Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
87 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.9) | 0.54% | — | Cesanta Mongoose | 23/2/2026 | 17/6/2026 | A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the file /src/dns.c of the component DNS Transaction ID Handler. Executing a manipulation of the argument random can lead to insufficiently random values. The attack can be launched remotely. The attack… | |
| Analizada | Media (4.3) | 0.29% | — | Cesanta Mongoose | 24/11/2025 | 17/6/2026 | Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of service via TLS initialization where SSL_CTX_get_cert_store() returns NULL. | |
| Analizada | Alta (7.5) | 0.43% | 💥 PoC | Cesanta Mongoose | 29/9/2025 | 17/6/2026 | An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the issue may lead to a buffer overflow. | |
| Analizada | Crítica (9.8) | 7.3% | 💥 Exploit | Mongoosejs Mongoose | 15/1/2025 | 17/6/2026 | Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900. | |
| Analizada | Crítica (9.1) | 4.0% | 💥 Exploit | Mongoosejs Mongoose | 2/12/2024 | 17/6/2026 | Mongoose before 8.8.3 can improperly use $where in match, leading to search injection. | |
| Modificada | Alta (7.5) | 0.23% | — | Cesanta Mongoose | 18/11/2024 | 8/9/2026 | Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters. | |
| Modificada | Media (5.3) | 0.28% | — | Cesanta Mongoose | 18/11/2024 | 8/9/2026 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. | |
| Analizada | Media (5.3) | 0.28% | — | Cesanta Mongoose | 18/11/2024 | 17/6/2026 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. | |
| Analizada | Media (5.3) | 0.31% | — | Cesanta Mongoose | 18/11/2024 | 17/6/2026 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. | |
| Analizada | Media (5.3) | 0.31% | — | Cesanta Mongoose | 18/11/2024 | 17/6/2026 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. | |
| Analizada | Media (5.3) | 0.31% | — | Cesanta Mongoose | 18/11/2024 | 17/6/2026 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. | |
| Modificada | Alta (7.5) | 0.38% | — | Cesanta Mongoose | 18/11/2024 | 8/9/2026 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application. | |
| Modificada | Alta (7) | 0.10% | — | Cesanta Mongoose | 18/11/2024 | 8/9/2026 | Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters. | |
| Modificada | Alta (7.5) | 0.48% | — | Cesanta Mongoose | 18/11/2024 | 8/9/2026 | Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application. | |
| Analizada | Crítica (9.8) | 0.27% | — | Cesanta Mongoose | 18/11/2024 | 17/6/2026 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for the hostname field. | |
| Aplazada | Alta (7.5) | 0.52% | — | Cesanta MongooseAI | 29/5/2024 | 17/6/2026 | Cesanta Mongoose commit b316989 was discovered to contain a NULL pointer dereference via the scpy function at src/fmt.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MQTT packet. | |
| Modificada | Alta (8.8) | 0.71% | — | Cesanta Mongoose | 22/8/2023 | 17/6/2026 | Buffer overflow in mg_resolve_from_hosts_file in Mongoose 6.18, when reading from a crafted hosts file. | |
| Modificada | Alta (8.8) | 1.0% | — | Cesanta Mongoose | 9/8/2023 | 17/6/2026 | Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version 7.9 and prior does not appear to be… | |
| Modificada | Crítica (9.8) | 1.2% | — | Mongoosejs Mongoose | 17/7/2023 | 17/6/2026 | Prototype Pollution in GitHub repository automattic/mongoose prior to 7.3.4. | |
| Modificada | Alta (7.5) | 1.0% | — | Cesanta Mongoose | 23/6/2023 | 17/6/2026 | The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers. By sending a single attack payload over TCP, an attacker can cause an infinite loop in which the server continuously reparses that payload, and does not respond to any other requests. | |
| Modificada | Media (5.4) | 0.47% | — | Mongoosemarketplace Mongoose Page Plugin | 23/1/2023 | 17/6/2026 | The Mongoose Page Plugin WordPress plugin before 1.9.0 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. | |
| Modificada | Crítica (9.8) | 33% | — | Mongoosejs Mongoose | 28/7/2022 | 17/6/2026 | Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6. | |
| Modificada | Crítica (9.8) | 1.7% | — | Cesanta Mongoose OS | 3/5/2022 | 17/6/2026 | Cesanta Software Mongoose-OS v2.17.0 is vulnerable to integer wrap-around in function mm_malloc. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution. | |
| Modificada | Alta (7.5) | 1.4% | — | Cesanta Mongoose | 18/2/2022 | 17/6/2026 | This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder. | |
| Modificada | Crítica (9.8) | 2.2% | — | Cesanta Mongooseos MJS | 29/4/2021 | 17/6/2026 | In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_json_parse, which can potentially lead to redirection of control flow. NOTE: the original reporter disputes the significance of this finding because "there isn’t very much of an… |