Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

77 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)0.17%—Pnpm25/6/202629/6/2026
pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it wants and pnpm will install it regardless of the lockfile. The lockfile does not store the hash of the dependencies from https://codeload.github.com. This means that if this server was…
Pendiente de análisisMedia (6.3)0.42%—NPM QSAI17/5/202617/6/2026
### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`). ### Details In the comma +…
AplazadaCrítica (9.8)1.5%—Next-npm-versionAI7/5/202617/6/2026
NPM package next-npm-version1.0.1 is vulnerable to Command injection.
Pendiente de análisisAlta (8.8)1.2%—NPM Node-ts-ocrAI7/5/202617/6/2026
NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.
Pendiente de análisisAlta (8.6)0.74%—Qnabot-on-awsAINPM Static-evalAI27/4/202617/6/2026
Improper use of the static-eval npm package in the open source solution qnabot-on-aws versions 7.2.4 and earlier may allow an authenticated administrator to execute arbitrary code within the fulfillment Lambda execution context by injecting a crafted conditional chaining expression via the Content Designer interface,…
AnalizadaMedia (6.7)0.28%—Pnpm26/1/202617/6/2026
pnpm is a package manager. Prior to version 10.28.2, when pnpm processes a package's `directories.bin` field, it uses `path.join()` without validating the result stays within the package root. A malicious npm package can specify `"directories": {"bin": "../../../../tmp"}` to escape the package directory, causing pnpm…
AnalizadaMedia (6.7)0.53%—Pnpm26/1/202617/6/2026
pnpm is a package manager. Prior to version 10.28.2, when pnpm installs a `file:` (directory) or `git:` dependency, it follows symlinks and reads their target contents without constraining them to the package root. A malicious package containing a symlink to an absolute path (e.g., `/etc/passwd`, `~/.ssh/id_rsa`)…
AnalizadaMedia (6.5)0.51%—Pnpm26/1/202617/6/2026
pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's bin linking allows malicious npm packages to create executable shims or symlinks outside of `node_modules/.bin`. Bin names starting with `@` bypass validation, and after scope normalization, path traversal sequences like…
AnalizadaMedia (6.5)0.49%—Pnpm26/1/202617/6/2026
pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's tarball extraction allows malicious packages to write files outside the package directory on Windows. The path normalization only checks for `./` but not `.\`. On Windows, backslashes are directory separators, enabling path…
AnalizadaMedia (6.5)0.46%—Pnpm26/1/202617/6/2026
pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's binary fetcher allows malicious packages to write files outside the intended extraction directory. The vulnerability has two attack vectors: (1) Malicious ZIP entries containing `../` or absolute paths that escape the…
AplazadaAlta (7)0.30%—NPM CLIAI23/1/202615/7/2026
npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of npm cli. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.…
AnalizadaAlta (7.8)1.0%—Pnpm7/1/202622/6/2026
pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environment variables during pnpm operations could achieve Remote Code Execution (RCE) in…
ModificadaCrítica (9.8)1.0%—Pnpm7/1/202615/7/2026
pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Dependency lifecycle scripts execution disabled by default". While pnpm v10 blocks postinstall scripts via the onlyBuiltDependencies mechanism,…
ModificadaAlta (8.8)0.47%—Pnpm7/1/202615/7/2026
pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve different content on each install, even when a lockfile is committed. An attacker who publishes a package with an HTTP tarball…
AplazadaCrítica (9.6)0.56%💥 PoCNPMAISiemens NXAI24/9/202517/6/2026
Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's…
AplazadaAlta (8.8)0.41%—BacklashAINPMAIBabelAIVercel Next.jsAI+215/9/202517/6/2026
backlash parses collected strings with escapes. On 8 September 2025, the npm publishing account for backslash was taken over after a phishing attack. Version 0.2.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to…
AplazadaCrítica (10)0.68%—Google Cloud DataformAINPMAI25/8/202517/6/2026
A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously crafted package.json file.
AnalizadaMedia (6.5)0.23%—Pnpm23/4/202522/6/2026
pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shortening compression function, and if a collision occurs, it will result in the same storage path for two different libraries. Although the real names are under the package name /node_modoules/, there are…
AplazadaAlta (8.2)0.21%—Velocidex WinpmemAI16/12/202417/6/2026
Velocidex WinPmem versions below 4.1 suffer from an Out of Bounds Write vulnerability. By using an IO Control, a user space program can trick the driver into writing a 0 into any chosen memory location. In conjunction with information leakage from the WinPmem driver, attackers can discover the location in memory for…
AplazadaAlta (7.3)0.16%—Velocidex WinpmemAI16/12/202417/6/2026
Velocidex WinPmem versions 4.1 and below suffer from an Improper Input Validation vulnerability whereby an attacker with admin access can trigger a BSOD with a parallel thread changing the memory’s access right under the control of the user-mode application. This is due to verification only being performed at the…
AnalizadaMedia (5.8)0.98%—Pnpm10/12/202422/6/2026
The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one workspace leak into npm metadata saved in global cache; npm metadata from global cache affects other workspaces; and installs by default don't revalidate the data (including on first lockfile generation).…
ModificadaAlta (8.1)1.2%—OpenpmixFedoraproject FedoraDebian Linux9/9/202317/6/2026
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
ModificadaCrítica (9.8)1.2%💥 PoCPnpm1/8/202317/6/2026
pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed via pnpm is malicious, due to how pnpm parses tar archives. This can result in a package that appears safe on the npm registry or when installed via npm being replaced…
AnalizadaAlta (7.5)2.8%—Npmjs Semver21/6/202317/6/2026
Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
ModificadaAlta (8.1)1.5%—Cpanpm Project CpanpmPerl29/4/202317/6/2026
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
Orbitaley — Vulnerabilidades