Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2565▼ 302 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.36%—Luci-app-upnpAIMiniupnpdAI12/7/202630/9/2026
luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests. Attackers can send malicious HTML in the NewPortMappingDescription field, which miniupnpd stores and luci-app-upnp renders without output encoding,…
AnalizadaAlta (7.1)1.1%—Miniupnp Project Miniupnpd17/4/202629/6/2026
miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote. Attackers can trigger an out-of-bounds memory read by exploiting improper length…
ModificadaAlta (7.5)2.3%—Miniupnp Project MiniupnpdDebian Linux1/11/201916/6/2026
MiniUPnPd has information disclosure use of snprintf()
ModificadaAlta (7.5)3.4%—Miniupnp Project MiniupnpdDebian Linux15/5/201917/6/2026
A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in copyIPv6IfDifferent in pcpserver.c.
ModificadaAlta (7.5)2.6%—Miniupnp.free Miniupnpd15/5/201917/6/2026
An AddPortMapping Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in upnpredirect.c.
ModificadaAlta (7.5)2.8%—Miniupnp Project Miniupnpd15/5/201917/6/2026
A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutboundPinholeTimeout in upnpsoap.c for rem_port.
ModificadaAlta (7.5)2.7%—Miniupnp Project Miniupnpd15/5/201917/6/2026
A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutboundPinholeTimeout in upnpsoap.c for int_port.
ModificadaAlta (7.5)3.0%—Miniupnp.free Miniupnpd15/5/201917/6/2026
The upnp_event_prepare function in upnpevents.c in MiniUPnP MiniUPnPd through 2.1 allows a remote attacker to leak information from the heap due to improper validation of an snprintf return value.
ModificadaAlta (7.5)2.8%—Miniupnp Project Miniupnpd15/5/201917/6/2026
The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and 1.5 allows a remote attacker to crash the process due to a Use After Free vulnerability.
ModificadaAlta (7.8)0.47%—Miniupnp Project Miniupnpd3/1/201817/6/2026
Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse.c) in miniupnpd < 2.0 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact
ModificadaCrítica (9.8)24%—Miniupnp Project Miniupnpd11/5/201717/6/2026
Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
ModificadaAlta (7.8)1.8%—Miniupnp Project Miniupnpd31/1/201316/6/2026
Integer signedness error in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to cause a denial of service (incorrect memory copy) via a SOAPAction header that lacks a " (double quote) character, a different vulnerability than CVE-2013-0230.
ModificadaAlta (7.8)2.8%—Miniupnp Project Miniupnpd31/1/201316/6/2026
The ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to cause a denial of service (NULL pointer dereference and service crash) via a SOAPAction header that lacks a # (pound sign) character, a different vulnerability than CVE-2013-0230.
ModificadaAlta (10)69%—Miniupnp Project Miniupnpd31/1/201316/6/2026
Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary code via a long quoted method.
ModificadaAlta (7.8)76%—Miniupnp Project Miniupnpd31/1/201316/6/2026
The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafted request that triggers a buffer over-read.