Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2566▼ 354 respecto a la semana anterior
Críticas / altas1319▲ 46 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)76▼ 451 respecto a la semana anterior
1343 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.63% | — | Jenkins Nodejs | 16/8/2023 | 17/6/2026 | Jenkins NodeJS Plugin 1.6.0 and earlier does not properly mask (i.e., replace with asterisks) credentials specified in the Npm config file in Pipeline build logs. | |
| Modificada | Alta (8.8) | 1.5% | — | Nodejs Node.jsFedoraproject Fedora | 15/8/2023 | 17/6/2026 | The use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x, and, 20.x. Please note that at the time… | |
| Modificada | Alta (8.8) | 2.1% | — | Nodejs Node.jsFedoraproject Fedora | 15/8/2023 | 17/6/2026 | A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improper handling of Buffers in file system APIs causing a traversal path to bypass when verifying file permissions. This vulnerability affects all users using the experimental… | |
| Modificada | Media (5.3) | 1.2% | — | Nodejs Node.jsFedoraproject Fedora | 15/8/2023 | 17/6/2026 | `fs.mkdtemp()` and `fs.mkdtempSync()` can be used to bypass the permission model check using a path traversal attack. This flaw arises from a missing check in the fs.mkdtemp() API and the impact is a malicious actor could create an arbitrary directory. This vulnerability affects all users using the experimental… | |
| Modificada | Media (6.5) | 0.59% | — | Thoughtworks Node-worker-threads-pool | 11/8/2023 | 17/6/2026 | An issue was discovered in StaticPool in SUCHMOKUO node-worker-threads-pool version 1.4.3, allows attackers to cause a denial of service. | |
| Analizada | Crítica (9.8) | 0.57% | — | CertifiFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Management Services FOR Element Software+4 | 25/7/2023 | 17/6/2026 | Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of… | |
| Modificada | Media (4.7) | 0.33% | — | Nodebb | 25/7/2023 | 17/6/2026 | NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation of this vulnerability allows certain user information to be extracted by attacker. | |
| Modificada | Crítica (9.8) | 1.0% | — | Nodebb | 24/7/2023 | 17/6/2026 | NodeBB is Node.js based forum software. Starting in version 2.5.0 and prior to version 2.8.7, due to the use of the object destructuring assignment syntax in the user export code path, combined with a path traversal vulnerability, a specially crafted payload could invoke the user export logic to arbitrarily execute… | |
| Modificada | Alta (8.1) | 2.4% | — | Linux KernelNetapp Solidfire & HCI Storage NodeNetapp H300sNetapp H410s+2 | 24/7/2023 | 17/6/2026 | A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP and SMB2_LOGOFF commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to… | |
| Modificada | Crítica (9.1) | 2.5% | — | Linux KernelNetapp SolidfireNetapp Solidfire & HCI Storage NodeNetapp H300s+3 | 18/7/2023 | 17/6/2026 | An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2misc.c in ksmbd does not validate the relationship between the command payload size and the RFC1002 length specification, leading to an out-of-bounds read. | |
| Modificada | Crítica (9.1) | 1.2% | — | Linux KernelNetapp Solidfire & HCI Management NodeNetapp H300sNetapp H410s+2 | 18/7/2023 | 17/6/2026 | An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/connection.c in ksmbd does not validate the relationship between the NetBIOS header's length field and the SMB header sizes, via pdu_size in ksmbd_conn_handler_loop, leading to an out-of-bounds read. | |
| Modificada | Crítica (9.1) | 1.2% | — | Linux KernelNetapp HCI Management NodeNetapp H300sNetapp H410s+2 | 18/7/2023 | 17/6/2026 | An issue was discovered in the Linux kernel before 6.3.9. ksmbd does not validate the SMB request protocol ID, leading to an out-of-bounds read. | |
| Modificada | Crítica (9.1) | 3.2% | — | Linux KernelNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage NodeNetapp H300s+3 | 18/7/2023 | 17/6/2026 | An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ksmbd does not properly check the UserName value because it does not consider the address of security buffer, leading to an out-of-bounds read. | |
| Modificada | Crítica (9.1) | 3.0% | — | Linux KernelNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage NodeNetapp H300s+3 | 18/7/2023 | 17/6/2026 | An issue was discovered in the Linux kernel before 6.3.4. ksmbd has an out-of-bounds read in smb2_find_context_vals when create_context's name_len is larger than the tag length. | |
| Modificada | Crítica (9.8) | 1.9% | — | Syncfusion Nodejs File System Provider | 12/7/2023 | 17/6/2026 | The Syncfusion EJ2 Node File Provider 0102271 is vulnerable to filesystem-server.js directory traversal. As a result, an unauthenticated attacker can: - On Windows, list files in any directory, read any file, delete any file, upload any file to any directory accessible by the web server. - On Linux, read any file,… | |
| Modificada | Alta (8.1) | 2.9% | — | Linux KernelNetapp HCI Management NodeNetapp H300sNetapp H410s+2 | 10/7/2023 | 17/6/2026 | A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_TREE_DISCONNECT commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code… | |
| Modificada | Alta (8.1) | 2.6% | — | Linux KernelNetapp HCINetapp HCI Storage NodesNetapp H300s+3 | 10/7/2023 | 17/6/2026 | A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in… | |
| Modificada | Alta (7.5) | 3.9% | — | Nodejs Node.jsFedoraproject Fedora | 1/7/2023 | 17/6/2026 | The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence… | |
| Modificada | Alta (7.5) | 1.3% | — | Nodejs Node.js | 1/7/2023 | 17/6/2026 | A privilege escalation vulnerability exists in Node.js 20 that allowed loading arbitrary OpenSSL engines when the experimental permission model is enabled, which can bypass and/or disable the permission model. The attack complexity is high. However, the crypto.setEngine() API can be used to bypass the permission model… | |
| Modificada | Media (6.3) | 0.29% | — | Lenovo Nextscale N1200 Enclosure FirmwareLenovo Thinkagile Cp-cb-10 FirmwareLenovo Thinkagile Cp-cb-10e FirmwareLenovo Thinkagile HX Enclosure Certified Node Firmware+4 | 26/6/2023 | 17/6/2026 | A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute. | |
| Modificada | Alta (7.5) | 0.62% | — | Lenovo Nextscale N1200 Enclosure FirmwareLenovo Thinkagile Cp-cb-10 FirmwareLenovo Thinkagile Cp-cb-10e FirmwareLenovo Thinkagile HX Enclosure Certified Node Firmware+4 | 26/6/2023 | 17/6/2026 | An unauthenticated denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted conditions. Rebooting SMM or FPC will restore access to the management web server. | |
| Modificada | Alta (7.8) | 0.29% | — | Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+4 | 24/4/2023 | 17/6/2026 | The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel. | |
| Modificada | Crítica (9.8) | 2.2% | — | Dawnsparks-node-tesseract Project Dawnsparks-node-tesseractHuedawn-tesseract Project Huedawn-tesseract | 24/4/2023 | 17/6/2026 | huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function. | |
| Modificada | Media (6.1) | 0.40% | — | Redhat Keycloak Node.js AdapterRedhat Single Sign-on | 27/3/2023 | 17/6/2026 | A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerability in the checkSso function. | |
| Modificada | Media (5.3) | 0.64% | — | Geosolutionsgroup Geonode | 24/3/2023 | 17/6/2026 | GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. Prior to versions 2.20.6, 2.19.6, and 2.18.7, anonymous users can obtain sensitive information about GeoNode configurations from the response of the `/geoserver/rest/about/status` Geoserver REST API… |