« Volver al listado

Freecadweb

Freecadweb Freecad: vulnerabilidades y CVE

Freecadweb Freecad tiene 8 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE8
Últimos 12 meses6
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-34789Alta (7)0.19%—17 ago 2026
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/PropertyPythonObject.cpp in PropertyPythonObject::Restore() passes the attacker-controlled module attribute from serialized…
CVE-2026-34399Alta (7.8)0.20%—17 ago 2026
FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, FreeCAD's BIM Workbench contains an eval() call on untrusted data from SVG template files. When a user creates a TechDraw…
CVE-2026-34398Alta (7.8)0.22%—17 ago 2026
FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, src/Mod/BIM/bimcommands/BimProjectManager.py in the BIM Project Manager Load Template flow passes attacker-controlled FCStd…
CVE-2026-73235Media (6.1)0.17%—11 ago 2026
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constructed in src/Base/Reader.cpp by Base::XMLReader::XMLReader() parses attacker-controlled Document.xml…
CVE-2026-73234Alta (7.8)0.20%—11 ago 2026
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() in src/App/PropertyFile.cpp concatenates an attacker-controlled file or data attribute from…
CVE-2026-73233Alta (8.5)0.20%—11 ago 2026
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the FEM Displacement Constraint task dialog in src/Mod/Fem/Gui/TaskFemConstraintDisplacement.cpp passes the xDisplacementFormula,…
CVE-2021-45845Alta (7.8)1.9%—25 ene 2022
The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an attacker to execute arbitrary commands via a crafted FCStd document.
CVE-2021-45844Alta (7.8)1.1%—25 ene 2022
Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution5
  2. T1059 Command and Scripting Interpreter4
  3. T1566.001 Spearphishing Attachment1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.