Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
90 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.89% | — | Flatnest Project Flatnest | 30/6/2023 | 17/6/2026 | All versions of the package flatnest are vulnerable to Prototype Pollution via the nest() function in the flatnest/nest.js file. | |
| Modificada | Baja (3.8) | 0.66% | — | Kylephillips Nested Pages | 31/5/2023 | 17/6/2026 | The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions up to, and including, 3.2.3. This makes it possible for authenticated attackers, with editor-level permissions and above, to reset plugin settings. | |
| Modificada | Media (5.3) | 0.71% | — | Nestjs Nest | 6/3/2023 | 17/6/2026 | Versions of the package @nestjs/core before 9.0.5 are vulnerable to Information Exposure via the StreamableFile pipe. Exploiting this vulnerability is possible when the client cancels a request while it is streaming a StreamableFile, the stream wrapped by the StreamableFile will be kept open. | |
| Modificada | Media (5.4) | 0.47% | — | Onlinestorekit Oneclick Chat TO Order | 23/1/2023 | 17/6/2026 | The OneClick Chat to Order WordPress plugin before 1.0.4.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users… | |
| Modificada | Crítica (9.3) | 1.5% | — | Wormnest Project Wormnest | 11/7/2022 | 17/6/2026 | The operatorequals/wormnest repository through 0.4.7 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Media (4.8) | 0.67% | — | Kylephillips Nested Pages | 27/6/2022 | 17/6/2026 | The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is disallowed | |
| Modificada | Media (6.1) | 0.96% | — | Jenkins Nested View | 23/6/2022 | 17/6/2026 | Jenkins Nested View Plugin 1.20 through 1.25 (both inclusive) does not escape search parameters, resulting in a reflected cross-site scripting (XSS) vulnerability. | |
| Modificada | Alta (7.5) | 0.63% | — | Finastra Nestjs-proxyNestjs-proxy Project Nestjs-proxy | 15/6/2022 | 17/6/2026 | NestJS Proxy is a NestJS module to decorate and proxy calls. Prior to version 0.7.0, the nestjs-proxy library did not have a way to block sensitive cookies (e.g. session cookies) from being forwarded to backend services configured by the application developer. This could have led to sensitive cookies being… | |
| Modificada | Alta (7.5) | 0.63% | — | Finastra Nestjs-proxyNestjs-proxy Project Nestjs-proxy | 15/6/2022 | 17/6/2026 | NestJS Proxy is a NestJS module to decorate and proxy calls. Prior to version 0.7.0, the nestjs-proxy library did not have a way to control when Authorization headers should should be forwarded for specific backend services configured by the application developer. This could have resulted in sensitive information such… | |
| Modificada | Alta (8.8) | 0.42% | — | BD Pyxis Anesthesia Station ES FirmwareBD Pyxis Ciisafe FirmwareBD Pyxis Logistics FirmwareBD Pyxis Medbank Firmware+12 | 2/6/2022 | 17/6/2026 | Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product… | |
| Modificada | Crítica (9.8) | 2.1% | — | Libnested Project Libnested | 17/3/2022 | 17/6/2026 | The package libnested before 1.5.2 are vulnerable to Prototype Pollution via the set function in index.js. **Note:** This vulnerability derives from an incomplete fix for [CVE-2020-28283](https://security.snyk.io/vuln/SNYK-JS-LIBNESTED-1054930) | |
| Modificada | Media (5.5) | 0.23% | — | BD Pyxis Anesthesia Station ES FirmwareBD Pyxis Anesthesia Station 4000 FirmwareBD Pyxis Cato FirmwareBD Pyxis Ciisafe Firmware+20 | 11/2/2022 | 17/6/2026 | Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access to electronic protected health… | |
| Modificada | Alta (7.1) | 1.3% | — | Jenkins Nested View | 31/8/2021 | 17/6/2026 | Jenkins Nested View Plugin 1.20 and earlier does not configure its XML transformer to prevent XML external entity (XXE) attacks. | |
| Modificada | Media (6.1) | 0.83% | — | Kylephillips Nested Pages | 30/8/2021 | 17/6/2026 | The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npBulkActions`, `npBulkEdit`, `npListingSort`, and `npCategoryFilter` `admin_post` actions. | |
| Modificada | Alta (8.1) | 0.49% | — | Kylephillips Nested Pages | 30/8/2021 | 17/6/2026 | The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `npBulkEdit` `admin_post` actions, which allowed attackers to trash or permanently purge arbitrary posts as well as changing their status, reassigning their ownership, and editing other metadata. | |
| Modificada | Crítica (9.8) | 0.86% | — | Cnesty Helpcom | 29/6/2021 | 17/6/2026 | A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficient validation of the parameter. This issue affects: Cnesty Helpcom 10.0 versions prior to. | |
| Modificada | Crítica (9.8) | 3.0% | — | Nestie Project Nestie | 3/6/2021 | 17/6/2026 | Prototype pollution vulnerability in 'nestie' versions 0.0.0 through 1.0.0 allows an attacker to cause a denial of service and may lead to remote code execution. | |
| Modificada | Crítica (9.8) | 0.85% | — | Cnesty Helpcom | 20/4/2021 | 17/6/2026 | A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficient authentication validation. | |
| Modificada | Alta (8.8) | 1.1% | — | Cnesty Helpcom | 24/2/2021 | 17/6/2026 | Helpcom before v10.0 contains a file download and execution vulnerability caused by storing hardcoded cryptographic key. It finally leads to a file download and execution via access to crafted web page. | |
| Modificada | Alta (7.5) | 1.5% | — | Getadigital Nested-object-assign | 31/1/2021 | 17/6/2026 | The package nested-object-assign before 1.0.4 are vulnerable to Prototype Pollution via the default function, as demonstrated by running the PoC below. | |
| Modificada | Crítica (9.8) | 3.4% | — | Libnested Project Libnested | 29/12/2020 | 17/6/2026 | Prototype pollution vulnerability in 'libnested' versions 0.0.0 through 1.5.0 allows an attacker to cause a denial of service and may lead to remote code execution. | |
| Modificada | Media (6.1) | 0.33% | — | BD Pyxis Medstation ES FirmwareBD Pyxis Anesthesia Station ES Firmware | 1/4/2020 | 17/6/2026 | In BD Pyxis MedStation ES System v1.6.1 and Pyxis Anesthesia (PAS) ES System v1.6.1, a restricted desktop environment escape vulnerability exists in the kiosk mode functionality of affected devices. Specially crafted inputs could allow the user to escape the restricted environment, resulting in access to sensitive… | |
| Modificada | Alta (7.8) | 0.37% | — | Pronestor Planner | 18/12/2019 | 17/6/2026 | An issue was discovered in the Outlook add-in in Pronestor Planner before 8.1.77. There is local privilege escalation in the Health Monitor service because PronestorHealthMonitor.exe access control is mishandled, aka PNB-2359. | |
| Modificada | Alta (7.5) | 0.67% | — | Google Nest CAM IQ Indoor Firmware | 31/10/2019 | 17/6/2026 | An exploitable denial-of-service vulnerability exists in the Weave daemon of the Nest Cam IQ Indoor, version 4620002. A set of TCP connections can cause unrestricted resource allocation, resulting in a denial of service. An attacker can connect multiple times to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 0.49% | — | Google Nest CAM IQ Indoor Firmware | 20/8/2019 | 17/6/2026 | An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indoor, version 4620002. A specially crafted weave packets can cause an arbitrary Weave Exchange Session to close, resulting in a denial of service. An attacker can send a specially crafted packet to… |