Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

202 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.35%—Hono27/1/202617/6/2026
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, IP Restriction Middleware in Hono is vulnerable to an IP address validation bypass. The `IPV4_REGEX` pattern and `convertIPv4ToBinary` function in `src/utils/ipaddr.ts` do not properly validate that IPv4…
AnalizadaMedia (6.5)0.14%—Hono13/1/202617/6/2026
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the algorithm specified in the JWT header to influence signature verification when the selected JWK did not explicitly define an algorithm. This…
AnalizadaMedia (6.5)0.16%—Hono13/1/202617/6/2026
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the JWT header’s alg value to influence signature verification when the selected JWK did not explicitly specify an algorithm. This could enable…
AnalizadaAlta (8.1)0.38%—Hono22/10/202517/6/2026
Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4.10.2, Hono’s JWT Auth Middleware does not provide a built-in aud (Audience) verification option, which can cause confused-deputy / token-mix-up issues: an API may accept a valid token that was…
AplazadaMedia (4)0.18%—HonorAI20/10/202517/6/2026
Some Honor products are affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality.
AnalizadaMedia (5.3)0.45%💥 PoCHono12/9/202517/6/2026
Hono is a Web application framework that provides support for any JavaScript runtime. In versions prior to 4.9.7, a flaw in the `bodyLimit` middleware could allow bypassing the configured request body size limit when conflicting HTTP headers were present. The middleware previously prioritized the `Content-Length`…
AnalizadaAlta (7.5)0.53%—Hono5/9/202517/6/2026
Hono is a Web application framework that provides support for any JavaScript runtime. Versions 4.8.0 through 4.9.5 contain a flaw in the getPath utility function which could allow path confusion and potential bypass of proxy-level ACLs (e.g. Nginx location blocks). The original implementation relied on fixed character…
AnalizadaAlta (8.8)0.42%—Honor PC Manager30/6/202517/6/2026
Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named pipe iMateBookAssistant with default or overly permissive security attributes, leading to a privilege escalation.
AnalizadaMedia (4.3)0.29%—Honor Baidu17/4/202517/6/2026
Browser is affected by type confusion vulnerability, successful exploitation of this vulnerability may affect service availability.
AnalizadaCrítica (9.1)0.34%—Honor Gamecenter17/4/202517/6/2026
There is a whitelist mechanism bypass in GameCenter ,successful exploitation of this vulnerability may affect service confidentiality and integrity.
AnalizadaCrítica (9.1)0.35%—Honor Phoneservice17/4/202517/6/2026
Phoneservice module is affected by code injection vulnerability, successful exploitation of this vulnerability may affect service confidentiality and integrity.
AnalizadaMedia (5.5)0.15%—Honor Magicos26/12/202417/6/2026
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
AnalizadaMedia (5.5)0.15%—Honor Magicos26/12/202417/6/2026
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
AnalizadaMedia (5.5)0.16%—Honor Magicos26/12/202417/6/2026
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
AnalizadaMedia (5.5)0.16%—Honor Magicos26/12/202417/6/2026
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
AnalizadaMedia (5.5)0.16%—Honor Magicos26/12/202417/6/2026
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
AnalizadaMedia (5.5)0.12%—Honor Magicos26/12/202417/6/2026
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
AnalizadaMedia (5.5)0.16%—Honor Magicos26/12/202417/6/2026
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
AnalizadaMedia (5.5)0.16%—Honor Magicos26/12/202417/6/2026
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
AnalizadaMedia (5.5)0.16%—Honor Magicos26/12/202417/6/2026
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
AnalizadaMedia (5.5)0.14%—Honor Magicos26/12/202417/6/2026
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
AnalizadaMedia (5.5)0.15%—Honor Magicos26/12/202417/6/2026
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
AnalizadaAlta (7.8)0.17%—Honor Magicos26/12/202417/6/2026
Some Honor products are affected by file writing vulnerability, successful exploitation could cause code execution
AnalizadaMedia (5.9)0.33%—Hono15/10/202417/6/2026
Hono, a web framework, prior to version 4.6.5 is vulnerable to bypass of cross-site request forgery (CSRF) middleware by a request without Content-Type header. Although the CSRF middleware verifies the Content-Type Header, Hono always considers a request without a Content-Type header to be safe. This can allow an…
AnalizadaMedia (5)0.24%—Hono22/8/202417/6/2026
Hono is a Web application framework that provides support for any JavaScript runtime. Hono CSRF middleware can be bypassed using crafted Content-Type header. MIME types are case insensitive, but isRequestedByFormElementRe only matches lower-case. As a result, attacker can bypass csrf middleware using upper-case…