Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1353 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.52% | — | Bionode-sra | 1/6/2018 | 17/6/2026 | bionode-sra is a Node.js wrapper for SRA Toolkit. bionode-sra downloads data resources over HTTP, which leaves it vulnerable to MITM attacks. | |
| Modificada | Alta (8.1) | 1.7% | — | Node-sauce-connect Project Node-sauce-connect | 1/6/2018 | 17/6/2026 | sauce-connect is a Node.js wrapper over the SauceLabs SauceConnect.jar program for establishing a secure tunnel for intranet testing. sauce-connect downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested… | |
| Modificada | Alta (8.1) | 1.7% | — | Nodewebkit Project Nodewebkit | 1/6/2018 | 17/6/2026 | nodewebkit is an installer for node-webkit. nodewebkit downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested zip file with an attacker controlled zip file if the attacker is on the network or positioned in… | |
| Modificada | Alta (8.2) | 0.79% | — | I18n-node-angular Project I18n-node-angular | 31/5/2018 | 17/6/2026 | i18n-node-angular is a module used to interact between i18n and angular without using additional resources. A REST API endpoint that is used for development in i18n-node-angular before 1.4.0 was not disabled in production environments a malicious user could fill up the server causing a Denial of Service or content… | |
| Modificada | Alta (7.5) | 1.1% | — | Node-tkinter Project Node-tkinter | 29/5/2018 | 17/6/2026 | node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| Modificada | Alta (8.1) | 1.7% | — | Cue-sdk-node Project Cue-sdk-node | 29/5/2018 | 17/6/2026 | cue-sdk-node is a Corsair Cue SDK wrapper for node.js. cue-sdk-node downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested zip file with an attacker controlled zip file if the attacker is on the network or… | |
| Modificada | Alta (8.8) | 9.9% | — | Nodejs Node.js | 17/5/2018 | 17/6/2026 | The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remote code execution. An attack is possible from malicious websites open in a web browser on the same computer, or another computer with network access to the computer running the Node.js process. A… | |
| Modificada | Media (5.3) | 3.6% | — | Nodejs Node.js | 17/5/2018 | 17/6/2026 | The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`. The HTTP specification does not allow for spaces in the `Content-Length` value and the Node.js HTTP parser has been brought into… | |
| Modificada | Alta (7.5) | 3.4% | — | Nodejs Node.js | 17/5/2018 | 17/6/2026 | The `'path'` module in the Node.js 4.x release line contains a potential regular expression denial of service (ReDoS) vector. The code in question was replaced in Node.js 6.x and later so this vulnerability only impacts all versions of Node.js 4.x. The regular expression, `splitPathRe`, used within the `'path'` module… | |
| Modificada | Alta (7.5) | 11% | — | Nghttp2Nodejs Node.jsDebian Linux | 8/5/2018 | 17/6/2026 | nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in >= 1.31.1. | |
| Modificada | Alta (8.8) | 2.7% | — | Kadnode Project Kadnode | 13/3/2018 | 17/6/2026 | KadNode version version 2.2.0 contains a Buffer Overflow vulnerability in Arguments when starting up the binary that can result in Control of program execution flow, leading to remote code execution. | |
| Modificada | Media (6.5) | 0.69% | — | Jenkins JOB AND Node Ownership | 13/3/2018 | 17/6/2026 | An improper authorization vulnerability exists in Jenkins Job and Node Ownership Plugin 0.11.0 and earlier in OwnershipDescription.java, JobOwnerJobProperty.java, and OwnerNodeProperty.java that allow an attacker with Job/Configure or Computer/Configure permission and without Ownership related permissions to override… | |
| Modificada | Crítica (9.8) | 7.7% | — | HP Network Node Manager I | 15/2/2018 | 17/6/2026 | A Remote Bypass Security Restriction vulnerability in HPE Network Node Manager i (NNMi) Software versions v10.0x, v10.1x, v10.2x was found. | |
| Modificada | Media (4.8) | 1.0% | — | Jenkins Pipeline Nodes AND Processes | 23/1/2018 | 17/6/2026 | On Jenkins instances with Authorize Project plugin, the authentication associated with a build may lack the Computer/Build permission on some agents. This did not prevent the execution of Pipeline `node` blocks on those agents due to incorrect permissions checks in Pipeline: Nodes and Processes plugin 2.17 and earlier. | |
| Modificada | Media (4.7) | 0.36% | — | Linux KernelFedoraproject FedoraCanonical Ubuntu LinuxRedhat Enterprise Linux+16 | 9/1/2018 | 17/6/2026 | A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in netns_ids idr, which could lead to double free and memory corruption.… | |
| Modificada | Media (5.6) | 74% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+216 | 4/1/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. | |
| Modificada | Alta (7.5) | 43% | 💥 Exploit | Cisco Node-jose | 4/1/2018 | 17/6/2026 | A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens using a key that is embedded within the token. The vulnerability is due to node-jose following the JSON Web Signature (JWS) standard for JSON Web Tokens (JWTs). This standard… | |
| Modificada | Baja (3.1) | 2.3% | — | Nodejs Node.js | 11/12/2017 | 17/6/2026 | Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified. For example, 'Buffer.alloc(0x100, "This is not correctly encoded", "hex");' The buffer implementation was updated such that the buffer will be initialized to… | |
| Modificada | Crítica (9.1) | 2.4% | — | Nodejs Node.js | 11/12/2017 | 17/6/2026 | Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could send application data to Node.js using the TLS or HTTP2 modules in a way that bypassed TLS authentication and encryption. | |
| Modificada | Media (5.9) | 13% | — | OpensslDebian LinuxNodejs Node.js | 7/12/2017 | 17/6/2026 | There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH1024 are… | |
| Modificada | Alta (7.5) | 8.3% | — | Nodejs Node.js | 30/10/2017 | 14/7/2026 | Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter. | |
| Modificada | Media (5.3) | 3.4% | — | Openbsd OpensshOracle SUN ZFS Storage Appliance KITDebian LinuxNetapp Active IQ Unified Manager+17 | 26/10/2017 | 17/6/2026 | The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files. | |
| Modificada | Alta (7.5) | 34% | 💥 Exploit | Nodejs Node.js | 23/10/2017 | 17/6/2026 | Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in an unspecified path. | |
| Modificada | Crítica (9.8) | 3.8% | — | Node-printer Project Node-printer | 23/10/2017 | 17/6/2026 | The printDirect function in lib/printer.js in the node-printer module 0.0.1 and earlier for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in the lpr command. | |
| Modificada | Alta (7.5) | 8.0% | — | Nodejs Node.js | 10/10/2017 | 17/6/2026 | Node.js 4.0.0, 4.1.0, and 4.1.1 allows remote attackers to cause a denial of service. |