Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
77 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.17% | — | Pnpm | 25/6/2026 | 29/6/2026 | pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it wants and pnpm will install it regardless of the lockfile. The lockfile does not store the hash of the dependencies from https://codeload.github.com. This means that if this server was… | |
| Pendiente de análisis | Media (6.3) | 0.42% | — | NPM QSAI | 17/5/2026 | 17/6/2026 | ### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`). ### Details In the comma +… | |
| Aplazada | Crítica (9.8) | 1.5% | — | Next-npm-versionAI | 7/5/2026 | 17/6/2026 | NPM package next-npm-version1.0.1 is vulnerable to Command injection. | |
| Pendiente de análisis | Alta (8.8) | 1.2% | — | NPM Node-ts-ocrAI | 7/5/2026 | 17/6/2026 | NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js. | |
| Pendiente de análisis | Alta (8.6) | 0.74% | — | Qnabot-on-awsAINPM Static-evalAI | 27/4/2026 | 17/6/2026 | Improper use of the static-eval npm package in the open source solution qnabot-on-aws versions 7.2.4 and earlier may allow an authenticated administrator to execute arbitrary code within the fulfillment Lambda execution context by injecting a crafted conditional chaining expression via the Content Designer interface,… | |
| Analizada | Media (6.7) | 0.28% | — | Pnpm | 26/1/2026 | 17/6/2026 | pnpm is a package manager. Prior to version 10.28.2, when pnpm processes a package's `directories.bin` field, it uses `path.join()` without validating the result stays within the package root. A malicious npm package can specify `"directories": {"bin": "../../../../tmp"}` to escape the package directory, causing pnpm… | |
| Analizada | Media (6.7) | 0.53% | — | Pnpm | 26/1/2026 | 17/6/2026 | pnpm is a package manager. Prior to version 10.28.2, when pnpm installs a `file:` (directory) or `git:` dependency, it follows symlinks and reads their target contents without constraining them to the package root. A malicious package containing a symlink to an absolute path (e.g., `/etc/passwd`, `~/.ssh/id_rsa`)… | |
| Analizada | Media (6.5) | 0.51% | — | Pnpm | 26/1/2026 | 17/6/2026 | pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's bin linking allows malicious npm packages to create executable shims or symlinks outside of `node_modules/.bin`. Bin names starting with `@` bypass validation, and after scope normalization, path traversal sequences like… | |
| Analizada | Media (6.5) | 0.49% | — | Pnpm | 26/1/2026 | 17/6/2026 | pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's tarball extraction allows malicious packages to write files outside the package directory on Windows. The path normalization only checks for `./` but not `.\`. On Windows, backslashes are directory separators, enabling path… | |
| Analizada | Media (6.5) | 0.46% | — | Pnpm | 26/1/2026 | 17/6/2026 | pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's binary fetcher allows malicious packages to write files outside the intended extraction directory. The vulnerability has two attack vectors: (1) Malicious ZIP entries containing `../` or absolute paths that escape the… | |
| Aplazada | Alta (7) | 0.30% | — | NPM CLIAI | 23/1/2026 | 15/7/2026 | npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of npm cli. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.… | |
| Analizada | Alta (7.8) | 1.0% | — | Pnpm | 7/1/2026 | 22/6/2026 | pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environment variables during pnpm operations could achieve Remote Code Execution (RCE) in… | |
| Modificada | Crítica (9.8) | 1.0% | — | Pnpm | 7/1/2026 | 15/7/2026 | pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Dependency lifecycle scripts execution disabled by default". While pnpm v10 blocks postinstall scripts via the onlyBuiltDependencies mechanism,… | |
| Modificada | Alta (8.8) | 0.47% | — | Pnpm | 7/1/2026 | 15/7/2026 | pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve different content on each install, even when a lockfile is committed. An attacker who publishes a package with an HTTP tarball… | |
| Aplazada | Crítica (9.6) | 0.56% | 💥 PoC | NPMAISiemens NXAI | 24/9/2025 | 17/6/2026 | Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's… | |
| Aplazada | Alta (8.8) | 0.41% | — | BacklashAINPMAIBabelAIVercel Next.jsAI+2 | 15/9/2025 | 17/6/2026 | backlash parses collected strings with escapes. On 8 September 2025, the npm publishing account for backslash was taken over after a phishing attack. Version 0.2.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to… | |
| Aplazada | Crítica (10) | 0.68% | — | Google Cloud DataformAINPMAI | 25/8/2025 | 17/6/2026 | A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously crafted package.json file. | |
| Analizada | Media (6.5) | 0.23% | — | Pnpm | 23/4/2025 | 22/6/2026 | pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shortening compression function, and if a collision occurs, it will result in the same storage path for two different libraries. Although the real names are under the package name /node_modoules/, there are… | |
| Aplazada | Alta (8.2) | 0.21% | — | Velocidex WinpmemAI | 16/12/2024 | 17/6/2026 | Velocidex WinPmem versions below 4.1 suffer from an Out of Bounds Write vulnerability. By using an IO Control, a user space program can trick the driver into writing a 0 into any chosen memory location. In conjunction with information leakage from the WinPmem driver, attackers can discover the location in memory for… | |
| Aplazada | Alta (7.3) | 0.16% | — | Velocidex WinpmemAI | 16/12/2024 | 17/6/2026 | Velocidex WinPmem versions 4.1 and below suffer from an Improper Input Validation vulnerability whereby an attacker with admin access can trigger a BSOD with a parallel thread changing the memory’s access right under the control of the user-mode application. This is due to verification only being performed at the… | |
| Analizada | Media (5.8) | 0.98% | — | Pnpm | 10/12/2024 | 22/6/2026 | The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one workspace leak into npm metadata saved in global cache; npm metadata from global cache affects other workspaces; and installs by default don't revalidate the data (including on first lockfile generation).… | |
| Modificada | Alta (8.1) | 1.2% | — | OpenpmixFedoraproject FedoraDebian Linux | 9/9/2023 | 17/6/2026 | OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0. | |
| Modificada | Crítica (9.8) | 1.2% | 💥 PoC | Pnpm | 1/8/2023 | 17/6/2026 | pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed via pnpm is malicious, due to how pnpm parses tar archives. This can result in a package that appears safe on the npm registry or when installed via npm being replaced… | |
| Analizada | Alta (7.5) | 2.8% | — | Npmjs Semver | 21/6/2023 | 17/6/2026 | Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range. | |
| Modificada | Alta (8.1) | 1.5% | — | Cpanpm Project CpanpmPerl | 29/4/2023 | 17/6/2026 | CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS. |