Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

64 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.97%—DenoDeno RuntimeDeno Serde V824/3/202317/6/2026
Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Resizable ArrayBuffers passed to asynchronous functions that are shrunk during the asynchronous operation could result in an out-of-bound read/write. It is unlikely that this has been exploited in the wild, as the only version affected…
ModificadaAlta (7.5)1.2%—Deno25/2/202317/6/2026
Versions of the package deno before 1.31.0 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the upgradeWebSocket function, which contains regexes in the form of /s*,s*/, used for splitting the Connection/Upgrade header. A specially crafted Connection/Upgrade header can be used to significantly…
ModificadaAlta (7.5)0.60%—Deno17/1/202317/6/2026
Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Multi-threaded programs were able to spoof interactive permission prompt by rewriting the prompt to suggest that program is waiting on user confirmation to unrelated action. A malicious program could clear the terminal screen after…
ModificadaMedia (5.3)0.41%—Codenotary Immudb23/11/202217/6/2026
immudb is a database with built-in cryptographic proof and verification. In versions prior to 1.4.1, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server…
ModificadaMedia (5.9)0.28%—Codenotary Immudb22/11/202217/6/2026
immudb is a database with built-in cryptographic proof and verification. immudb client SDKs use server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. SDK does not validate this uuid and can accept any value…
ModificadaAlta (8.4)0.38%—Deno12/6/202217/6/2026
Deno <=1.14.0 file sandbox does not handle symbolic links correctly. When running Deno with specific write access, the Deno.symlink method can be used to gain access to any directory.
ModificadaCrítica (10)1.1%—Deno25/3/202217/6/2026
Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are vulnerable to an attack where a malicious actor controlling the code executed in a Deno runtime could bypass all permission checks and execute arbitrary shell code. This vulnerability does not affect…
ModificadaCrítica (9.8)2.1%—Deno Standard Modules11/10/202117/6/2026
Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations.
ModificadaCrítica (9.8)1.1%—Deno28/5/202117/6/2026
Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. In Deno versions 1.5.0 to 1.10.1, modules that are dynamically imported through `import()` or `new Worker` might have been able to bypass network and file system permission checks when statically importing other modules. The…
ModificadaAlta (7.5)1.5%—Linuxfoundation Nats.denoLinuxfoundation Nats.jsLinuxfoundation Nats.ws30/9/202017/6/2026
NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server.
ModificadaMedia (4.3)0.98%—Denon Avr-3313ci6/11/201417/6/2026
Cross-site scripting (XSS) vulnerability in s_network.asp in the Denon AVR-3313CI audio/video receiver allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, related to Friendlyname.
ModificadaMedia (4.3)1.1%—Denorastats Phpdenora10/3/200916/6/2026
Cross-site scripting (XSS) vulnerability in phpDenora before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via an IRC channel name. NOTE: some of these details are obtained from third party information.
ModificadaMedia (5)1.2%—Denora IRC Stats25/9/200816/6/2026
Unspecified vulnerability in Denora IRC Stats Server before 1.4.1 allows remote IRC servers to cause a denial of service (application crash) via a crafted CTCP response.
ModificadaAlta (7.5)2.9%—Denora IRC Stats7/8/200516/6/2026
Buffer overflow in the rdb_query function for Denora IRC Stats 1.0 might allow attackers to execute arbitrary code.
Orbitaley — Vulnerabilidades