Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 307 respecto a la semana anterior
Críticas / altas1348▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
1343 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.8% | — | Nodepdf Project Nodepdf | 28/7/2022 | 17/6/2026 | Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not properly encode all special characters, namely, semicolon and curly braces. This can be abused to achieve command execution. This problem affects nodepdf 1.3.0. | |
| Modificada | Alta (7.5) | 7.6% | — | Linux KernelDebian LinuxNetapp Active IQ Unified ManagerNetapp Solidfire & HCI Management Node+3 | 27/7/2022 | 17/6/2026 | nfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a denial of service (panic) because, in the case of an nf_queue verdict with a one-byte nfta_payload attribute, an skb_pull can encounter a negative skb->len. | |
| Modificada | Crítica (9.8) | 1.1% | — | Node-import Project Node-import | 25/7/2022 | 17/6/2026 | This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “eval” function located in line 79 in the index file "index.js". | |
| Modificada | Media (6.5) | 0.72% | — | Nodejs Undici | 21/7/2022 | 17/6/2026 | Authorization headers are cleared on cross-origin redirect. However, cookie headers which are sensitive headers and are official headers found in the spec, remain uncleared. There are active users using cookie headers in undici. This may lead to accidental leakage of cookie to a 3rd-party site or a malicious attacker… | |
| Modificada | Media (5.3) | 2.5% | — | Oracle GraalvmOracle JDKOracle JREAzul Zulu+10 | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.3.1; Oracle GraalVM Enterprise Edition: 21.3.2 and 22.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Modificada | Media (5.9) | 2.9% | — | Oracle GraalvmOracle JDKOracle JREOracle Openjdk+11 | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1; Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Difficult to exploit vulnerability… | |
| Modificada | Media (5.3) | 4.2% | — | Oracle GraalvmOracle JDKOracle JREOracle Openjdk+11 | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1; Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Easily exploitable vulnerability… | |
| Modificada | Media (6.5) | 1.5% | — | Nodejs Undici | 19/7/2022 | 17/6/2026 | undici is an HTTP/1.1 client, written from scratch for Node.js. It is possible to inject CRLF sequences into request headers in undici in versions less than 5.7.1. A fix was released in version 5.8.0. Sanitizing all HTTP headers from untrusted sources to eliminate `\r\n` is a workaround for this issue. | |
| Modificada | Alta (7.5) | 82% | — | Apache Xalan-javaDebian LinuxOracle GraalvmOracle JDK+12 | 19/7/2022 | 17/6/2026 | The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java… | |
| Modificada | Alta (7.5) | 1.9% | — | Apache Skywalking Nodejs Agent | 18/7/2022 | 17/6/2026 | A vulnerability in Apache SkyWalking NodeJS Agent prior to 0.5.1. The vulnerability will cause NodeJS services that has this agent installed to be unavailable if the OAP is unhealthy and NodeJS agent can't establish the connection. | |
| Modificada | Alta (7.3) | 1.8% | — | Nodejs Node.js | 14/7/2022 | 17/6/2026 | Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploited if the victim has the following dependencies on a Windows machine:* OpenSSL has been installed and “C:\Program Files\Common Files\SSL\openssl.cnf” exists.Whenever the above… | |
| Modificada | Media (5.3) | 2.2% | — | Nodejs Node.jsSiemens Sinec INS | 14/7/2022 | 17/6/2026 | A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3. | |
| Modificada | Media (6.5) | 70% | — | LlhttpNodejs Node.jsFedoraproject FedoraSiemens Sinec INS+2 | 14/7/2022 | 17/6/2026 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS). | |
| Modificada | Media (6.5) | 82% | — | LlhttpNodejs Node.jsDebian LinuxStormshield Management Center | 14/7/2022 | 17/6/2026 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). | |
| Modificada | Media (6.5) | 46% | — | LlhttpNodejs Node.jsFedoraproject FedoraSiemens Sinec INS+2 | 14/7/2022 | 17/6/2026 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS). | |
| Modificada | Alta (8.1) | 6.4% | — | Nodejs Node.jsDebian LinuxFedoraproject FedoraSiemens Sinec INS | 14/7/2022 | 17/6/2026 | A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks. | |
| Modificada | Media (6.5) | 0.47% | — | Nodejs Undici | 14/7/2022 | 17/6/2026 | `Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly means that proxies can MitM all HTTPS traffic, and if the proxy's URL is HTTP then it also means that nominally HTTPS requests are actually sent via plain-text HTTP between… | |
| Modificada | Alta (7.5) | 2.6% | — | Eclipse JettyDebian LinuxNetapp Element Plug-in FOR Vcenter ServerManagement Services FOR Element Software AND Netapp HCI+4 | 7/7/2022 | 17/6/2026 | In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good… | |
| Modificada | Baja (2.7) | 1.3% | — | Eclipse JettyDebian LinuxNetapp Element Plug-in FOR Vcenter ServerManagement Services FOR Element Software AND Netapp HCI+3 | 7/7/2022 | 17/6/2026 | In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This can lead to failures in a Proxy scenario. | |
| Modificada | Media (5.9) | 7.5% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+10 | 7/7/2022 | 17/6/2026 | When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client. | |
| Modificada | Crítica (9.8) | 7.7% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+10 | 7/7/2022 | 17/6/2026 | When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file… | |
| Modificada | Media (6.5) | 33% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+15 | 7/7/2022 | 17/6/2026 | curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of… | |
| Modificada | Media (4.3) | 28% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+15 | 7/7/2022 | 17/6/2026 | A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the cookies match, create requests that become larger than the threshold… | |
| Modificada | Media (5.5) | 0.22% | — | Redhat Openshift-origin-node-util | 30/6/2022 | 17/6/2026 | It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission. | |
| Modificada | Alta (7.3) | 95% | — | OpensslDebian LinuxFedoraproject FedoraSiemens Sinec INS+24 | 21/6/2022 | 17/6/2026 | In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in… |