Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2565▼ 302 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
1343 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.33% | — | Node-forgeAI | 3/9/2026 | 24/9/2026 | node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitrary messages using low-exponent RSA keys. This is an incomplete fix for… | |
| Aplazada | Alta (7.5) | 0.33% | — | Ovirt NodeAI | 3/9/2026 | 9/9/2026 | Signum Node is a HDD-mined cryptocurrency using an energy efficient and fair Proof-of-Commitment (PoC+) consensus algorithm. Prior to version 3.9.9, an integer overflow in BlockServiceImpl.applyBlock() allowed a miner to receive an arbitrarily inflated block reward by crafting a block with a negative… | |
| Aplazada | Alta (7.5) | 0.54% | — | Nodeca Js-yamlAI | 1/9/2026 | 28/9/2026 | js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2, 4.3.2, and 5.4.1, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key <<. An attacker can alias a large sequence of empty mappings into many merge targets, causing O(N *… | |
| Pendiente de análisis | Baja (3.7) | 0.27% | — | NodejsAI | 1/9/2026 | 3/9/2026 | A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while piping the original body to a reused backend connection. Node.js can omit headers beyond `maxHeadersCount` / `maxHeaderPairs` from… | |
| Pendiente de análisis | Crítica (9.3) | 2.0% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size property containing CRLF characters to sendMail(), the value is concatenated into the SMTP MAIL FROM command (as SIZE=...) without… | |
| Pendiente de análisis | Media (6.9) | 1.0% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly into SMTP commands without sanitizing carriage return and line feed characters, allowing attackers to inject arbitrary SMTP commands for… | |
| Pendiente de análisis | Alta (8.3) | 0.19% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised… | |
| Pendiente de análisis | Media (5.3) | 0.26% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF sequences to create additional headers in generated RFC822 messages, altering mail… | |
| Pendiente de análisis | Media (5.3) | 0.26% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls. | |
| Pendiente de análisis | Alta (7.1) | 0.35% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by crafting raw messages with file paths or… | |
| Pendiente de análisis | Media (6.9) | 0.30% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send specially crafted emails with malicious data URLs or embedded attachments to cause the event loop to hang and deny… | |
| Pendiente de análisis | Media (6.5) | 0.47% | — | Mariadb Connector/node.jsAIMysqlAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js permits SQL injection when attacker-controlled Buffer parameters are escaped client-side under the big5, gbk, sjis, cp932, or gb18030 client… | |
| Pendiente de análisis | Media (5.9) | 0.42% | — | Mariadb Connector/node.jsAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js can disclose an account password when PAM dialog authentication is negotiated over an insecure transport. In… | |
| Pendiente de análisis | Alta (7.5) | 0.57% | — | Mariadb Connector Node.jsAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to versions 3.3.3, 3.4.6, and 3.5.3, when ssl is enabled without a pinned CA or server certificate, MariaDB Connector/Node.js sends credentials before completing certificate fingerprint validation. In… | |
| Analizada | Media (6.1) | 0.58% | — | Dangerblack N8n-node-sqlite3 | 27/8/2026 | 23/9/2026 | n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n. Prior to 1.0.0, nodes/SqliteNode/v1/SqliteV1.node.ts exposes the db_path database file path as a node parameter that permits data expressions from upstream workflow input. A workflow author who maps untrusted input to db_path can allow a… | |
| Aplazada | Media (6.9) | 0.40% | — | Fdawgs Node-popplerAI | 25/8/2026 | 28/9/2026 | A vulnerability was detected in Fdawgs node-poppler up to 9.1.2/10.0.1. The impacted element is the function pdfInfo/pdfToText/pdfToCairo/pdfToPpm/pdfImages/pdfToHtml/pdfToPs/pdfFonts/pdfDetach/pdfAttach/pdfSeparate/pdfUnite of the file src/index.js of the component Argument Injection Handler. Performing a… | |
| Aplazada | Alta (8.8) | 0.49% | — | Mercadopago Node.js SDKAI | 24/8/2026 | 24/9/2026 | The Mercado Pago Node.js SDK interpolates caller-supplied identifiers into API request paths without percent-encoding them, so characters that are structural in a URL survive into the outgoing request. The payment (get, capture, cancel), paymentRefund (create, total, list, get), advancedPayment (get, capture, cancel,… | |
| Aplazada | Alta (7.1) | 0.24% | — | Stigmem-nodeAI | 19/8/2026 | 11/9/2026 | stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federation peer-token validation that can cause valid peer tokens to be incorrectly treated as expired. This affects the availability and reliability of authenticated federation flows on nodes using federation peer… | |
| Aplazada | Crítica (9.1) | 0.27% | — | Stigmem-nodeAI | 19/8/2026 | 11/9/2026 | stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled. Operators who explicitly disabled mTLS while binding federation to non-loopback addresses expose federation traffic to cleartext… | |
| Aplazada | Crítica (9.1) | 0.35% | — | Stigmem-nodeAI | 19/8/2026 | 11/9/2026 | stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval step. On nodes that accept federation peer registration over a network where initial registration can be intercepted or misdirected, an attacker can register a malicious… | |
| Aplazada | Alta (7.3) | 0.11% | — | Stigmem NodeAI | 19/8/2026 | 11/9/2026 | stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second explicit acknowledgment. If that setting is carried into an environment where plugin directories are writable by less-trusted users, unsigned (potentially malicious) plugin code could be loaded and… | |
| Aplazada | Alta (7.5) | 0.38% | — | Stigmem-nodeAIPostgresqlAI | 19/8/2026 | 11/9/2026 | stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting. In the affected code path the schema value is operator-controlled, but the unsafe pattern could allow SQL injection if a schema name were derived from tenant, request, or user input. Fixed in 0.9.0a2,… | |
| Aplazada | Alta (7.2) | 0.36% | — | Stigmem-nodeAI | 19/8/2026 | 11/9/2026 | stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism. issue_tombstone defaulted the tenant to "default" instead of the caller's tenant, allowing deletion records to be written to the wrong tenant, and the… | |
| Aplazada | Alta (8.6) | 0.36% | — | Stigmem-nodeAIStigmem-plugin-multi-tenantAI | 19/8/2026 | 24/9/2026 | stigmem-node before 0.9.0a12 contains a broken object level authorization (cross-tenant BOLA) vulnerability in the quarantine review endpoints. On multi-tenant deployments running the opt-in stigmem-plugin-multi-tenant, the list/count queries and _get_quarantined_fact in routes/quarantine.py lacked a tenant_id… | |
| Aplazada | Crítica (9.2) | 0.69% | — | Frangoteam FuxaAINodered Node-redAI | 18/8/2026 | 9/9/2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the allowDashboard authorization gate in server/integrations/node-red/index.js calls authJwt.verify for /nodered without inspecting the decoded identity. When nodeRedEnabled is true, secureEnabled is true, and… |