Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

1353 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)12%—OpensslCanonical Ubuntu LinuxDebian LinuxNodejs Node.js+1530/10/201817/6/2026
The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected…
ModificadaMedia (5.9)4.7%—OpensslCanonical Ubuntu LinuxDebian LinuxNodejs Node.js+1829/10/201817/6/2026
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).
ModificadaAlta (7.5)2.8%—Nodejs Node.js21/8/201817/6/2026
In all versions of Node.js 10 prior to 10.9.0, an argument processing flaw can cause `Buffer.alloc()` to return uninitialized memory. This method is intended to be safe and only return initialized, or cleared, memory. The third argument specifying `encoding` can be passed as a number, this is misinterpreted by…
ModificadaAlta (7.5)8.1%—Nodejs Node.jsRedhat Openshift Container Platform21/8/201817/6/2026
In all versions of Node.js prior to 6.14.4, 8.11.4 and 10.9.0 when used with UCS-2 encoding (recognized by Node.js under the names `'ucs2'`, `'ucs-2'`, `'utf16le'` and `'utf-16le'`), `Buffer#write()` can be abused to write outside of the bounds of a single `Buffer`. Writes that start from the second-to-last position…
ModificadaMedia (5.4)0.81%—HP Network Node Manager I6/8/201817/6/2026
A security vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10. The vulnerability could result in cross-site scripting (XSS).
ModificadaMedia (5.4)0.81%—HP Network Node Manager I6/8/201817/6/2026
A security vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10. The vulnerability could result in cross-site scripting (XSS).
ModificadaAlta (8.8)4.8%—HP Network Node Manager I6/8/201817/6/2026
A remote arbitrary code execution vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10 using Java Deserialization.
ModificadaAlta (7.8)1.0%—HP Network Node Manager I6/8/201817/6/2026
A local code execution security vulnerability was identified in HP Network Node Manager i (NNMi) v10.00, v10.10 and v10.20 Software.
ModificadaMedia (5.6)8.6%—Intel Atom CIntel Atom EIntel Atom X3Intel Atom Z+22110/7/201817/6/2026
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis.
ModificadaAlta (8.2)0.56%—Intel Converged Security Management Engine FirmwareNetapp Element Software Management Node10/7/201817/6/2026
Logic bug in Intel Converged Security Management Engine 11.x may allow an attacker to execute arbitrary code via local privileged access.
ModificadaCrítica (9.8)6.7%💥 PoCNode-macaddress Project Node-macaddress10/7/201817/6/2026
The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.
ModificadaCrítica (9.8)19%—Eclipse JettyDebian LinuxOracle Rest Data ServicesOracle Retail Xstore Payment+1526/6/201817/6/2026
In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC…
ModificadaCrítica (9.8)15%—Eclipse JettyDebian LinuxNetapp E-series Santricity ManagementNetapp E-series Santricity OS Controller+1326/6/201817/6/2026
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk…
ModificadaAlta (7.5)0.89%—Intchain Node Token25/6/201817/6/2026
The mintToken function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "tradeTrap" issue.
ModificadaAlta (7.5)0.89%—Intchain Node Token25/6/201817/6/2026
The sell function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amount and a manipulable variable sellPrice, aka the…
ModificadaAlta (7.5)7.1%—Nodejs Node.js13/6/201817/6/2026
Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x…
ModificadaAlta (7.5)6.4%—Nodejs Node.js13/6/201817/6/2026
Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net.Socket object directly as a stream. An attacker could use this cause a denial of service by sending tiny chunks of…
ModificadaAlta (7.5)6.9%—Nodejs Node.js13/6/201817/6/2026
All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node process which provides an http server supporting TLS server to crash. This can be accomplished by sending duplicate/unexpected messages during the handshake. This…
ModificadaAlta (7.5)7.8%—Nodejs Node.js13/6/201817/6/2026
All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with the http2 server in a manner that triggers a cleanup bug where objects are used…
ModificadaAlta (7.5)49%—OpensslCanonical Ubuntu LinuxDebian LinuxNodejs Node.js12/6/201817/6/2026
During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited…
ModificadaMedia (6.5)8.6%💥 ExploitNode-srv Project Node-srv7/6/201817/6/2026
node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malicious user to read content of any file with known path.
ModificadaAlta (7.5)2.0%—Nodeaaaaa Project Nodeaaaaa7/6/201817/6/2026
nodeaaaaa is a static file server. nodeaaaaa is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaAlta (7.5)2.0%—Caolilinode Project Caolilinode7/6/201817/6/2026
caolilinode is a simple file server. caolilinode is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaAlta (7.5)2.0%—Node-server-forfront Project Node-server-forfront7/6/201817/6/2026
node-server-forfront is a simple static file server. node-server-forfront is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaAlta (7.5)2.0%—Node-simple-router7/6/201817/6/2026
node-simple-router is a minimalistic router for Node. node-simple-router is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.