Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
49 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.53% | — | Clerk NextjsAIClerk NuxtAIClerk AstroAIClerk SharedAI | 24/4/2026 | 17/6/2026 | Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by certain crafted requests, allowing them to skip middleware gating and reach downstream handlers. This vulnerability is fixed in @clerk/astro 1.5.7,… | |
| Analizada | Media (6.1) | 0.26% | — | Nuxt OG Image | 31/3/2026 | 24/7/2026 | Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a vulnerability that allows injection of arbitrary attributes into the HTML page body. This issue has been patched in version 6.2.5. | |
| Analizada | Media (6.9) | 0.46% | — | Nuxt OG Image | 31/3/2026 | 24/7/2026 | Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a Denial of Service (DoS) vulnerability. The issue arises because there is no restriction on the width and height parameters of the… | |
| Analizada | Media (6.1) | 0.24% | — | Nuxt Devtools | 7/11/2025 | 17/6/2026 | A vulnerability in Nuxt DevTools has been fixed in version **2.6.4***. This issue may have allowed Nuxt auth token extraction via XSS under certain configurations. All users are encouraged to upgrade. More details: https://vercel.com/changelog/cve-2025-52662-xss-on-nuxt-devtools | |
| Analizada | Baja (3.1) | 0.37% | — | Nuxt | 17/9/2025 | 17/6/2026 | Nuxt is an open-source web development framework for Vue.js. Prior to 3.19.0 and 4.1.0, A client-side path traversal vulnerability in Nuxt's Island payload revival mechanism allowed attackers to manipulate client-side requests to different endpoints within the same application domain when specific prerendering… | |
| Aplazada | Alta (8.3) | 0.30% | — | Nuxtjs MDCAI | 18/7/2025 | 17/6/2026 | MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to version 0.17.2, a remote script-inclusion / stored cross-site scripting vulnerability in @nuxtjs/mdc lets a Markdown author inject a `<base href="https://attacker.tld">` element. The `<base>` tag rewrites how… | |
| Analizada | Alta (7.5) | 0.38% | — | Nuxt | 19/3/2025 | 17/6/2026 | Nuxt is an open-source web development framework for Vue.js. Prior to 3.16.0, by sending a crafted HTTP request to a server behind an CDN, it is possible in some circumstances to poison the CDN cache and highly impacts the availability of a site. It is possible to craft a request, such as… | |
| Aplazada | Media (5.3) | 0.34% | — | NuxtAIRspackAIWebpack.js WebpackAI | 25/1/2025 | 17/6/2026 | Nuxt is an open-source web development framework for Vue.js. Source code may be stolen during dev when using version 3.0.0 through 3.15.12 of the webpack builder or version 3.12.2 through 3.152 of the rspack builder and a victim opens a malicious web site. Because the request for classic script by a script tag is not… | |
| Aplazada | Media (5.3) | 0.55% | — | NuxtAI | 25/1/2025 | 17/6/2026 | Nuxt is an open-source web development framework for Vue.js. Starting in version 3.8.1 and prior to version 3.15.3, Nuxt allows any websites to send any requests to the development server and read the response due to default CORS settings. Users with the default server.cors option using Vite builder may get the source… | |
| Analizada | Alta (7.5) | 0.65% | — | Nuxt | 5/8/2024 | 17/6/2026 | Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. `nuxt/icon` provides an API to allow client side icon lookup. This endpoint is at `/api/_nuxt_icon/[name]`. The proxied request path is improperly parsed, allowing an attacker to change the scheme and host of the… | |
| Analizada | Alta (8.8) | 0.83% | — | Nuxt | 5/8/2024 | 17/6/2026 | Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Due to the insufficient validation of the `path` parameter in the NuxtTestComponentWrapper, an attacker can execute arbitrary JavaScript on the server side, which allows them to execute arbitrary commands. Users… | |
| Analizada | Media (6.1) | 0.44% | — | Nuxt | 5/8/2024 | 17/6/2026 | Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. The `navigateTo` function attempts to blockthe `javascript:` protocol, but does not correctly use API's provided by `unjs/ufo`. This library also contains parsing discrepancies. The function first tests to see if… | |
| Analizada | Alta (8.8) | 1.2% | — | Nuxt | 5/8/2024 | 17/6/2026 | Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Nuxt Devtools is missing authentication on the `getTextAssetContent` RPC function which is vulnerable to path traversal. Combined with a lack of Origin checks on the WebSocket handler, an attacker is able to… | |
| Modificada | Alta (7.5) | 0.80% | — | Johannschopplich Nuxt API Party | 9/12/2023 | 17/6/2026 | `nuxt-api-party` is an open source module to proxy API requests. The library allows the user to send many options directly to `ofetch`. There is no filter on which options are available. We can abuse the retry logic to cause the server to crash from a stack overflow. fetchOptions are obtained directly from the request… | |
| Modificada | Alta (7.5) | 0.82% | — | Johannschopplich Nuxt API Party | 9/12/2023 | 17/6/2026 | `nuxt-api-party` is an open source module to proxy API requests. nuxt-api-party attempts to check if the user has passed an absolute URL to prevent the aforementioned attack. This has been recently changed to use the regular expression `^https?://`, however this regular expression can be bypassed by an absolute URL… | |
| Modificada | Crítica (9.8) | 59% | — | Nuxt | 13/6/2023 | 17/6/2026 | Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3. | |
| Modificada | Crítica (9.8) | 0.74% | — | Nuxtlabs Nuxt | 18/4/2023 | 17/6/2026 | Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2. | |
| Analizada | Media (6.1) | 0.53% | — | Nuxt | 17/2/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository nuxt/framework prior to 3.2.1. | |
| Modificada | Media (6.1) | 0.46% | — | Nuxt Framework | 12/12/2022 | 17/6/2026 | Cross-site Scripting (XSS) - DOM in GitHub repository nuxt/framework prior to v3.0.0-rc.13. | |
| Modificada | Media (6.1) | 0.52% | — | Nuxt Framework | 12/12/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository nuxt/framework prior to v3.0.0-rc.13. | |
| Modificada | Media (5.4) | 0.43% | — | Nuxtjs Netlify-ipx | 23/9/2022 | 17/6/2026 | netlify-ipx is an on-Demand image optimization for Netlify using ipx. In versions prior to 1.2.3, an attacker can bypass the source image domain allowlist by sending specially crafted headers, causing the handler to load and return arbitrary images. Because the response is cached globally, this image will then be… | |
| Modificada | Media (4.4) | 0.36% | — | Linuxtv XawtvDebian LinuxOpensuse Backports SLEOpensuse Leap+2 | 8/6/2020 | 17/6/2026 | An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. This allows a local attacker with access to the v4l-conf setuid-root program to test for the… | |
| Modificada | Media (6.1) | 1.3% | — | Nuxtjs @nuxt/devalueNuxtjs Nuxt.js | 11/7/2019 | 17/6/2026 | @nuxt/devalue before 1.2.3, as used in Nuxt.js before 2.6.2, mishandles object keys, leading to XSS. | |
| Modificada | Media (6.9) | 0.40% | — | Linuxtrade | 6/11/2008 | 16/6/2026 | linuxtrade 3.65 allows local users to overwrite arbitrary files via a symlink attack on the (a) /tmp/bwk, (b) /tmp/zzz, and (c) /tmp/ggg temporary files, related to the (1) linuxtrade.bwkvol, (2) linuxtrade.wn, and (3) moneyam.helper scripts. |