Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2598▼ 321 respecto a la semana anterior
Críticas / altas1342▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
1343 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.85% | — | Node-bluetooth Project Node-bluetooth | 9/3/2023 | 17/6/2026 | All versions of the package node-bluetooth are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation. | |
| Modificada | Crítica (9.8) | 0.66% | — | Node-bluetooth-serial-port Project Node-bluetooth-serial-port | 9/3/2023 | 17/6/2026 | All versions of the package node-bluetooth-serial-port are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation. | |
| Modificada | Alta (7.5) | 1.4% | — | @nubosoftware/node-static Project @nubosoftware/node-staticNode-static Project Node-static | 6/3/2023 | 17/6/2026 | All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function. | |
| Modificada | Media (6.5) | 0.84% | — | Geosolutionsgroup Geonode | 27/2/2023 | 17/6/2026 | GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. GeoNode is vulnerable to an XML External Entity (XXE) injection in the style upload functionality of GeoServer leading to Arbitrary File Read. This issue has been patched in version 4.0.3. | |
| Modificada | Media (4.2) | 0.47% | — | Nodejs Node.jsDebian Linux | 23/2/2023 | 17/6/2026 | An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges. | |
| Modificada | Alta (7.5) | 2.2% | — | Nodejs Node.js | 23/2/2023 | 17/6/2026 | A cryptographic vulnerability exists in Node.js <19.2.0, <18.14.1, <16.19.1, <14.21.3 that in some cases did does not clear the OpenSSL error stack after operations that may set it. This may lead to false positive errors during subsequent cryptographic operations that happen to be on the same thread. This in turn… | |
| Modificada | Alta (7.5) | 2.0% | — | Nodejs Node.js | 23/2/2023 | 17/6/2026 | A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.require(). This only affects users who… | |
| Modificada | Alta (7.5) | 0.55% | — | Cisco Node-jose | 16/2/2023 | 17/6/2026 | node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for web browsers and node.js-based servers. Prior to version 2.2.0, when using the non-default "fallback" crypto back-end, ECC operations in `node-jose` can trigger a Denial-of-Service (DoS) condition, due to a possible infinite… | |
| Modificada | Alta (7.5) | 1.3% | — | Nodejs Undici | 16/2/2023 | 17/6/2026 | Undici is an HTTP/1.1 client for Node.js. Prior to version 5.19.1, the `Headers.set()` and `Headers.append()` methods are vulnerable to Regular Expression Denial of Service (ReDoS) attacks when untrusted values are passed into the functions. This is due to the inefficient regular expression used to normalize the… | |
| Modificada | Media (5.4) | 1.1% | — | Nodejs Node.jsNodejs Undici | 16/2/2023 | 17/6/2026 | Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does not protect `host` HTTP header from CRLF injection vulnerabilities. This issue is patched in Undici v5.19.1. As a workaround, sanitize the `headers.host` string before passing to undici. | |
| Modificada | Alta (7.5) | 0.91% | — | Protocol Go-unixfsnode | 9/2/2023 | 17/6/2026 | github.com/ipfs/go-unixfsnode is an ADL IPLD prime node that wraps go-codec-dagpb's implementation of protobuf to enable pathing. In versions priot to 1.5.2 trying to read malformed HAMT sharded directories can cause panics and virtual memory leaks. If you are reading untrusted user input, an attacker can then trigger… | |
| Modificada | Media (4.4) | 0.20% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+321 | 30/1/2023 | 17/6/2026 | An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. | |
| Modificada | Media (4.3) | 0.41% | — | Lenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Certified Node FirmwareLenovo Thinkagile Hx1021 FirmwareLenovo Thinkagile Hx1320 Firmware+94 | 30/1/2023 | 17/6/2026 | The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls, as applicable, remain in effect. | |
| Modificada | Media (6.5) | 0.63% | — | Lenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Certified Node FirmwareLenovo Thinkagile Hx1021 FirmwareLenovo Thinkagile Hx1320 Firmware+94 | 30/1/2023 | 17/6/2026 | A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem denial of service. | |
| Modificada | Alta (8.8) | 0.83% | — | Dell EMC Metro Node | 18/1/2023 | 17/6/2026 | Dell EMC Metro node, Version(s) prior to 7.1, contain a Code Injection Vulnerability. An authenticated nonprivileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application. | |
| Modificada | Alta (7.5) | 0.90% | — | Nodeserver Project Nodeserver | 18/1/2023 | 17/6/2026 | A vulnerability has been found in youngerheart nodeserver and classified as critical. Affected by this vulnerability is an unknown functionality of the file nodeserver.js. The manipulation leads to path traversal. The identifier of the patch is c4c0f0138ab5afbac58e03915d446680421bde28. It is recommended to apply a… | |
| Modificada | Crítica (9.8) | 0.68% | — | Nodebatis Project Nodebatis | 6/1/2023 | 17/6/2026 | A vulnerability was found in PeterMu nodebatis up to 2.1.x. It has been classified as critical. Affected is an unknown function. The manipulation leads to sql injection. Upgrading to version 2.2.0 is able to address this issue. The patch is identified as 6629ff5b7e3d62ad8319007a54589ec1f62c7c35. It is recommended to… | |
| Analizada | Alta (7.8) | 0.57% | — | Apple MacosNetapp HCI Compute NodeNeovimVIM+1 | 4/1/2023 | 24/9/2026 | Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143. | |
| Modificada | Crítica (9.8) | 0.97% | — | Furqansofware Node Whois | 19/12/2022 | 17/6/2026 | A vulnerability classified as critical has been found in Furqan node-whois. Affected is an unknown function of the file index.coffee. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). It is possible to launch the attack remotely. The name of the patch… | |
| Modificada | Alta (7.5) | 1.0% | — | Owasp Nodegoat | 18/12/2022 | 17/6/2026 | A vulnerability has been found in OWASP NodeGoat and classified as problematic. This vulnerability affects unknown code of the file app/routes/research.js of the component Query Parameter Handler. The manipulation leads to denial of service. The attack can be initiated remotely. The name of the patch is… | |
| Modificada | Alta (8.1) | 15% | — | Nodejs Node.jsDebian Linux | 5/12/2022 | 17/6/2026 | A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.The fix for this… | |
| Modificada | Media (6.5) | 2.8% | — | Nodejs Node.jsLlhttpSiemens Sinec INSDebian Linux | 5/12/2022 | 17/6/2026 | The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling. | |
| Modificada | Crítica (9.1) | 2.1% | — | Nodejs Node.jsSiemens Sinec INSDebian Linux | 5/12/2022 | 17/6/2026 | A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes… | |
| Modificada | Crítica (9.8) | 47% | — | Nodebb | 5/12/2022 | 17/6/2026 | NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts. This vulnerability has been patched in version 2.6.1. Users are advised to upgrade. Users… | |
| Modificada | Alta (8.8) | 1.1% | — | Telosalliance Omnia MPX Node Firmware | 2/12/2022 | 17/6/2026 | Insecure permissions in Telos Alliance Omnia MPX Node v1.0.0 to v1.4.9 allow attackers to manipulate and access system settings with backdoor account low privilege, this can lead to change hardware settings and execute arbitrary commands in vulnerable system functions that is requires high privilege to access. |