Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

265 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.45%—SimdjsonAI14/5/202617/6/2026
An integer overflow vulnerability in the simdjson document-builder API allows incorrect buffer size calculations in "string_builder::escape_and_append()" when processing very large input strings on platforms with limited "size_t" width (e.g., 32-bit builds). The overflow can cause insufficient buffer allocation,…
AplazadaAlta (7.5)0.75%—LwjsonAI8/5/202617/6/2026
lwjson 1.8.1 contains an improper input validation vulnerability in the streaming JSON parser (lwjson_stream.c). The end-of-string detection logic incorrectly identifies escaped quote characters by only checking the immediately preceding character rather than counting consecutive backslashes, causing valid JSON…
ModificadaAlta (7.5)0.97%—Jsonparser Project Jsonparser26/3/20269/9/2026
The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.
ModificadaAlta (8.3)1.0%—Ruby-lang Json20/3/202621/8/2026
Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This…
ModificadaAlta (7.5)0.77%—Ultrajson Project Ultrajson20/3/202615/7/2026
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.10 through 5.11.0 are vulnerable to buffer overflow or infinite loop through large indent handling. ujson.dumps() crashes the Python interpreter (segmentation fault) when the product of the indent parameter and the…
ModificadaAlta (7.5)0.68%—Ultrajson Project Ultrajson20/3/202615/7/2026
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.4.0 through 5.11.0 contain an accumulating memory leak in JSON parsing large (outside of the range [-2^63, 2^64 - 1]) integers. The leaked memory is a copy of the string form of the integer plus an additional NULL…
AplazadaAlta (8.1)1.0%—Zumba Json SerializerAI21/2/202617/6/2026
Zumba Json Serializer is a library to serialize PHP variables in JSON format. In versions 3.2.2 and below, the library allows deserialization of PHP objects from JSON using a special @type field. The deserializer instantiates any class specified in the @type field without restriction. When processing untrusted JSON…
AplazadaAlta (7.8)0.67%—Newtonsoft JsonAIAlex4ssb ADB ExplorerAI13/2/202617/6/2026
ADB Explorer is a fluent UI for ADB on Windows. Prior to Beta 0.9.26020, ADB Explorer is vulnerable to Insecure Deserialization leading to Remote Code Execution. The application attempts to deserialize the App.txt settings file using Newtonsoft.Json with TypeNameHandling set to Objects. This allows an attacker to…
AplazadaAlta (8.2)1.1%—Dchester JsonpathAI9/2/202625/8/2026
Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JSON Path input, which is not designed to handle untrusted data safely. An attacker can exploit this…
AnalizadaMedia (5.5)0.62%—Keats Jsonwebtoken4/2/202617/6/2026
jsonwebtoken is a JWT lib in rust. Prior to version 10.3.0, there is a Type Confusion vulnerability in jsonwebtoken, specifically, in its claim validation logic. When a standard claim (such as nbf or exp) is provided with an incorrect JSON type (Like a String instead of a Number), the library’s internal parsing…
AnalizadaCrítica (9.8)0.51%—Dchester Jsonpath28/1/20267/9/2026
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
AplazadaMedia (5.3)0.43%—Briandilley Jsonrpc4jAI27/1/202617/6/2026
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in briandilley jsonrpc4j (src/main/java/com/googlecode/jsonrpc4j modules). This vulnerability is associated with program files NoCloseOutputStream.Java. This issue affects jsonrpc4j: through 1.6.0.
AnalizadaAlta (7.5)0.64%—IJL Orjson22/1/202617/6/2026
The orjson.dumps function in orjson thru 3.11.4 does not limit recursion for deeply nested JSON documents.
AplazadaCrítica (10)0.76%—Alibaba FastjsonAI9/1/202615/7/2026
Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of those methods, there may be JNDI injection with an attacker-supplied payload…
AnalizadaMedia (6.1)0.20%—Json Field Project Json Field30/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal JSON Field allows Cross-Site Scripting (XSS).This issue affects JSON Field: from 0.0.0 before 1.5.
AplazadaAlta (7.5)0.36%—Capev2AIMongodbAIIJL OrjsonAI20/10/20255/7/2026
Denial-of-analysis in reporting/mongodb.py and reporting/jsondump.py in CAPEv2 (commit 52e4b43, on 2025-05-17) allows attackers who can submit samples to cause incomplete or missing behavioral analysis reports by generating deeply nested or oversized behavior data that trigger MongoDB BSON limits or orjson recursion…
AnalizadaMedia (5.3)0.25%—Synchronize Composer.json With Contrib Modules Project Synchronize Composer.json With Contrib Modules10/10/202530/9/2026
Vulnerability in Drupal Synchronize composer.Json With Contrib Modules.This issue affects Synchronize composer.Json With Contrib Modules: *.*.
AnalizadaMedia (6.5)0.32%—Open-federation Json-schema-editor-visual24/9/202517/6/2026
json-schema-editor-visual is a package that provides jsonschema editor. A Prototype Pollution vulnerability in the setData and deleteData function of json-schema-editor-visual versions thru 1.1.1 allows attackers to inject or delete properties on Object.prototype via supplying a crafted payload, causing denial of…
AnalizadaAlta (7.5)0.39%—Pradeep-mishra Csvjson24/9/202517/6/2026
A Prototype Pollution vulnerability in the toCsv function of csvjson versions thru 5.1.0 allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.
AnalizadaAlta (8.6)0.31%—Keyangxiang Csvtojson24/9/202517/6/2026
The csvtojson package, a tool for converting CSV data to JSON with customizable parsing capabilities, contains a prototype pollution vulnerability in versions prior to 2.0.10. This issue arises due to insufficient sanitization of nested header names during the parsing process in the parser_jsonarray component. When…
AplazadaBaja (1.3)0.30%—JsondiffpatchAI11/9/202517/6/2026
Versions of the package jsondiffpatch before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin. An attacker can inject malicious scripts into HTML payloads that may lead to code execution if untrusted payloads were used as source for the diff, and the result renderer using the built-in…
AplazadaAlta (7.5)0.68%—Json SimdAI8/9/202517/6/2026
JSON::SIMD before version 1.07 and earlier for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact.
AplazadaMedia (5.6)0.44%—Cpanel Json XSAI8/9/202517/6/2026
Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact
AplazadaAlta (7.5)0.64%—Json XSAI8/9/202517/6/2026
JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact
ModificadaCrítica (9.8)0.74%—Davegamble Cjson3/9/202517/6/2026
cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing alphanumeric characters.