Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 334 respecto a la semana anterior
Críticas / altas1340▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
1343 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.44% | — | Node-opcua-alarm-conditionAI | 5/2/2025 | 17/6/2026 | A prototype pollution in the function fieldsToJson of node-opcua-alarm-condition v2.134.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |
| Analizada | Alta (7.3) | 1.3% | — | Netapp HCI Baseboard Management ControllerNetapp HCI H610s FirmwareNetapp HCI H610c FirmwareNetapp HCI H615c Firmware+4 | 5/2/2025 | 17/6/2026 | When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow. | |
| Analizada | Baja (3.4) | 0.69% | — | Haxx CurlNetapp H700s FirmwareNetapp H615c FirmwareNetapp H610s Firmware+12 | 5/2/2025 | 17/6/2026 | When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance. | |
| Analizada | Media (6.8) | 0.90% | — | Sparkle-project SparkleNetapp HCI Compute NodeNetapp Oncommand Workflow Automation | 4/2/2025 | 17/6/2026 | A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks. | |
| Modificada | Media (5.5) | 1.6% | — | Nodejs Node.js | 28/1/2025 | 17/6/2026 | A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.js functions do not treat drive names as special on Windows. As a result, although Node.js assumes a relative path, it actually refers to the root directory. On Windows, a path… | |
| Modificada | Media (4.6) | 39% | — | Nodebb | 24/1/2025 | 5/7/2026 | A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' section of their profile. | |
| Aplazada | Alta (7.7) | 0.42% | — | NodejsAI | 22/1/2025 | 17/6/2026 | With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability… | |
| Aplazada | Media (6.8) | 0.76% | — | Nodejs UndiciAI | 21/1/2025 | 17/6/2026 | Undici is an HTTP/1.1 client. Starting in version 4.5.0 and prior to versions 5.28.5, 6.21.1, and 7.2.3, undici uses `Math.random()` to choose the boundary for a multipart/form-data request. It is known that the output of `Math.random()` can be predicted if several of its generated values are known. If there is a… | |
| Analizada | Media (5.5) | 0.28% | — | VIMNetapp HCI Compute Node Firmware | 20/1/2025 | 17/6/2026 | Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mode (-s -e), Vim typically doesn't show a screen and just operates silently in batch mode. However, it is still possible to trigger the function that handles the scrolling of a gui version of Vim by… | |
| Aplazada | Media (6.5) | 0.31% | — | Aginode GigaswitchAI | 15/1/2025 | 17/6/2026 | Insecure permissions in Aginode GigaSwitch v5 allows attackers to access sensitive information via using the SCP command. | |
| Analizada | Media (6.6) | 0.41% | — | Node Export Project Node Export | 9/1/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Drupal Node export allows Object Injection.This issue affects Node export: from 7.X-* before 7.X-3.3. | |
| Analizada | Media (5.4) | 0.21% | — | Node Access Rebuild Progressive Project Node Access Rebuild Progressive | 9/1/2025 | 17/6/2026 | Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 7.X-1.0 before 7.X-1.2. | |
| Analizada | Media (5.3) | 0.27% | — | Node Access Rebuild Progressive Project Node Access Rebuild Progressive | 9/1/2025 | 17/6/2026 | Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 0.0.0 before 2.0.2. | |
| Aplazada | Alta (8.1) | 1.4% | — | Nodejs Node.jsAI | 9/1/2025 | 17/6/2026 | Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled. | |
| Analizada | Crítica (9.1) | 1.2% | — | Xmlsoft Libxml2Netapp HCI Compute NodeNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage Node+5 | 23/12/2024 | 17/6/2026 | In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible. | |
| Modificada | Alta (7.5) | 0.92% | — | ES Iperf3Netapp Ontap 9Netapp HCI Compute Node | 18/12/2024 | 17/6/2026 | iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function. | |
| Aplazada | Alta (7.1) | 0.35% | — | Metup Clevernode Related ContentAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metup CleverNode Related Content clevernode-related-content allows Reflected XSS.This issue affects CleverNode Related Content: from n/a through <= 1.1.5. | |
| Aplazada | Crítica (10) | 0.59% | — | Comfyui ACE NodesAI | 13/12/2024 | 17/6/2026 | ComfyUI-Ace-Nodes is vulnerable to Code Injection. The ACE_ExpressionEval node contains an eval() in its entrypoint function that accepts arbitrary user-controlled data. A user can create a workflow that results in executing arbitrary code on the server. | |
| Aplazada | Crítica (10) | 0.57% | — | Comfyui Bmad NodesAI | 13/12/2024 | 17/6/2026 | ComfyUI-Bmad-Nodes is vulnerable to Code Injection. The issue stems from a validation bypass in the BuildColorRangeHSVAdvanced, FilterContour and FindContour custom nodes. In the entrypoint function to each node, there’s a call to eval which can be triggered by generating a workflow that injects a crafted string into… | |
| Aplazada | Alta (8.8) | 0.45% | — | Aginode Gigaswitch V5AI | 4/12/2024 | 17/6/2026 | An issue in Aginode GigaSwitch V5 before version 7.06G allows authenticated attackers with Administrator privileges to upload an earlier firmware version, exposing the device to previously patched vulnerabilities. | |
| Aplazada | Media (5.4) | 0.37% | — | Backstage Plugin-scaffolder-nodeAI | 29/11/2024 | 17/6/2026 | The Backstage Scaffolder plugin Houses types and utilities for building scaffolder-related modules. A vulnerability is identified in Backstage Scaffolder template functionality where Server-Side Template Injection (SSTI) can be exploited to perform Git config injection. The vulnerability allows an attacker to capture… | |
| Aplazada | Crítica (9.8) | 0.77% | — | NodemcuAI | 29/11/2024 | 17/6/2026 | nodemcu before v3.0.0-release_20240225 was discovered to contain an integer overflow via the getnum function at /modules/struct.c. | |
| Modificada | Media (6) | 0.55% | — | QemuNetapp HCI Compute Node | 14/11/2024 | 17/6/2026 | A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_count` and the size of `s->fifo_buffer` are set to 0x200, leading to an out-of-bound access. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of… | |
| Analizada | Media (5.9) | 1.0% | — | Netapp Active IQ Unified ManagerNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage NodeNetapp Windows Host Utilities+8 | 27/10/2024 | 17/6/2026 | An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser. | |
| Aplazada | Alta (8.7) | 0.41% | — | Secp256k1-nodeAIEllipticAI | 21/10/2024 | 17/6/2026 | secp256k1-node is a Node.js binding for an Optimized C library for EC operations on curve secp256k1. In `elliptic`-based version, `loadUncompressedPublicKey` has a check that the public key is on the curve. Prior to versions 5.0.1, 4.0.4, and 3.8.1, however, `loadCompressedPublicKey` is missing that check. That allows… |