Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
202 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.35% | — | Hono | 27/1/2026 | 17/6/2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, IP Restriction Middleware in Hono is vulnerable to an IP address validation bypass. The `IPV4_REGEX` pattern and `convertIPv4ToBinary` function in `src/utils/ipaddr.ts` do not properly validate that IPv4… | |
| Analizada | Media (6.5) | 0.14% | — | Hono | 13/1/2026 | 17/6/2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the algorithm specified in the JWT header to influence signature verification when the selected JWK did not explicitly define an algorithm. This… | |
| Analizada | Media (6.5) | 0.16% | — | Hono | 13/1/2026 | 17/6/2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the JWT header’s alg value to influence signature verification when the selected JWK did not explicitly specify an algorithm. This could enable… | |
| Analizada | Alta (8.1) | 0.38% | — | Hono | 22/10/2025 | 17/6/2026 | Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4.10.2, Hono’s JWT Auth Middleware does not provide a built-in aud (Audience) verification option, which can cause confused-deputy / token-mix-up issues: an API may accept a valid token that was… | |
| Aplazada | Media (4) | 0.18% | — | HonorAI | 20/10/2025 | 17/6/2026 | Some Honor products are affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality. | |
| Analizada | Media (5.3) | 0.45% | 💥 PoC | Hono | 12/9/2025 | 17/6/2026 | Hono is a Web application framework that provides support for any JavaScript runtime. In versions prior to 4.9.7, a flaw in the `bodyLimit` middleware could allow bypassing the configured request body size limit when conflicting HTTP headers were present. The middleware previously prioritized the `Content-Length`… | |
| Analizada | Alta (7.5) | 0.53% | — | Hono | 5/9/2025 | 17/6/2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Versions 4.8.0 through 4.9.5 contain a flaw in the getPath utility function which could allow path confusion and potential bypass of proxy-level ACLs (e.g. Nginx location blocks). The original implementation relied on fixed character… | |
| Analizada | Alta (8.8) | 0.42% | — | Honor PC Manager | 30/6/2025 | 17/6/2026 | Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named pipe iMateBookAssistant with default or overly permissive security attributes, leading to a privilege escalation. | |
| Analizada | Media (4.3) | 0.29% | — | Honor Baidu | 17/4/2025 | 17/6/2026 | Browser is affected by type confusion vulnerability, successful exploitation of this vulnerability may affect service availability. | |
| Analizada | Crítica (9.1) | 0.34% | — | Honor Gamecenter | 17/4/2025 | 17/6/2026 | There is a whitelist mechanism bypass in GameCenter ,successful exploitation of this vulnerability may affect service confidentiality and integrity. | |
| Analizada | Crítica (9.1) | 0.35% | — | Honor Phoneservice | 17/4/2025 | 17/6/2026 | Phoneservice module is affected by code injection vulnerability, successful exploitation of this vulnerability may affect service confidentiality and integrity. | |
| Analizada | Media (5.5) | 0.15% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | |
| Analizada | Media (5.5) | 0.15% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions. | |
| Analizada | Media (5.5) | 0.16% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | |
| Analizada | Media (5.5) | 0.16% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | |
| Analizada | Media (5.5) | 0.16% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | |
| Analizada | Media (5.5) | 0.12% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions. | |
| Analizada | Media (5.5) | 0.16% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | |
| Analizada | Media (5.5) | 0.16% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | |
| Analizada | Media (5.5) | 0.16% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | |
| Analizada | Media (5.5) | 0.14% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions. | |
| Analizada | Media (5.5) | 0.15% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | |
| Analizada | Alta (7.8) | 0.17% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by file writing vulnerability, successful exploitation could cause code execution | |
| Analizada | Media (5.9) | 0.33% | — | Hono | 15/10/2024 | 17/6/2026 | Hono, a web framework, prior to version 4.6.5 is vulnerable to bypass of cross-site request forgery (CSRF) middleware by a request without Content-Type header. Although the CSRF middleware verifies the Content-Type Header, Hono always considers a request without a Content-Type header to be safe. This can allow an… | |
| Analizada | Media (5) | 0.24% | — | Hono | 22/8/2024 | 17/6/2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Hono CSRF middleware can be bypassed using crafted Content-Type header. MIME types are case insensitive, but isRequestedByFormElementRe only matches lower-case. As a result, attacker can bypass csrf middleware using upper-case… |