Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
265 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.22% | — | Perl PreparecompanyprofileexportjsonAI | 27/8/2025 | 17/6/2026 | In the PrepareCDExportJSON.pl service, the "getPerfServiceIds" function is vulnerable to SQL injection. | |
| Aplazada | Media (5.4) | 0.17% | — | Structured Content Json LDAI | 14/8/2025 | 17/6/2026 | The Structured Content (JSON-LD) #wpsc WordPress plugin before 1.7.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Media (5.7) | 0.15% | — | ERCAIJsonpickleAI | 7/8/2025 | 17/6/2026 | ERC (aka Emotion Recognition in Conversation) through 0.3 has insecure deserialization via a serialized object because jsonpickle is used. | |
| Analizada | Alta (7.5) | 0.38% | — | Cosmwasm Serde-json-wasm | 27/7/2025 | 17/6/2026 | The serde-json-wasm crate before 1.0.1 for Rust allows stack consumption via deeply nested JSON data. | |
| Aplazada | Crítica (10) | 22% | — | Hikvision Integrated Security Management PlatformAIAlibaba FastjsonAI | 2/7/2025 | 17/6/2026 | An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger… | |
| Modificada | Media (5.5) | 0.27% | — | Cjson Project Cjson | 23/5/2025 | 17/6/2026 | parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called. | |
| Aplazada | Media (6.6) | 1.3% | — | Ejson2envAI | 21/5/2025 | 17/6/2026 | ejson2env allows users to decrypt EJSON secrets and export them as environment variables. Prior to version 2.0.8, the `ejson2env` tool has a vulnerability related to how it writes to `stdout`. Specifically, the tool is intended to write an export statement for environment variables and their values. However, due to… | |
| Aplazada | Baja (2.9) | 0.16% | — | MjsonAI | 19/4/2025 | 17/6/2026 | mystrtod in mjson 1.2.7 requires more than a billion iterations during processing of certain digit strings such as 8891110122900e913013935755114. | |
| Modificada | Baja (2.9) | 0.23% | — | Cjson Project Cjson | 19/4/2025 | 17/6/2026 | cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}. | |
| Aplazada | Media (4.8) | 0.21% | — | Joelittlejohn Jsonschema2pojoAI | 14/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in joelittlejohn jsonschema2pojo 1.2.2. This issue affects the function apply of the file org/jsonschema2pojo/rules/SchemaRule.java of the component JSON File Handler. The manipulation leads to stack-based buffer overflow. Attacking locally is a… | |
| Aplazada | Alta (7.1) | 0.14% | — | Samiahmedsiddiqui Json Structuring MarkupAI | 1/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Sami Ahmed Siddiqui JSON Structuring Markup json-structuring-markup allows Stored XSS.This issue affects JSON Structuring Markup: from n/a through <= 0.1. | |
| Analizada | Alta (8.8) | 1.6% | — | Nhairs Python Json Logger | 7/3/2025 | 17/6/2026 | Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE through a missing dependency. This occurred because msgspec-python313-pre was deleted by the owner leaving the name open to being claimed by a third party. If the package was… | |
| Aplazada | Alta (7.1) | 0.39% | — | Webgdawg Form TO JsonAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webgdawg Form To JSON form-to-json allows Reflected XSS.This issue affects Form To JSON: from n/a through <= 1.0. | |
| Aplazada | Alta (8.9) | 10% | — | Jsonpath-plusAI | 15/2/2025 | 17/6/2026 | Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode. **Note:** This is caused by an incomplete fix for… | |
| Aplazada | Alta (7.5) | 0.59% | — | Netplex Json-smartAI | 5/2/2025 | 17/6/2026 | A security issue was found in Netplex Json-smart 2.5.0 through 2.5.1. When loading a specially crafted JSON input, containing a large number of ’{’, a stack exhaustion can be trigger, which could allow an attacker to cause a Denial of Service (DoS). This issue exists because of an incomplete fix for CVE-2023-1370. | |
| Analizada | Crítica (9.8) | 0.64% | — | Rest & Json API Authentication Project Rest & Json API Authentication | 9/1/2025 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issue affects Drupal REST & JSON API Authentication: from 0.0.0 before 2.0.13. | |
| Aplazada | Alta (7.1) | 0.14% | — | Check JsonschemaAI | 29/11/2024 | 17/6/2026 | check-jsonschema is a CLI and set of pre-commit hooks for jsonschema validation. The default cache strategy uses the basename of a remote schema as the name of the file in the cache, e.g. `https://example.org/schema.json` will be stored as `schema.json`. This naming allows for conflicts. If an attacker can get a user… | |
| Aplazada | Crítica (9.8) | 9.0% | — | Jsonpath-plusAI | 11/10/2024 | 17/6/2026 | All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** There were several attempts to fix it in versions… | |
| Aplazada | Media (5.3) | 18% | — | Json-libAI | 4/10/2024 | 17/6/2026 | util/JSONTokener.java in JSON-lib before 3.1.0 mishandles an unbalanced comment string. | |
| Modificada | Crítica (9.8) | 0.97% | — | Lukebond Json-override | 30/7/2024 | 17/6/2026 | Prototype Pollution in lukebond json-override 0.2.0 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via the __proto__ property. | |
| Modificada | Media (6.4) | 0.25% | — | Json-content-importer Json Content Importer | 22/7/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Bernhard Kux JSON Content Importer.This issue affects JSON Content Importer: from n/a through 1.5.6. | |
| Modificada | Crítica (9.8) | 2.9% | — | Parorrey Json API User | 11/7/2024 | 17/6/2026 | The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper controls on custom user meta fields. This makes it possible for unauthenticated attackers to register as administrators on the site. The plugin requires the JSON API plugin… | |
| Aplazada | Alta (7.8) | 0.42% | — | Tencent RapidjsonAI | 9/7/2024 | 17/6/2026 | Tencent RapidJSON is vulnerable to privilege escalation due to an integer overflow in the `GenericReader::ParseNumber()` function of `include/rapidjson/reader.h` when parsing JSON text from a stream. An attacker needs to send the victim a crafted file which needs to be opened; this triggers the integer overflow… | |
| Aplazada | Alta (7.8) | 0.38% | — | Tencent RapidjsonAI | 9/7/2024 | 17/6/2026 | Tencent RapidJSON is vulnerable to privilege escalation due to an integer underflow in the `GenericReader::ParseNumber()` function of `include/rapidjson/reader.h` when parsing JSON text from a stream. An attacker needs to send the victim a crafted file which needs to be opened; this triggers the integer underflow… | |
| Analizada | Media (6.3) | 0.50% | — | Richardrodger Jsonic | 1/7/2024 | 17/6/2026 | rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function util.clone. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. |