Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
265 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.1% | 💥 PoC | Owasp Json-sanitizer | 9/6/2020 | 17/6/2026 | OWASP json-sanitizer before 1.2.1 allows XSS. An attacker who controls a substring of the input JSON, and controls another substring adjacent to a SCRIPT element in which the output is embedded as JavaScript, may be able to confuse the HTML parser as to where the SCRIPT element ends, and cause non-script content to be… | |
| Modificada | Alta (7.8) | 1.9% | — | Json-cFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+1 | 9/5/2020 | 17/6/2026 | json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. | |
| Modificada | Alta (7.5) | 6.8% | 💥 PoC | Json Project JsonFedoraproject FedoraOpensuse LeapDebian Linux+1 | 28/4/2020 | 17/6/2026 | The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to… | |
| Modificada | Alta (7.5) | 2.6% | — | Jsonparser Project JsonparserFedoraproject Fedora | 19/3/2020 | 17/6/2026 | The Library API in buger jsonparser through 2019-12-04 allows attackers to cause a denial of service (infinite loop) via a Delete call. | |
| Modificada | Crítica (9.1) | 1.6% | — | Styria Django-rest-framework-json WEB Tokens | 15/3/2020 | 17/6/2026 | An issue was discovered in drf-jwt 1.15.x before 1.15.1. It allows attackers with access to a notionally invalidated token to obtain a new, working token via the refresh endpoint, because the blacklist protection mechanism is incompatible with the token-refresh feature. NOTE: drf-jwt is a fork of… | |
| Modificada | Alta (8.8) | 0.94% | — | Suse Openstack CloudSuse Keystone-json-assignmentHP Helion Openstack | 17/1/2020 | 17/6/2026 | The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/keystone/user-project-map.json was assigned full "member" role access to every project. This allowed these users to access, modify, create and delete arbitrary resources,… | |
| Modificada | Media (5.3) | 0.97% | — | Json Pattern Validator Project Json Pattern Validator | 2/12/2019 | 17/6/2026 | In jpv (aka Json Pattern Validator) before 2.1.1, compareCommon() can be bypassed because certain internal attributes can be overwritten via a conflicting name, as demonstrated by 'constructor': {'name':'Array'}. This affects validate(). Hence, a crafted payload can overwrite this builtin attribute to manipulate the… | |
| Modificada | Alta (7.5) | 1.3% | — | Json-jwt Project Json-jwtDebian Linux | 12/11/2019 | 17/6/2026 | The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. | |
| Modificada | Alta (7.5) | 1.4% | — | Simdjson Project Simdjson | 26/8/2019 | 17/6/2026 | An issue was discovered in the simd-json crate before 0.1.15 for Rust. There is an out-of-bounds read and an incorrect crossing of a page boundary. | |
| Modificada | Alta (7.5) | 2.4% | — | Davegamble CjsonOracle Timesten In-memory Database | 19/7/2019 | 17/6/2026 | DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions. The impact is: Null dereference, so attack can cause denial of service. The component is: cJSON_GetObjectItemCaseSensitive() function. The attack vector is: crafted json file. The fixed version is: 1.7.9 and later. | |
| Modificada | Crítica (9.8) | 2.6% | — | Davegamble CjsonOracle Timesten In-memory Database | 9/5/2019 | 17/6/2026 | cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments. | |
| Modificada | Crítica (9.8) | 2.5% | — | Davegamble CjsonOracle Timesten In-memory Database | 9/5/2019 | 17/6/2026 | cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal. | |
| Modificada | Crítica (9.8) | 2.5% | — | Davegamble Cjson | 29/4/2019 | 17/6/2026 | parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a \ character. | |
| Modificada | Alta (8.8) | 2.7% | — | Gpsd Project GpsdMicrojson Project MicrojsonDebian Linux | 13/3/2019 | 17/6/2026 | gpsd versions 2.90 to 3.17 and microjson versions 1.0 to 1.3, an open source project, allow a stack-based buffer overflow, which may allow remote attackers to execute arbitrary code on embedded platforms via traffic on Port 2947/TCP or crafted JSON inputs. | |
| Modificada | Alta (7.5) | 1.9% | — | Lightbend Spray-json | 31/10/2018 | 17/6/2026 | Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic Complexity during the parsing of many JSON object fields (with keys that have the same hash code). | |
| Modificada | Alta (7.5) | 1.9% | — | Lightbend Spray-json | 31/10/2018 | 17/6/2026 | Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic Complexity during the parsing of a field composed of many decimal digits. | |
| Modificada | Crítica (9.8) | 39% | 💥 Exploit | Alibaba FastjsonPippo | 23/10/2018 | 17/6/2026 | parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in… | |
| Modificada | Crítica (9.8) | 1.6% | — | Json++ Project Json++ | 16/9/2018 | 17/6/2026 | JSON++ through 2016-06-15 has a buffer over-read in yyparse() in json.y. | |
| Modificada | Alta (7.7) | 1.9% | — | Redhat Openshift Container PlatformStarcounter-jack Json-patch | 6/9/2018 | 17/6/2026 | An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management. | |
| Modificada | Crítica (9.8) | 1.8% | — | Davegamble Cjson | 20/8/2018 | 17/6/2026 | Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible crash, corruption of data or even RCE. This attack appear to be exploitable via Depends on how application uses cJSON library. If application provides network interface then can be… | |
| Modificada | Alta (8.8) | 1.5% | — | Davegamble Cjson | 20/8/2018 | 17/6/2026 | Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE. This attack appear to be exploitable via Attacker must be able to force victim to print JSON data, depending on how cJSON library is used this could be either local or… | |
| Modificada | Alta (7.5) | 1.7% | — | Davegamble Cjson | 20/8/2018 | 17/6/2026 | Dave Gamble cJSON version 1.7.6 and earlier contains a CWE-772 vulnerability in cJSON library that can result in Denial of Service (DoS). This attack appear to be exploitable via If the attacker can force the data to be printed and the system is in low memory it can force a leak of memory. This vulnerability appears… | |
| Modificada | Alta (8.8) | 1.6% | — | Flowpaper Pdf2json | 5/8/2018 | 17/6/2026 | An issue has been found in PDF2JSON 0.69. XmlFontAccu::CSStyle in XmlFonts.cc has Mismatched Memory Management Routines (operator new [] versus operator delete). | |
| Modificada | Alta (8.8) | 1.6% | — | Flowpaper Pdf2json | 5/8/2018 | 17/6/2026 | An issue has been found in PDF2JSON 0.69. The HtmlString class in ImgOutputDev.cc has Mismatched Memory Management Routines (malloc versus operator delete). | |
| Modificada | Media (5.3) | 0.78% | — | Json-jwt Project Json-jwt | 26/6/2018 | 17/6/2026 | Nov json-jwt version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability… |