Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.61% | — | Hapi Formula | 8/2/2023 | 17/6/2026 | formula is a math and string formula parser. In versions prior to 3.0.1 crafted user-provided strings to formula's parser might lead to polynomial execution time and a denial of service. Users should upgrade to 3.0.1+. There are no known workarounds for this vulnerability. | |
| Modificada | Alta (8.1) | 1.2% | — | Hapifhir HL7 Fhir CoreHL7 Fhir IG Publisher | 26/1/2023 | 17/6/2026 | HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal from a crafted ZIP or TGZ archive (for a prepackaged terminology cache, NPM package, or comparison archive). | |
| Modificada | Alta (8.1) | 1.2% | — | Hapijs Hoek | 23/9/2022 | 17/6/2026 | hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function. | |
| Modificada | Alta (7.8) | 0.66% | — | Aplixio PDF Shapingup | 22/10/2021 | 17/6/2026 | Aplioxio PDF ShapingUp 5.0.0.139 contains a buffer overflow which allows attackers to cause a denial of service (DoS) via a crafted PDF file. | |
| Modificada | Media (5.3) | 1.6% | — | Hapi Fhir | 10/5/2021 | 17/6/2026 | JPA Server in HAPI FHIR before 5.4.0 allows a user to deny service (e.g., disable access to the database after the attack stops) via history requests. This occurs because of a SELECT COUNT statement that requires a full index scan, with an accompanying large amount of server resources if there are many simultaneous… | |
| Modificada | Media (6.1) | 0.95% | — | Hapifhir Testpage Overlay | 8/10/2020 | 17/6/2026 | Users of the HAPI FHIR Testpage Overlay 5.0.0 and below can use a specially crafted URL to exploit an XSS vulnerability in this module, allowing arbitrary JavaScript to be executed in the user's browser. The impact of this vulnerability is believed to be low, as this module is intended for testing and not believed to… | |
| Modificada | Alta (7.4) | 7.2% | — | Prisma Graphql-playground-htmlPrisma Graphql-playground-middleware-expressPrisma Graphql-playground-middleware-hapiPrisma Graphql-playground-middleware-koa+1 | 8/6/2020 | 17/6/2026 | GraphQL Playground (graphql-playground-html NPM package) before version 1.6.22 have a severe XSS Reflection attack vulnerability. All unsanitized user input passed into renderPlaygroundPage() method could trigger this vulnerability. This has been patched in graphql-playground-html version 1.6.22. Note that some of the… | |
| Modificada | Media (6.1) | 1.3% | — | Hapi Fhir | 5/6/2019 | 17/6/2026 | XSS exists in the HAPI FHIR testpage overlay module of the HAPI FHIR library before 3.8.0. The attack involves unsanitized HTTP parameters being output in a form page, allowing attackers to leak cookies and other sensitive information from ca/uhn/fhir/to/BaseController.java via a specially crafted URL. (This module is… | |
| Modificada | Media (5.9) | 1.9% | — | Hapijs NES | 4/6/2018 | 17/6/2026 | Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denial of service vulnerability via an invalid Cookie header. This is only present when websocket authentication is set to `cookie`. Submitting an invalid cookie on the websocket upgrade request will… | |
| Modificada | Alta (7.5) | 1.6% | — | Hapijs Hapi | 4/6/2018 | 17/6/2026 | hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` header an uncaught exception is thrown. This may cause hapi to crash or to hang the client connection until the timeout period is reached. | |
| Modificada | Media (5.3) | 1.5% | — | Hapijs Hapi | 31/5/2018 | 17/6/2026 | Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsistent headers and at worst allowed cross-origin activities that were expected to be forbidden. If the connection has CORS enabled but one route has it off, and the route is not GET, the OPTIONS… | |
| Modificada | Crítica (9.8) | 2.5% | — | Dwyl Hapi-auth-jwt2 | 29/5/2018 | 17/6/2026 | When attempting to allow authentication mode `try` in hapi, hapi-auth-jwt2 version 5.1.1 introduced an issue whereby people could bypass authentication. | |
| Modificada | Media (5.9) | 1.0% | — | Hapijs Hapi | 29/5/2018 | 17/6/2026 | When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined and when a higher level config included security restrictions (like origin), a higher level config that included security restrictions (like origin) would have those restrictions overridden by less… | |
| Modificada | Alta (7.5) | 2.1% | — | Hapijs Hapi | 29/5/2018 | 17/6/2026 | Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be raised. Instead of sending a HTTP 500 error back to the sender, hapi node module before 11.1.3 will continue to hold the socket open until timed out (default node timeout is 2 minutes). | |
| Modificada | Alta (7.5) | 1.9% | — | Hapi Inert | 29/5/2018 | 17/6/2026 | The inert directory handler in inert node module before 1.1.1 always allows files in hidden directories to be served, even when `showHidden` is false. | |
| Modificada | Alta (8.8) | 4.2% | — | Hapijs Hoek | 30/3/2018 | 17/6/2026 | hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge' and 'applyToDefaults' functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that… | |
| Modificada | Media (5.8) | 1.4% | — | Sideway Hapi Crumb | 25/12/2014 | 17/6/2026 | The Crumb plugin before 3.0.0 for Node.js does not properly restrict token access in situations where a hapi route handler has CORS enabled, which allows remote attackers to obtain sensitive information, and potentially obtain the ability to spoof requests to non-CORS routes, via a crafted web site that is visited by… | |
| Modificada | Media (5) | 2.4% | — | Spumko Project Hapi Server Framework | 16/5/2014 | 17/6/2026 | The hapi server framework 2.0.x and 2.1.x before 2.2.0 for Node.js allows remote attackers to cause a denial of service (file descriptor consumption and process crash) via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.0% | — | Chapi Tiny Event | 2/4/2007 | 16/6/2026 | SQL injection vulnerability in index.php in the Tiny Event (tinyevent) 1.01 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action. |