Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 331 respecto a la semana anterior
Críticas / altas1352▲ 94 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.36% | — | Luci-app-upnpAIMiniupnpdAI | 12/7/2026 | 30/9/2026 | luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests. Attackers can send malicious HTML in the NewPortMappingDescription field, which miniupnpd stores and luci-app-upnp renders without output encoding,… | |
| Analizada | Alta (7.1) | 1.1% | — | Miniupnp Project Miniupnpd | 17/4/2026 | 29/6/2026 | miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote. Attackers can trigger an out-of-bounds memory read by exploiting improper length… | |
| Aplazada | Crítica (9.8) | 1.3% | — | MiniupnpAIBitcoin CoreAI | 18/11/2024 | 17/6/2026 | miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values, leading to a buffer overflow and significant data leak, a different vulnerability than CVE-2019-12107. In Bitcoin Core before 0.12, remote code execution was possible in conjunction with… | |
| Modificada | Media (5.5) | 0.32% | — | Miniupnp Project Ngiflib | 11/8/2023 | 17/6/2026 | An issue was discovered in GetByte function in miniupnp ngiflib version 0.4, allows local attackers to cause a denial of service (DoS) via crafted .gif file (infinite loop). | |
| Modificada | Media (5.5) | 0.27% | — | Miniupnp Project Ngiflib | 2/8/2023 | 17/6/2026 | ngiflib commit 84a75 was discovered to contain a segmentation violation via the function SDL_LoadAnimatedGif at ngiflibSDL.c. This vulnerability is triggered when running the program SDLaffgif. | |
| Modificada | Media (5.5) | 0.27% | — | Miniupnp Project Ngiflib | 2/8/2023 | 17/6/2026 | ngiflib commit fb271 was discovered to contain a segmentation violation via the function "main" at gif2tag.c. This vulnerability is triggered when running the program gif2tga. | |
| Modificada | Media (5.5) | 0.28% | — | Miniupnp Project Ngiflib | 19/7/2023 | 17/6/2026 | ngiflib commit 5e7292 was discovered to contain an infinite loop via the function DecodeGifImg at ngiflib.c. | |
| Modificada | Media (6.5) | 0.62% | — | Miniupnp Project Ngiflib | 17/7/2023 | 17/6/2026 | An issue was discovered in ngiflib 0.4. There is SEGV in SDL_LoadAnimatedGif when use SDLaffgif. poc : ./SDLaffgif CA_file2_0 | |
| Modificada | Alta (8.8) | 1.1% | — | Miniupnp Project Ngiflib | 27/8/2021 | 17/6/2026 | ngiflib 0.4 has a heap overflow in GetByte() at ngiflib.c:70 in NGIFLIB_NO_FILE mode, GetByte() reads memory buffer without checking the boundary. | |
| Modificada | Alta (8.8) | 1.1% | — | Miniupnp Project Ngiflib | 27/8/2021 | 17/6/2026 | ngiflib 0.4 has a heap overflow in GetByteStr() at ngiflib.c:108 in NGIFLIB_NO_FILE mode, GetByteStr() copy memory buffer without checking the boundary. | |
| Modificada | Alta (8.8) | 1.3% | — | Miniupnp Project Ngiflib | 2/1/2020 | 17/6/2026 | ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor in ngiflib.c. | |
| Modificada | Alta (7.5) | 1.7% | — | Miniupnp Project Ngiflib | 17/11/2019 | 17/6/2026 | MiniUPnP ngiflib 0.4 has a NULL pointer dereference in GifIndexToTrueColor in ngiflib.c via a file that lacks a palette. | |
| Modificada | Alta (7.5) | 2.3% | — | Miniupnp Project MiniupnpdDebian Linux | 1/11/2019 | 16/6/2026 | MiniUPnPd has information disclosure use of snprintf() | |
| Modificada | Alta (8.8) | 1.5% | — | Miniupnp Project Ngiflib | 16/9/2019 | 17/6/2026 | ngiflib 0.4 has a heap-based buffer overflow in WritePixels() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pictures is mishandled. | |
| Modificada | Alta (8.8) | 1.6% | — | Miniupnp Project Ngiflib | 16/9/2019 | 17/6/2026 | ngiflib 0.4 has a heap-based buffer overflow in WritePixel() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pictures is mishandled. | |
| Modificada | Alta (7.5) | 3.4% | — | Miniupnp Project MiniupnpdDebian Linux | 15/5/2019 | 17/6/2026 | A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in copyIPv6IfDifferent in pcpserver.c. | |
| Modificada | Alta (7.5) | 2.6% | — | Miniupnp.free Miniupnpd | 15/5/2019 | 17/6/2026 | An AddPortMapping Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in upnpredirect.c. | |
| Modificada | Alta (7.5) | 2.8% | — | Miniupnp Project Miniupnpd | 15/5/2019 | 17/6/2026 | A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutboundPinholeTimeout in upnpsoap.c for rem_port. | |
| Modificada | Alta (7.5) | 2.7% | — | Miniupnp Project Miniupnpd | 15/5/2019 | 17/6/2026 | A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutboundPinholeTimeout in upnpsoap.c for int_port. | |
| Modificada | Alta (7.5) | 3.0% | — | Miniupnp.free Miniupnpd | 15/5/2019 | 17/6/2026 | The upnp_event_prepare function in upnpevents.c in MiniUPnP MiniUPnPd through 2.1 allows a remote attacker to leak information from the heap due to improper validation of an snprintf return value. | |
| Modificada | Alta (7.5) | 2.8% | — | Miniupnp Project Miniupnpd | 15/5/2019 | 17/6/2026 | The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and 1.5 allows a remote attacker to crash the process due to a Use After Free vulnerability. | |
| Modificada | Alta (7.5) | 1.1% | — | Miniupnp Project Ngiflib | 1/6/2018 | 17/6/2026 | ngiflib.c in MiniUPnP ngiflib 0.4 has an infinite loop in DecodeGifImg and LoadGif. | |
| Modificada | Media (6.5) | 1.0% | — | Miniupnp Project Ngiflib | 31/5/2018 | 17/6/2026 | GifIndexToTrueColor in ngiflib.c in MiniUPnP ngiflib 0.4 has a Segmentation fault. | |
| Modificada | Crítica (9.8) | 1.4% | — | Miniupnp Project Ngiflib | 31/5/2018 | 17/6/2026 | ngiflib.c in MiniUPnP ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor. | |
| Modificada | Crítica (9.8) | 1.5% | — | Miniupnp Project Ngiflib | 31/5/2018 | 17/6/2026 | ngiflib.c in MiniUPnP ngiflib 0.4 has a stack-based buffer overflow in DecodeGifImg. |