Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
94 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.26% | — | Csaf-validator-lib Project Csaf-validator-lib | 27/3/2023 | 17/6/2026 | An high privileged attacker may pass crafted arguments to the validate function of csaf-validator-lib of a locally installed Secvisogram in versions < 0.1.0 wich can result in arbitrary code execution and DoS once the users triggers the validation. | |
| Modificada | Crítica (9.8) | 0.72% | — | Healthit Code-validator-api | 29/12/2022 | 17/6/2026 | A vulnerability classified as problematic was found in ONC code-validator-api up to 1.0.30. This vulnerability affects the function vocabularyValidationConfigurations of the file src/main/java/org/sitenv/vocabularies/configuration/CodeValidatorApiConfiguration.java of the component XML Handler. The manipulation leads… | |
| Modificada | Alta (7.5) | 1.1% | — | Scniro-validator Project Scniro-validator | 27/6/2022 | 17/6/2026 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scniro-validator v1.0.1 when validating crafted invalid emails. | |
| Modificada | Alta (7.5) | 1.1% | — | Fort Validator Project Fort ValidatorDebian Linux | 9/11/2021 | 17/6/2026 | FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Origin Validation. | |
| Modificada | Alta (7.5) | 1.8% | — | Validator Project Validator | 2/11/2021 | 17/6/2026 | validator.js is vulnerable to Inefficient Regular Expression Complexity | |
| Modificada | Alta (7.5) | 1.8% | — | Djvalidator Project Djvalidator | 26/11/2020 | 17/6/2026 | All versions of package djvalidator are vulnerable to Regular Expression Denial of Service (ReDoS) by sending crafted invalid emails - for example, --@------------------------------------------------------------------------------------------------------------------------!. | |
| Modificada | Media (5.3) | 1.6% | — | Express-validators Project Express-validators | 11/11/2020 | 17/6/2026 | All versions of package express-validators are vulnerable to Regular Expression Denial of Service (ReDoS) when validating specifically-crafted invalid urls. | |
| Modificada | Crítica (9.8) | 2.5% | — | Json Pattern Validator Project Json Pattern Validator | 10/8/2020 | 17/6/2026 | jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array. | |
| Modificada | Alta (7.4) | 0.91% | — | Ripe Rpki Validator 3 | 30/7/2020 | 17/6/2026 | An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. It allows remote attackers to bypass intended access restrictions or to cause a denial of service on dependent routing systems by strategically withholding RPKI Route Origin Authorisation ".roa" files or X509 Certificate Revocation… | |
| Modificada | Crítica (9.1) | 1.3% | — | Ripe Rpki Validator 3 | 30/7/2020 | 17/6/2026 | An issue was discovered in RIPE NCC RPKI Validator 3.x before 3.1-2020.07.06.14.28. RRDP fetches proceed even with a lack of validation of a TLS HTTPS endpoint. This allows remote attackers to bypass intended access restrictions, or to trigger denial of service to traffic directed to co-dependent routing systems.… | |
| Modificada | Alta (7.5) | 0.74% | — | Ripe Rpki Validator 3 | 30/7/2020 | 17/6/2026 | An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. Missing validation checks on CRL presence or CRL staleness in the X509-based RPKI certificate-tree validation procedure allow remote attackers to bypass intended access restrictions by using revoked certificates. NOTE: there may be… | |
| Modificada | Alta (8.8) | 1.8% | — | Silverstripe MimevalidatorSilverstripe Recipe | 15/7/2020 | 17/6/2026 | Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML code in a TXT file). When these files are stored as protected or draft files, the MIME detection can cause browsers to execute the file contents. Uploads stored as… | |
| Modificada | Media (5.4) | 0.55% | — | W3C CSS Validator | 22/6/2020 | 17/6/2026 | In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A user would have to click on a specifically crafted validator link to trigger it. This has been patched in commit e5c09a9. | |
| Modificada | Media (5.3) | 2.4% | — | Redhat Hibernate ValidatorIBM Websphere Application ServerRedhat Jboss Enterprise Application PlatformRedhat Satellite+3 | 6/5/2020 | 17/6/2026 | A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling… | |
| Modificada | Alta (7.5) | 1.5% | — | Validators Project Validators | 5/12/2019 | 17/6/2026 | The validators package 0.12.2 through 0.12.5 for Python enters an infinite loop when validators.domain is called with a crafted domain string. This is fixed in 0.12.6. | |
| Modificada | Media (5.3) | 0.97% | — | Json Pattern Validator Project Json Pattern Validator | 2/12/2019 | 17/6/2026 | In jpv (aka Json Pattern Validator) before 2.1.1, compareCommon() can be bypassed because certain internal attributes can be overwritten via a conflicting name, as demonstrated by 'constructor': {'name':'Array'}. This affects validate(). Hence, a crafted payload can overwrite this builtin attribute to manipulate the… | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Crítica (9.8) | 2.0% | — | Typestack Class-validator Project Typestack Class-validator | 24/10/2019 | 17/6/2026 | In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name. Even though there is an optional forbidUnknownValues parameter that can be used to reduce the risk of this bypass, this option is not documented and thus most… | |
| Modificada | Alta (7.8) | 1.3% | — | Datools Daviewindy | 25/4/2019 | 17/6/2026 | DaviewIndy 8.98.7 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed PDF file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution. | |
| Modificada | Alta (7.8) | 1.3% | — | Datools Daviewindy | 25/4/2019 | 17/6/2026 | DaviewIndy 8.98.7 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed PhotoShop file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution. | |
| Modificada | Alta (7.8) | 1.2% | — | Datools Daviewindy | 25/4/2019 | 17/6/2026 | DaviewIndy 8.98.7 and earlier versions have a Heap-based overflow vulnerability, triggered when the user opens a malformed JPEG2000 format file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution. | |
| Modificada | Alta (7.8) | 1.3% | — | Datools Daviewindy | 25/4/2019 | 17/6/2026 | DaviewIndy 8.98.7 and earlier versions have a Heap-based overflow vulnerability, triggered when the user opens a malformed DIB format file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution. | |
| Modificada | Alta (7.5) | 1.1% | — | Ladatoken Project Ladatoken | 5/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for LadaToken (LDT), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (8.8) | 34% | 💥 Exploit | Cognitect DatomicH2database H2 | 11/4/2018 | 17/6/2026 | H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designed to be run outside of a secure environment." | |
| Modificada | Alta (7.8) | 0.39% | — | Gemalto Safenet Authentication Service Tokenvalidator Proxy Agent | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service TokenValidator Proxy Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module. |