Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 354 respecto a la semana anterior
Críticas / altas1295▼ 24 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (2.1) | 0.33% | — | GNU DiffutilsAI | 22/7/2026 | 27/7/2026 | diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds. When processing crafted diff output, these… | |
| Aplazada | Alta (7.2) | 0.48% | — | Nevware21 Ts-utilsAI | 21/7/2026 | 23/7/2026 | @nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility library. Prior to version 0.14.0, the _copyProps function in lib/src/object/copy.ts uses for...in to iterate over source object properties without an Object.hasOwnProperty check, and does not filter dangerous keys (__proto__, constructor, prototype).… | |
| Aplazada | Alta (8.2) | 0.46% | — | Tmlmobilidade UtilsAI | 16/7/2026 | 17/7/2026 | Gestor de Oferta is a web application for managing mobility service offerings. Prior to 20260509.0340.15, @tmlmobilidade/utils has a prototype pollution vulnerability in setValueAtPath() in packages/utils/src/generic/value-at-path.ts because unsafe path segments are not blocked. This issue is fixed in version… | |
| Aplazada | Alta (8.6) | 0.55% | — | Adonisjs BodyparserAIPoppinss UtilsAILodashAI | 15/7/2026 | 16/7/2026 | AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompletely fixed CVE-2026-25754 because nested multipart field payloads such as user.__proto__.polluted and constructor.prototype still caused lodash _.set() via @poppinss/utils to create plain… | |
| Aplazada | Media (5.5) | 2.1% | — | Facebook Create-react-appAIFacebook React-dev-utilsAI | 6/7/2026 | 6/7/2026 | A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProcess of the file openBrowser.js of the component react-dev-utils. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and… | |
| Aplazada | Media (6.3) | 0.48% | — | Apache Commons-beanutilsAIMchange C3p0AI | 30/6/2026 | 2/7/2026 | c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can compose to a "sink" for deserialization gadgets. The JDBC spec's DataSource.getConnection() and ConnectionPoolDataSource.getPooledConnection() match the getXXX() form, so JavaBean libraries treat them… | |
| Aplazada | Alta (7.5) | 0.66% | — | Perl List Someutils XSAI | 25/6/2026 | 25/6/2026 | List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise function. pairwise() collects the values returned by the block into a heap buffer sized to the longer input array, then grows the buffer before each copy with a single quadrupling (alloc <<= 2) instead of a loop. A block call… | |
| Pendiente de análisis | Alta (7.8) | 0.16% | — | Cifs-utilsAI | 18/6/2026 | 31/8/2026 | A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Analizada | Baja (3.3) | 0.15% | — | Uutils Coreutils | 22/4/2026 | 17/6/2026 | A logic error in the cut utility of uutils coreutils causes the utility to ignore the -s (only-delimited) flag when using the -z (null-terminated) and -d '' (empty delimiter) options together. The implementation incorrectly routes this specific combination through a specialized newline-delimiter code path that fails… | |
| Analizada | Media (5.5) | 0.16% | — | Uutils Coreutils | 22/4/2026 | 17/6/2026 | A logic error in the cut utility of uutils coreutils causes the program to incorrectly interpret the literal two-byte string '' (two single quotes) as an empty delimiter. The implementation mistakenly maps this string to the NUL character for both the -d (delimiter) and --output-delimiter options. This vulnerability… | |
| Analizada | Baja (3.3) | 0.15% | — | Uutils Coreutils | 22/4/2026 | 17/6/2026 | A logic error in the tr utility of uutils coreutils causes the program to incorrectly define the [:graph:] and [:print:] character classes. The implementation mistakenly includes the ASCII space character (0x20) in the [:graph:] class and excludes it from the [:print:] class, effectively reversing the standard… | |
| Analizada | Baja (3.3) | 0.16% | — | Uutils Coreutils | 22/4/2026 | 17/6/2026 | A logic error in the expr utility of uutils coreutils causes the program to evaluate parenthesized subexpressions during the parsing phase rather than at the execution phase. This implementation flaw prevents the utility from performing proper short-circuiting for logical OR (|) and AND (&) operations. As a result,… | |
| Analizada | Baja (3.3) | 0.13% | — | Uutils Coreutils | 22/4/2026 | 17/6/2026 | A logic error in the env utility of uutils coreutils causes a failure to correctly parse command-line arguments when utilizing the -S (split-string) option. In GNU env, backslashes within single quotes are treated literally (with the exceptions of \\ and \'). However, the uutils implementation incorrectly attempts to… | |
| Analizada | Media (5.8) | 0.11% | — | Uutils Coreutils | 22/4/2026 | 17/6/2026 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the chcon utility of uutils coreutils during recursive operations. The implementation resolves recursive targets using a fresh path lookup (via fts_accpath) rather than binding the traversal and label application to the specific directory state… | |
| Analizada | Baja (3.3) | 0.15% | — | Uutils Coreutils | 22/4/2026 | 17/6/2026 | A logic error in the split utility of uutils coreutils causes the corruption of output filenames when provided with non-UTF-8 prefix or suffix inputs. The implementation utilizes to_string_lossy() when constructing chunk filenames, which automatically rewrites invalid byte sequences into the UTF-8 replacement… | |
| Analizada | Media (6.3) | 0.09% | — | Uutils Coreutils | 22/4/2026 | 17/6/2026 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the split utility of uutils coreutils. The program attempts to prevent data loss by checking for identity between input and output files using their file paths before initiating the split operation. However, the utility subsequently opens the output file… | |
| Analizada | Media (5.5) | 0.14% | — | Uutils Coreutils | 22/4/2026 | 17/6/2026 | A logic error in the ln utility of uutils coreutils causes the program to reject source paths containing non-UTF-8 filename bytes when using target-directory forms (e.g., ln SOURCE... DIRECTORY). While GNU ln treats filenames as raw bytes and creates the links correctly, the uutils implementation enforces UTF-8… | |
| Analizada | Media (5) | 0.16% | — | Uutils Coreutils | 22/4/2026 | 17/6/2026 | A logic error in the ln utility of uutils coreutils allows the utility to dereference a symbolic link target even when the --no-dereference (or -n) flag is explicitly provided. The implementation previously only honored the "no-dereference" intent if the --force (overwrite) mode was also enabled. This flaw causes ln… | |
| Analizada | Baja (3.3) | 0.14% | — | Uutils Coreutils | 22/4/2026 | 17/6/2026 | The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly uses the effective GID instead of the effective UID when performing a name lookup for the effective user. This results in misleading diagnostic output… | |
| Analizada | Media (4.4) | 0.13% | — | Uutils Coreutils | 22/4/2026 | 17/6/2026 | The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of… | |
| Analizada | Media (5.5) | 0.15% | — | Uutils Coreutils | 22/4/2026 | 17/6/2026 | An argument parsing error in the kill utility of uutils coreutils incorrectly interprets kill -1 as a request to send the default signal (SIGTERM) to PID -1. Sending a signal to PID -1 causes the kernel to terminate all processes visible to the caller, potentially leading to a system crash or massive process… | |
| Analizada | Alta (7.8) | 0.15% | — | Uutils Coreutils | 22/4/2026 | 17/6/2026 | A vulnerability exists in the chroot utility of uutils coreutils when using the --userspec option. The utility resolves the user specification via getpwnam() after entering the chroot but before dropping root privileges. On glibc-based systems, this can trigger the Name Service Switch (NSS) to load shared libraries… | |
| Analizada | Baja (3.3) | 0.13% | — | Uutils Coreutils | 22/4/2026 | 17/6/2026 | The nohup utility in uutils coreutils creates its default output file, nohup.out, without specifying explicit restricted permissions. This causes the file to inherit umask-based permissions, typically resulting in a world-readable file (0644). In multi-user environments, this allows any user on the system to read the… | |
| Analizada | Media (4.4) | 0.19% | — | Uutils Coreutils | 22/4/2026 | 17/6/2026 | The printenv utility in uutils coreutils fails to display environment variables containing invalid UTF-8 byte sequences. While POSIX permits arbitrary bytes in environment strings, the uutils implementation silently skips these entries rather than printing the raw bytes. This vulnerability allows malicious environment… |