own dictionary and was not checked against the number of bytes actually present, so copying the stream read and wrote past the end of the buffer holding it. In… | |
| Aplazada | Media (5.4) | 0.11% | — | Libreoffice DrawAI | 22/9/2026 | 22/9/2026 | LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was taken from the document's own encryption dictionary and was used to fill a fixed size key buffer without being checked against it, so a length larger than that buffer… | |
| Aplazada | Media (5.4) | 0.17% | — | LibreofficeAI | 22/9/2026 | 22/9/2026 | LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the length of the text were read separately from the file and were not required to agree, so drawing the… | |
| Pendiente de análisis | Alta (7.3) | 0.35% | — | MaplibreAIGrafana GeomapAI | 17/9/2026 | 18/9/2026 | A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escalation to Org Admin. | |
| Aplazada | Media (6.9) | 0.53% | — | LibretranslateAI | 16/9/2026 | 22/9/2026 | LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated access to translated files. Attackers can bypass API key requirements and abuse ban lists to download files without authentication on protected instances. | |
| Aplazada | Baja (1.9) | 0.17% | — | GNU LibredwgAI | 14/9/2026 | 15/9/2026 | A security flaw has been discovered in GNU libredwg 0.13.4. This impacts the function DWG_TABLE of the file src/dwg.spec of the component Layer Encoding. Performing a manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit has been released to the public and may be used… | |
| Pendiente de análisis | Media (5) | 0.34% | — | LibrenmsAI | 13/9/2026 | 22/9/2026 | An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the searchPhrase parameter in the /ajax_table.php API endpoint. This affects as-selection.inc.php, edit-ports.inc.php,… | |
| Aplazada | Alta (7.5) | 0.39% | — | Ankaref Innovation AND Technology INC LibridAIAnkaref Innovation AND Technology INC LibrefAI | 10/9/2026 | 23/9/2026 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation. This issue affects LIBRID/LIBREF: from 2.01.0.2183 before 18.9.26.2319. | |
| Analizada | Alta (8.7) | 0.60% | — | Librenms | 7/9/2026 | 18/9/2026 | LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows authenticated attackers to inject arbitrary rrdtool arguments by breaking out of double-quote escaping. Attackers can inject DEF and LINE arguments to read RRD files from unauthorized devices, or use newline… | |
| Analizada | Crítica (9.2) | 3.9% | 💥 Exploit | Librenms | 7/9/2026 | 18/9/2026 | LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens. Attackers can exploit MySQL type coercion by sending small integers like 0 through 9 to match token hashes,… | |
| Aplazada | Media (4.8) | 0.28% | — | WgerAIMicrosoft ExcelAILibreoffice CalcAI | 6/9/2026 | 8/9/2026 | wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers can inject formulas like =HYPERLINK to exfiltrate admin data or execute code when admins open the exported file in Excel or LibreOffice Calc. | |
| Aplazada | Crítica (10) | 0.52% | — | Maplibre GL JSAI | 3/9/2026 | 9/9/2026 | MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collection, shifting indexes and skipping an adjacent dangerous attribute. An attacker… | |
| Aplazada | Alta (7.5) | 0.47% | — | LibreswanAI | 2/9/2026 | 9/9/2026 | In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT… | |
| Aplazada | Alta (8.6) | 1.5% | — | LibrenmsAI | 1/9/2026 | 8/9/2026 | LibreNMS versions >= 23.10.0 and < 26.2.0 (fixed in 26.4.0) contain an authenticated OS command injection vulnerability in libvirt discovery. When libvirt support is enabled (enable_libvirt=true), the device hostname ($this->getDevice()->hostname) is concatenated into shell commands (ssh, virsh list/dumpxml/domstate)… | |
| Aplazada | Media (5.8) | 0.35% | — | LibrenmsAI | 1/9/2026 | 8/9/2026 | LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that render unescaped SNMP-sourced data fields including BGP peer descriptions, VRF names, process information, and SLA tags. Attackers with device management access or network access to enroll a rogue SNMP device… | |
| Aplazada | Alta (7.1) | 0.33% | — | LibrenmsAI | 1/9/2026 | 8/9/2026 | LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and syslog-sourced data without escaping. An attacker who controls a monitored network device can inject arbitrary JavaScript through SNMP interface descriptions or syslog program fields that… |