Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

265 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.22%—Perl PreparecompanyprofileexportjsonAI27/8/202517/6/2026
In the PrepareCDExportJSON.pl service, the "getPerfServiceIds" function is vulnerable to SQL injection.
AplazadaMedia (5.4)0.17%—Structured Content Json LDAI14/8/202517/6/2026
The Structured Content (JSON-LD) #wpsc WordPress plugin before 1.7.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
AplazadaMedia (5.7)0.15%—ERCAIJsonpickleAI7/8/202517/6/2026
ERC (aka Emotion Recognition in Conversation) through 0.3 has insecure deserialization via a serialized object because jsonpickle is used.
AnalizadaAlta (7.5)0.38%—Cosmwasm Serde-json-wasm27/7/202517/6/2026
The serde-json-wasm crate before 1.0.1 for Rust allows stack consumption via deeply nested JSON data.
AplazadaCrítica (10)22%—Hikvision Integrated Security Management PlatformAIAlibaba FastjsonAI2/7/202517/6/2026
An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger…
ModificadaMedia (5.5)0.27%—Cjson Project Cjson23/5/202517/6/2026
parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.
AplazadaMedia (6.6)1.3%—Ejson2envAI21/5/202517/6/2026
ejson2env allows users to decrypt EJSON secrets and export them as environment variables. Prior to version 2.0.8, the `ejson2env` tool has a vulnerability related to how it writes to `stdout`. Specifically, the tool is intended to write an export statement for environment variables and their values. However, due to…
AplazadaBaja (2.9)0.16%—MjsonAI19/4/202517/6/2026
mystrtod in mjson 1.2.7 requires more than a billion iterations during processing of certain digit strings such as 8891110122900e913013935755114.
ModificadaBaja (2.9)0.23%—Cjson Project Cjson19/4/202517/6/2026
cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.
AplazadaMedia (4.8)0.21%—Joelittlejohn Jsonschema2pojoAI14/4/202517/6/2026
A vulnerability, which was classified as problematic, has been found in joelittlejohn jsonschema2pojo 1.2.2. This issue affects the function apply of the file org/jsonschema2pojo/rules/SchemaRule.java of the component JSON File Handler. The manipulation leads to stack-based buffer overflow. Attacking locally is a…
AplazadaAlta (7.1)0.14%—Samiahmedsiddiqui Json Structuring MarkupAI1/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Sami Ahmed Siddiqui JSON Structuring Markup json-structuring-markup allows Stored XSS.This issue affects JSON Structuring Markup: from n/a through <= 0.1.
AnalizadaAlta (8.8)1.6%—Nhairs Python Json Logger7/3/202517/6/2026
Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE through a missing dependency. This occurred because msgspec-python313-pre was deleted by the owner leaving the name open to being claimed by a third party. If the package was…
AplazadaAlta (7.1)0.39%—Webgdawg Form TO JsonAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webgdawg Form To JSON form-to-json allows Reflected XSS.This issue affects Form To JSON: from n/a through <= 1.0.
AplazadaAlta (8.9)10%—Jsonpath-plusAI15/2/202517/6/2026
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode. **Note:** This is caused by an incomplete fix for…
AplazadaAlta (7.5)0.59%—Netplex Json-smartAI5/2/202517/6/2026
A security issue was found in Netplex Json-smart 2.5.0 through 2.5.1. When loading a specially crafted JSON input, containing a large number of ’{’, a stack exhaustion can be trigger, which could allow an attacker to cause a Denial of Service (DoS). This issue exists because of an incomplete fix for CVE-2023-1370.
AnalizadaCrítica (9.8)0.64%—Rest & Json API Authentication Project Rest & Json API Authentication9/1/202517/6/2026
Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issue affects Drupal REST & JSON API Authentication: from 0.0.0 before 2.0.13.
AplazadaAlta (7.1)0.14%—Check JsonschemaAI29/11/202417/6/2026
check-jsonschema is a CLI and set of pre-commit hooks for jsonschema validation. The default cache strategy uses the basename of a remote schema as the name of the file in the cache, e.g. `https://example.org/schema.json` will be stored as `schema.json`. This naming allows for conflicts. If an attacker can get a user…
AplazadaCrítica (9.8)9.0%—Jsonpath-plusAI11/10/202417/6/2026
All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** There were several attempts to fix it in versions…
AplazadaMedia (5.3)18%—Json-libAI4/10/202417/6/2026
util/JSONTokener.java in JSON-lib before 3.1.0 mishandles an unbalanced comment string.
ModificadaCrítica (9.8)0.97%—Lukebond Json-override30/7/202417/6/2026
Prototype Pollution in lukebond json-override 0.2.0 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via the __proto__ property.
ModificadaMedia (6.4)0.25%—Json-content-importer Json Content Importer22/7/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Bernhard Kux JSON Content Importer.This issue affects JSON Content Importer: from n/a through 1.5.6.
ModificadaCrítica (9.8)2.9%—Parorrey Json API User11/7/202417/6/2026
The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper controls on custom user meta fields. This makes it possible for unauthenticated attackers to register as administrators on the site. The plugin requires the JSON API plugin…
AplazadaAlta (7.8)0.42%—Tencent RapidjsonAI9/7/202417/6/2026
Tencent RapidJSON is vulnerable to privilege escalation due to an integer overflow in the `GenericReader::ParseNumber()` function of `include/rapidjson/reader.h` when parsing JSON text from a stream. An attacker needs to send the victim a crafted file which needs to be opened; this triggers the integer overflow…
AplazadaAlta (7.8)0.38%—Tencent RapidjsonAI9/7/202417/6/2026
Tencent RapidJSON is vulnerable to privilege escalation due to an integer underflow in the `GenericReader::ParseNumber()` function of `include/rapidjson/reader.h` when parsing JSON text from a stream. An attacker needs to send the victim a crafted file which needs to be opened; this triggers the integer underflow…
AnalizadaMedia (6.3)0.50%—Richardrodger Jsonic1/7/202417/6/2026
rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function util.clone. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.