Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.48% | — | Nicmx Fort-validator | 24/8/2024 | 17/6/2026 | An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a signed object containing an empty signedAttributes field. Fort accesses the set's elements without sanitizing it first. Because Fort is an RPKI Relying Party, a crash… | |
| Modificada | Alta (7.5) | 0.30% | — | Nicmx Fort Validator | 24/8/2024 | 17/6/2026 | An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing an Authority Key Identifier extension that lacks the keyIdentifier field. Fort references this pointer without sanitizing it first.… | |
| Modificada | Alta (7.5) | 0.45% | — | Nicmx Fort-validator | 24/8/2024 | 17/6/2026 | An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a signedAttrs encoded in non-canonical form. This bypasses Fort's BER decoder, reaching a point in the code that panics when faced with… | |
| Modificada | Alta (7.5) | 0.80% | — | Torbot Project TorbotValidators Project Validators | 18/10/2023 | 17/6/2026 | Torbot is an open source tor network intelligence tool. In affected versions the `torbot.modules.validators.validate_link function` uses the python-validators URL validation regex. This particular regular expression has an exponential complexity which allows an attacker to cause an application crash using a… | |
| Modificada | Media (4.8) | 0.47% | — | Nikolov Serial Codes Generator AND Validator With Woocommerce Support | 19/9/2023 | 17/6/2026 | The Serial Codes Generator and Validator with WooCommerce Support WordPress plugin before 2.4.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in… | |
| Modificada | Alta (7.5) | 0.92% | — | Csaf-validator-lib Project Csaf-validator-lib | 27/3/2023 | 17/6/2026 | The validate JSON endpoint of the Secvisogram csaf-validator-service in versions < 0.1.0 processes tests with unexpected names. This insufficient input validation of requests by an unauthenticated remote user might lead to a partial DoS of the service. Only the request of the attacker is affected by this vulnerability. | |
| Modificada | Media (6.5) | 0.26% | — | Csaf-validator-lib Project Csaf-validator-lib | 27/3/2023 | 17/6/2026 | An high privileged attacker may pass crafted arguments to the validate function of csaf-validator-lib of a locally installed Secvisogram in versions < 0.1.0 wich can result in arbitrary code execution and DoS once the users triggers the validation. | |
| Modificada | Crítica (9.8) | 0.72% | — | Healthit Code-validator-api | 29/12/2022 | 17/6/2026 | A vulnerability classified as problematic was found in ONC code-validator-api up to 1.0.30. This vulnerability affects the function vocabularyValidationConfigurations of the file src/main/java/org/sitenv/vocabularies/configuration/CodeValidatorApiConfiguration.java of the component XML Handler. The manipulation leads… | |
| Modificada | Alta (7.5) | 1.1% | — | Scniro-validator Project Scniro-validator | 27/6/2022 | 17/6/2026 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scniro-validator v1.0.1 when validating crafted invalid emails. | |
| Modificada | Alta (7.5) | 1.1% | — | Fort Validator Project Fort ValidatorDebian Linux | 9/11/2021 | 17/6/2026 | FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Origin Validation. | |
| Modificada | Alta (7.5) | 1.8% | — | Validator Project Validator | 2/11/2021 | 17/6/2026 | validator.js is vulnerable to Inefficient Regular Expression Complexity | |
| Modificada | Alta (7.5) | 1.8% | — | Djvalidator Project Djvalidator | 26/11/2020 | 17/6/2026 | All versions of package djvalidator are vulnerable to Regular Expression Denial of Service (ReDoS) by sending crafted invalid emails - for example, --@------------------------------------------------------------------------------------------------------------------------!. | |
| Modificada | Media (5.3) | 1.6% | — | Express-validators Project Express-validators | 11/11/2020 | 17/6/2026 | All versions of package express-validators are vulnerable to Regular Expression Denial of Service (ReDoS) when validating specifically-crafted invalid urls. | |
| Modificada | Crítica (9.8) | 2.5% | — | Json Pattern Validator Project Json Pattern Validator | 10/8/2020 | 17/6/2026 | jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array. | |
| Modificada | Alta (7.4) | 0.91% | — | Ripe Rpki Validator 3 | 30/7/2020 | 17/6/2026 | An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. It allows remote attackers to bypass intended access restrictions or to cause a denial of service on dependent routing systems by strategically withholding RPKI Route Origin Authorisation ".roa" files or X509 Certificate Revocation… | |
| Modificada | Crítica (9.1) | 1.3% | — | Ripe Rpki Validator 3 | 30/7/2020 | 17/6/2026 | An issue was discovered in RIPE NCC RPKI Validator 3.x before 3.1-2020.07.06.14.28. RRDP fetches proceed even with a lack of validation of a TLS HTTPS endpoint. This allows remote attackers to bypass intended access restrictions, or to trigger denial of service to traffic directed to co-dependent routing systems.… | |
| Modificada | Alta (7.5) | 0.74% | — | Ripe Rpki Validator 3 | 30/7/2020 | 17/6/2026 | An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. Missing validation checks on CRL presence or CRL staleness in the X509-based RPKI certificate-tree validation procedure allow remote attackers to bypass intended access restrictions by using revoked certificates. NOTE: there may be… | |
| Modificada | Alta (8.8) | 1.8% | — | Silverstripe MimevalidatorSilverstripe Recipe | 15/7/2020 | 17/6/2026 | Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML code in a TXT file). When these files are stored as protected or draft files, the MIME detection can cause browsers to execute the file contents. Uploads stored as… | |
| Modificada | Media (5.4) | 0.55% | — | W3C CSS Validator | 22/6/2020 | 17/6/2026 | In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A user would have to click on a specifically crafted validator link to trigger it. This has been patched in commit e5c09a9. | |
| Modificada | Media (5.3) | 2.4% | — | Redhat Hibernate ValidatorIBM Websphere Application ServerRedhat Jboss Enterprise Application PlatformRedhat Satellite+3 | 6/5/2020 | 17/6/2026 | A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling… | |
| Modificada | Alta (7.5) | 1.5% | — | Validators Project Validators | 5/12/2019 | 17/6/2026 | The validators package 0.12.2 through 0.12.5 for Python enters an infinite loop when validators.domain is called with a crafted domain string. This is fixed in 0.12.6. | |
| Modificada | Media (5.3) | 0.97% | — | Json Pattern Validator Project Json Pattern Validator | 2/12/2019 | 17/6/2026 | In jpv (aka Json Pattern Validator) before 2.1.1, compareCommon() can be bypassed because certain internal attributes can be overwritten via a conflicting name, as demonstrated by 'constructor': {'name':'Array'}. This affects validate(). Hence, a crafted payload can overwrite this builtin attribute to manipulate the… | |
| Modificada | Media (6.1) | 2.2% | — | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Crítica (9.8) | 2.0% | — | Typestack Class-validator Project Typestack Class-validator | 24/10/2019 | 17/6/2026 | In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name. Even though there is an optional forbidUnknownValues parameter that can be used to reduce the risk of this bypass, this option is not documented and thus most… | |
| Modificada | Alta (7.8) | 0.39% | — | Gemalto Safenet Authentication Service Tokenvalidator Proxy Agent | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service TokenValidator Proxy Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module. |