Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2546▼ 402 respecto a la semana anterior
Críticas / altas1312▲ 29 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
–

1343 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
En análisisAlta (7.3)88%—GNU GlibcNetapp Active IQ Unified ManagerDebian LinuxNetapp HCI H300s Firmware+917/4/202417/6/2026
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
AnalizadaAlta (8.6)0.63%—Greenwoodsoftware LessDebian LinuxNetapp Bootstrap OSNetapp HCI Storage Nodes+113/4/202417/6/2026
less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment…
AnalizadaCrítica (9.8)6.9%—Haskell Process LibraryNodejs Node.jsPHPRust-lang Rust+110/4/202417/6/2026
A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.
AplazadaAlta (8.2)87%—NodejsAINghttp2AI9/4/202417/6/2026
An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTTP/2 CONTINUATION frame are sent to the server and then a TCP connection is…
ModificadaMedia (4.3)0.73%—Nodejs UndiciFedoraproject Fedora4/4/202417/6/2026
Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.
ModificadaBaja (3.5)0.80%—Nodejs UndiciFedoraproject Fedora4/4/202417/6/2026
Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been tampered. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.
AnalizadaMedia (6.3)0.43%—Nodebb28/3/202417/6/2026
NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Admin group via "isadmin":true.
AnalizadaMedia (6.1)0.38%—Geosolutionsgroup Geonode27/3/202417/6/2026
GeoNode is a geospatial content management system, a platform for the management and publication of geospatial data. An issue exists within GEONODE where the current rich text editor is vulnerable to Stored XSS. The applications cookies are set securely, but it is possible to retrieve a victims CSRF token and issue a…
AplazadaMedia (6.5)1.3%—NodejsAI19/3/202417/6/2026
A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL. The vulnerability stems from the fact that the fetch() function in Node.js always decodes Brotli, making it possible for…
AplazadaAlta (7.3)0.89%—Nodejs Node.jsAI19/3/202417/6/2026
setuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid(). This allows the process to perform privileged operations despite presumably having dropped such privileges through a call to setuid(). This vulnerability affects all users using version greater or equal than…
ModificadaAlta (7.5)3.2%—Nodejs Node.jsNetapp Astra Control Center20/2/202417/6/2026
A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The…
AnalizadaCrítica (9.8)1.3%—Nodejs Node.js20/2/202417/6/2026
The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user. If the path is to be treated as a Buffer, the implementation uses Buffer.from() to obtain a Buffer from the result of path.resolve(). By monkey-patching Buffer internals, namely,…
ModificadaAlta (7.8)0.56%—Nodejs Node.js20/2/202417/6/2026
On Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the process is running with elevated privileges with the only exception of CAP_NET_BIND_SERVICE. Due to a bug in the implementation of this exception, Node.js incorrectly applies this exception even when…
ModificadaAlta (8.8)1.2%—Nodejs Node.js20/2/202417/6/2026
Node.js depends on multiple built-in utility functions to normalize paths provided to node:fs functions, which can be overwitten with user-defined implementations leading to filesystem permission model bypass through path traversal attack. This vulnerability affects all users using the experimental permission model in…
AnalizadaMedia (6.5)0.95%—Nodejs Node.js20/2/202417/6/2026
The Node.js Permission Model does not clarify in the documentation that wildcards should be only used as the last character of a file path. For example: ``` --allow-fs-read=/home/node/.ssh/*.pub ``` will ignore `pub` and give access to everything after `.ssh/`. This misleading documentation affects all users using the…
AnalizadaMedia (4.5)0.77%—Nodejs Undici16/2/202417/6/2026
Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici already cleared Authorization headers on cross-origin redirects, but did not clear `Proxy-Authentication` headers. This issue has been patched in versions 5.28.3 and 6.6.1. Users are advised to upgrade. There are no known workarounds for this…
AnalizadaMedia (6.5)0.70%—Nodejs Undici16/2/202417/6/2026
Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. This issue has been addressed in version 6.6.1. Users are advised to upgrade. Users unable to upgrade should make…
AnalizadaMedia (4.9)0.69%—Intel Server Platform ServicesNetapp HCI Bootstrap OSNetapp HCI Compute Node Bios14/2/202417/6/2026
Uncontrolled resource consumption for some Intel(R) SPS firmware before version SPS_E5_06.01.04.002.0 may allow a privileged user to potentially enable denial of service via network access.
ModificadaMedia (5.3)0.72%—Shanxi Tianneng Technology Noderp29/1/202417/6/2026
A vulnerability was found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This issue affects some unknown processing of the file application/index/common.php of the component Cookie Handler. The manipulation of the argument Nod_User_Id/Nod_User_Token leads to improper authentication. The…
ModificadaAlta (7.5)0.91%—Shanxi Tianneng Technology Noderp29/1/202417/6/2026
A vulnerability has been found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This vulnerability affects unknown code of the file /runtime/log. The manipulation leads to files or directories accessible. The attack can be initiated remotely. The exploit has been disclosed to the public…
ModificadaAlta (7.5)0.76%—Svelte Adapter-nodeSvelte KIT24/1/202417/6/2026
SvelteKit is a web development kit. In SvelteKit 2, sending a GET request with a body eg `{}` to a built and previewed/hosted sveltekit app throws `Request with GET/HEAD method cannot have body.` and crashes the preview/hosting. After this happens, one must manually restart the app. `TRACE` requests will also cause…
ModificadaMedia (5.3)0.72%—Hono Node-server22/1/202417/6/2026
@hono/node-server is an adapter that allows users to run Hono applications on Node.js. Since v1.3.0, @hono/node-server has used its own Request object with `url` behavior that is unexpected. In the standard API, if the URL contains `..`, here called "double dots", the URL string returned by Request will be in the…
ModificadaAlta (7.5)1.5%—Nodejs Node.js28/11/202317/6/2026
The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says…
ModificadaMedia (5.3)1.2%—Nodejs Node.js28/11/202317/6/2026
When an invalid public key is used to create an x509 certificate using the crypto.X509Certificate() API a non-expect termination occurs making it susceptible to DoS attacks when the attacker could force interruptions of application processing, as the process terminates when accessing public key info of provided…
ModificadaAlta (7.5)1.5%—Nodejs Node.js28/11/202317/6/2026
A vulnerability has been identified in the Node.js (.msi version) installation process, specifically affecting Windows users who install Node.js using the .msi installer. This vulnerability emerges during the repair operation, where the "msiexec.exe" process, running under the NT AUTHORITY\SYSTEM context, attempts to…