Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
77 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.9% | — | Get-npm-package-version Project Get-npm-package-version | 2/8/2022 | 17/6/2026 | The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js. | |
| Modificada | Crítica (9.8) | 1.5% | — | Npm-help Project Npm-help | 25/7/2022 | 17/6/2026 | This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.latestVersion() function. | |
| Modificada | Alta (7.5) | 3.9% | — | Npmjs NPMNetapp Ontap Select Deploy Administration Utility | 13/6/2022 | 17/6/2026 | npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files… | |
| Modificada | Crítica (9.8) | 2.2% | — | Npm-dependency-versions Project Npm-dependency-versions | 12/4/2022 | 17/6/2026 | The npm-dependency-versions package through 0.3.0 for Node.js allows command injection if an attacker is able to call dependencyVersions with a JSON object in which pkgs is a key, and there are shell metacharacters in a value. | |
| Modificada | Alta (8.8) | 1.6% | — | Pnpm | 21/3/2022 | 17/6/2026 | PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute PNPM commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS. | |
| Modificada | Crítica (9.8) | 2.5% | — | Npm-lockfile Project Npm-lockfile | 3/3/2022 | 17/6/2026 | OS Command Injection in GitHub repository ljharb/npm-lockfile in v2.0.3 and v2.0.4. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 PoC | Npmjs NPMNetapp Next Generation Application Programming InterfaceFedoraproject Fedora | 13/11/2021 | 17/6/2026 | The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact… | |
| Modificada | Alta (7.8) | 0.55% | — | Npmjs ArboristOracle GraalvmSiemens Sinec Infrastructure Network Services | 31/8/2021 | 17/6/2026 | `@npmcli/arborist`, the library that calculates dependency trees and manages the node_modules folder hierarchy for the npm command line interface, aims to guarantee that package dependency contracts will be met, and the extraction of package contents will always be performed into the expected folder. This is… | |
| Modificada | Alta (7.8) | 0.58% | — | Npmjs ArboristOracle GraalvmSiemens Sinec Infrastructure Network Services | 31/8/2021 | 17/6/2026 | `@npmcli/arborist`, the library that calculates dependency trees and manages the `node_modules` folder hierarchy for the npm command line interface, aims to guarantee that package dependency contracts will be met, and the extraction of package contents will always be performed into the expected folder. This is, in… | |
| Modificada | Alta (8.6) | 1.3% | — | Npmjs TAROracle GraalvmSiemens Sinec Infrastructure Network Services | 31/8/2021 | 17/6/2026 | The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be outside of the extraction target directory is not extracted. This is, in part,… | |
| Modificada | Alta (8.6) | 1.9% | — | Npmjs TARDebian LinuxOracle GraalvmSiemens Sinec Infrastructure Network Services | 31/8/2021 | 17/6/2026 | The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that… | |
| Modificada | Alta (8.6) | 3.3% | — | Npmjs TARDebian LinuxOracle GraalvmSiemens Sinec Infrastructure Network Services | 31/8/2021 | 17/6/2026 | The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that… | |
| Modificada | Media (5.3) | 3.6% | — | Npmjs Hosted-git-infoSiemens Sinec Infrastructure Network Services | 23/3/2021 | 17/6/2026 | The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity. | |
| Modificada | Alta (7.8) | 6.0% | 💥 PoC | Microsoft NPM | 25/2/2021 | 17/6/2026 | Visual Studio Code npm-script Extension Remote Code Execution Vulnerability | |
| Modificada | Alta (7.5) | 3.5% | — | Npmjs Npm-user-validate | 27/10/2020 | 17/6/2026 | This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters. | |
| Modificada | Media (4.4) | 0.40% | — | Npmjs NPMOpensuse LeapFedoraproject Fedora | 7/7/2020 | 17/6/2026 | Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>". The password value is not redacted and is printed to stdout and also to any generated log files. | |
| Modificada | Crítica (9.8) | 3.6% | — | Npm-programmatic Project Npm-programmatic | 7/4/2020 | 17/6/2026 | npm-programmatic through 0.0.12 is vulnerable to Command Injection.The packages and option properties are concatenated together without any validation and are used by the 'exec' function directly. | |
| Modificada | Media (5.4) | 1.4% | — | Solarwinds Network Performance Monitor Orion Platform 2018 NetpathSolarwinds Network Performance Monitor Orion Platform 2018 NPM | 17/2/2020 | 17/6/2026 | SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users via a crafted onerror attribute of a VIDEO element in an action for an ALERT. | |
| Modificada | Media (6.5) | 2.1% | — | Npmjs NPMOpensuse LeapOracle GraalvmFedoraproject Fedora+2 | 13/12/2019 | 17/6/2026 | Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of packages that also… | |
| Modificada | Alta (8.1) | 3.4% | — | Npmjs NPMOpensuse LeapOracle GraalvmFedoraproject Fedora+2 | 13/12/2019 | 17/6/2026 | Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field would allow a package publisher to modify and/or gain access to… | |
| Modificada | Media (6.5) | 3.3% | — | Redhat Enterprise LinuxRedhat Enterprise Linux EUSNpmjs NPMOpensuse Leap+2 | 13/12/2019 | 17/6/2026 | Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a… | |
| Modificada | Alta (7.5) | 2.0% | — | Simple-npm-registry Project Simple-npm-registry | 7/6/2018 | 17/6/2026 | simple-npm-registry is a local npm package cache. simple-npm-registry is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Crítica (9.8) | 1.5% | — | Npm-script-demo Project Npm-script-demo | 7/6/2018 | 17/6/2026 | The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry. | |
| Modificada | Alta (8.1) | 1.8% | — | Mapbox Npm-test-sqlite3-trunk | 4/6/2018 | 17/6/2026 | The npm-test-sqlite3-trunk module provides asynchronous, non-blocking SQLite3 bindings. npm-test-sqlite3-trunk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled… | |
| Modificada | Alta (8.1) | 1.1% | — | Cnpmjs Operadriver | 31/5/2018 | 17/6/2026 | operadriver is a Opera Driver for Selenium. operadriver versions below 0.2.3 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network… |