Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

79 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.3%—Ecstatic Project Ecstatic2/1/202017/6/2026
ecstatic have a denial of service vulnerability. Successful exploitation could lead to crash of an application.
ModificadaCrítica (9.8)8.4%—Static Http Server Project Static Http Server27/12/201916/6/2026
Static HTTP Server 1.0 has a Local Overflow
ModificadaAlta (7.5)1.5%—Statics-server Project Statics-server18/12/201917/6/2026
A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory.
ModificadaMedia (5.3)1.6%—Statichttpserver Project Statichttpserver3/9/201917/6/2026
A path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary folders.
ModificadaMedia (6.5)1.5%—Jenkins Static Analysis Utilities30/4/201917/6/2026
A missing permission check in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGraphConfigurationView#doSave form handler method allowed attackers with Overall/Read permission to change the per-job default graph configuration for all users.
ModificadaMedia (6.5)1.0%—Jenkins Static Analysis Utilities30/4/201917/6/2026
A cross-site request forgery vulnerability in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGraphConfigurationView#doSave form handler method allowed attackers to change the per-job default graph configuration for all users.
ModificadaAlta (7.5)1.8%—Static-resource-server Project Static-resource-server1/2/201917/6/2026
A path traversal vulnerability was found in module static-resource-server 1.7.2 that allows unauthorized read access to any file on the server by appending slashes in the URL.
ModificadaAlta (7.5)1.8%—Mcstatic Project Mcstatic1/2/201917/6/2026
A server directory traversal vulnerability was found on node module mcstatic <=0.0.20 that would allow an attack to access sensitive information in the file system by appending slashes in the URL path.
ModificadaMedia (6.1)0.77%—Tianma-static Project Tianma-static6/11/201817/6/2026
A stored xss in tianma-static module versions <=1.0.4 allows an attacker to execute arbitrary javascript.
ModificadaCrítica (10)7.0%—Apex-publish-static-files Project Apex-publish-static-files30/10/201817/6/2026
A command injection vulnerability in the apex-publish-static-files npm module version <2.0.1 which allows arbitrary shell command execution through a maliciously crafted argument.
ModificadaMedia (6.1)0.93%—Statics-server Project Statics-server20/7/201817/6/2026
An XSS in statics-server <= 0.0.9 can be used via injected iframe in the filename when statics-server displays directory index in the browser.
ModificadaAlta (7.5)2.0%—Mcstatic Project Mcstatic7/6/201817/6/2026
mcstatic node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a malicious user to read content of any file with known path.
ModificadaCrítica (9.8)3.6%—Static-eval Project Static-eval7/6/201817/6/2026
The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user input is able to access the global function constructor, effectively allowing arbitrary code execution.
ModificadaAlta (7.5)2.0%—Calmquist.static-server Project Calmquist.static-server7/6/201817/6/2026
calmquist.static-server is a static file server. calmquist.static-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaAlta (7.5)2.0%—Static-html-server Project Static-html-server7/6/201817/6/2026
static-html-server is a static file server. static-html-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaAlta (7.5)2.0%—Http Static Simple Project Http Static Simple7/6/201817/6/2026
http_static_simple is an http server. http_static_simple is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaMedia (6.1)0.93%—Sexstatic Project Sexstatic1/6/201817/6/2026
XSS in sexstatic <=0.6.2 causes HTML injection in directory name(s) leads to Stored XSS when malicious file is embed with <iframe> element used in directory name.
ModificadaAlta (7.5)2.1%—Ecstatic Project Ecstatic29/5/201817/6/2026
Certain input strings when passed to new Date() or Date.parse() in ecstatic node module before 1.4.0 will cause v8 to raise an exception. This leads to a crash and denial of service in ecstatic when this input is passed into the server via the If-Modified-Since header.
ModificadaAlta (7.5)2.6%—Ecstatic Project Ecstatic14/12/201717/6/2026
A regular expression Denial of Service (DoS) vulnerability in the file lib/ecstatic.js of the ecstatic npm package, before version 2.0.0, allows a remote attacker to overload and crash a server by passing a maliciously crafted string.
ModificadaAlta (7.5)2.4%—Catalyst-plugin-static-simple Project Catalyst-plugin-static-simple1/11/201717/6/2026
The Catalyst-Plugin-Static-Simple module before 0.34 for Perl allows remote attackers to read arbitrary files if there is a '.' character anywhere in the pathname, which differs from the intended policy of allowing access only when the filename itself has a '.' character.
ModificadaMedia (5.4)0.74%—Jenkins Static Analysis Utilities5/10/201717/6/2026
The Details view of some Static Analysis Utilities based plugins, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to these plugins, for example the console output which is parsed to extract build warnings (Warnings Plugin), could insert arbitrary HTML into…
ModificadaMedia (5.9)0.69%—Cloudfoundry Cf-releaseCloudfoundry Staticfile Buildpack13/6/201717/6/2026
An issue was discovered in Cloud Foundry Foundation cf-release v255 and Staticfile buildpack versions v1.4.0 - v1.4.3. A regression introduced in the Static file build pack causes the Staticfile.auth configuration to be ignored when the Static file file is not present in the application root. Applications containing a…
ModificadaMedia (4.3)2.6%—Serve-static Project Serve-static21/1/201517/6/2026
Open redirect vulnerability in the serve-static plugin before 1.7.2 for Node.js, when mounted at the root, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in the PATH_INFO to the default URI.
ModificadaMedia (4.3)1.3%—Stanislas Rolland Static Info Tables20/8/201316/6/2026
Cross-site scripting (XSS) vulnerability in the Static Info Tables (static_info_tables) extension before 2.3.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.3%—Franz Holzinger Static Methods9/8/201316/6/2026
Cross-site scripting (XSS) vulnerability in the Static Methods since 2007 (div2007) extension before 0.10.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the t3lib_div::quoteJSvalue function.