Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

77 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.9%—Get-npm-package-version Project Get-npm-package-version2/8/202217/6/2026
The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js.
ModificadaCrítica (9.8)1.5%—Npm-help Project Npm-help25/7/202217/6/2026
This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.latestVersion() function.
ModificadaAlta (7.5)3.9%—Npmjs NPMNetapp Ontap Select Deploy Administration Utility13/6/202217/6/2026
npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files…
ModificadaCrítica (9.8)2.2%—Npm-dependency-versions Project Npm-dependency-versions12/4/202217/6/2026
The npm-dependency-versions package through 0.3.0 for Node.js allows command injection if an attacker is able to call dependencyVersions with a JSON object in which pkgs is a key, and there are shell metacharacters in a value.
ModificadaAlta (8.8)1.6%—Pnpm21/3/202217/6/2026
PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute PNPM commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.
ModificadaCrítica (9.8)2.5%—Npm-lockfile Project Npm-lockfile3/3/202217/6/2026
OS Command Injection in GitHub repository ljharb/npm-lockfile in v2.0.3 and v2.0.4.
ModificadaCrítica (9.8)2.7%💥 PoCNpmjs NPMNetapp Next Generation Application Programming InterfaceFedoraproject Fedora13/11/202117/6/2026
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact…
ModificadaAlta (7.8)0.55%—Npmjs ArboristOracle GraalvmSiemens Sinec Infrastructure Network Services31/8/202117/6/2026
`@npmcli/arborist`, the library that calculates dependency trees and manages the node_modules folder hierarchy for the npm command line interface, aims to guarantee that package dependency contracts will be met, and the extraction of package contents will always be performed into the expected folder. This is…
ModificadaAlta (7.8)0.58%—Npmjs ArboristOracle GraalvmSiemens Sinec Infrastructure Network Services31/8/202117/6/2026
`@npmcli/arborist`, the library that calculates dependency trees and manages the `node_modules` folder hierarchy for the npm command line interface, aims to guarantee that package dependency contracts will be met, and the extraction of package contents will always be performed into the expected folder. This is, in…
ModificadaAlta (8.6)1.3%—Npmjs TAROracle GraalvmSiemens Sinec Infrastructure Network Services31/8/202117/6/2026
The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be outside of the extraction target directory is not extracted. This is, in part,…
ModificadaAlta (8.6)1.9%—Npmjs TARDebian LinuxOracle GraalvmSiemens Sinec Infrastructure Network Services31/8/202117/6/2026
The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that…
ModificadaAlta (8.6)3.3%—Npmjs TARDebian LinuxOracle GraalvmSiemens Sinec Infrastructure Network Services31/8/202117/6/2026
The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that…
ModificadaMedia (5.3)3.6%—Npmjs Hosted-git-infoSiemens Sinec Infrastructure Network Services23/3/202117/6/2026
The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity.
ModificadaAlta (7.8)6.0%💥 PoCMicrosoft NPM25/2/202117/6/2026
Visual Studio Code npm-script Extension Remote Code Execution Vulnerability
ModificadaAlta (7.5)3.5%—Npmjs Npm-user-validate27/10/202017/6/2026
This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.
ModificadaMedia (4.4)0.40%—Npmjs NPMOpensuse LeapFedoraproject Fedora7/7/202017/6/2026
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>". The password value is not redacted and is printed to stdout and also to any generated log files.
ModificadaCrítica (9.8)3.6%—Npm-programmatic Project Npm-programmatic7/4/202017/6/2026
npm-programmatic through 0.0.12 is vulnerable to Command Injection.The packages and option properties are concatenated together without any validation and are used by the 'exec' function directly.
ModificadaMedia (5.4)1.4%—Solarwinds Network Performance Monitor Orion Platform 2018 NetpathSolarwinds Network Performance Monitor Orion Platform 2018 NPM17/2/202017/6/2026
SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users via a crafted onerror attribute of a VIDEO element in an action for an ALERT.
ModificadaMedia (6.5)2.1%—Npmjs NPMOpensuse LeapOracle GraalvmFedoraproject Fedora+213/12/201917/6/2026
Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of packages that also…
ModificadaAlta (8.1)3.4%—Npmjs NPMOpensuse LeapOracle GraalvmFedoraproject Fedora+213/12/201917/6/2026
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field would allow a package publisher to modify and/or gain access to…
ModificadaMedia (6.5)3.3%—Redhat Enterprise LinuxRedhat Enterprise Linux EUSNpmjs NPMOpensuse Leap+213/12/201917/6/2026
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a…
ModificadaAlta (7.5)2.0%—Simple-npm-registry Project Simple-npm-registry7/6/201817/6/2026
simple-npm-registry is a local npm package cache. simple-npm-registry is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaCrítica (9.8)1.5%—Npm-script-demo Project Npm-script-demo7/6/201817/6/2026
The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry.
ModificadaAlta (8.1)1.8%—Mapbox Npm-test-sqlite3-trunk4/6/201817/6/2026
The npm-test-sqlite3-trunk module provides asynchronous, non-blocking SQLite3 bindings. npm-test-sqlite3-trunk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled…
ModificadaAlta (8.1)1.1%—Cnpmjs Operadriver31/5/201817/6/2026
operadriver is a Opera Driver for Selenium. operadriver versions below 0.2.3 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network…
Orbitaley — Vulnerabilidades