Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
196 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 8.5% | 💥 Exploit | Nortekcontrol Emerge E3 Firmware | 25/8/2022 | 17/6/2026 | Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an attacker to take over an admin account or a user account. | |
| Modificada | Crítica (9.8) | 65% | 💥 Exploit | Nortekcontrol Emerge E3 Firmware | 25/8/2022 | 17/6/2026 | Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256. | |
| Modificada | Alta (8.2) | 7.0% | 💥 Exploit | Nortekcontrol Emerge E3 Firmware | 25/8/2022 | 17/6/2026 | Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.) | |
| Modificada | Crítica (9.8) | 1.8% | — | Typescript Deep Merge Project Typescript Deep Merge | 9/8/2022 | 17/6/2026 | The package ts-deepmerge before 2.0.2 are vulnerable to Prototype Pollution due to missing sanitization of the merge function. | |
| Modificada | Crítica (9.8) | 0.80% | — | Merge Project Merge | 25/7/2022 | 17/6/2026 | All versions of package @ianwalter/merge are vulnerable to Prototype Pollution via the main (merge) function. Maintainer suggests using @generates/merger instead. | |
| Modificada | Media (6.5) | 0.73% | — | Jenkins Jigomerge | 30/6/2022 | 17/6/2026 | Jenkins Jigomerge Plugin 0.9 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system. | |
| Modificada | Media (6.5) | 0.49% | — | Fastify Github Action Merge Dependabot | 31/5/2022 | 17/6/2026 | github-action-merge-dependabot is an action that automatically approves and merges dependabot pull requests (PRs). Prior to version 3.2.0, github-action-merge-dependabot does not check if a commit created by dependabot is verified with the proper GPG key. There is just a check if the actor is set to `dependabot[bot]`… | |
| Modificada | Crítica (9.8) | 1.7% | — | Deepmerge-ts Project Deepmerge-ts | 1/4/2022 | 17/6/2026 | deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. deepmerge-ts is vulnerable to Prototype Pollution via file deepmerge.ts, function defaultMergeRecords(). This issue has been patched in version 4.0.2. There are no known workarounds for this issue. | |
| Modificada | Crítica (9.8) | 1.3% | — | Putil-merge Project Putil-merge | 4/2/2022 | 17/6/2026 | This affects the package putil-merge before 3.8.0. The merge() function does not check the values passed into the argument. An attacker can supply a malicious value by adjusting the value to include the constructor property. Note: This vulnerability derives from an incomplete fix in… | |
| Modificada | Crítica (9.8) | 1.2% | — | Merge-deep2 Project Merge-deep2 | 10/12/2021 | 17/6/2026 | All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function. | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Crítica (9.8) | 1.4% | — | Merge Project Merge | 10/9/2021 | 17/6/2026 | merge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Modificada | Crítica (9.8) | 1.1% | — | Merge-change Project Merge-change | 11/8/2021 | 17/6/2026 | All versions of package merge-change are vulnerable to Prototype Pollution via the utils.set function. | |
| Modificada | Crítica (9.8) | 1.1% | — | Deepmergefn Project Deepmergefn | 28/7/2021 | 17/6/2026 | All versions of package deepmergefn are vulnerable to Prototype Pollution via deepMerge function. | |
| Modificada | Crítica (9.8) | 3.0% | — | Putil-merge Project Putil-merge | 14/7/2021 | 17/6/2026 | Prototype pollution vulnerability in 'putil-merge' versions1.0.0 through 3.6.6 allows attacker to cause a denial of service and may lead to remote code execution. | |
| Modificada | Crítica (9.8) | 1.9% | — | Merge-deep Project Merge-deepNetapp E-series Performance Analyzer | 2/6/2021 | 17/6/2026 | The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library. | |
| Modificada | Crítica (9.8) | 3.5% | — | Patchmerge Project Patchmerge | 16/3/2021 | 17/6/2026 | Prototype pollution vulnerability in 'patchmerge' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution. | |
| Modificada | Crítica (9.8) | 1.4% | — | Merge Project Merge | 18/2/2021 | 17/6/2026 | All versions of package merge are vulnerable to Prototype Pollution via _recursiveMerge . | |
| Modificada | Media (6.5) | 0.91% | — | Cisco Emergency ResponderCisco Prime License ManagerCisco Unified Communications ManagerCisco Unified Communications Manager IM & Presence Service+1 | 13/1/2021 | 17/6/2026 | A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, Cisco Emergency Responder, and Cisco Prime License Manager could allow an… | |
| Modificada | Media (6.1) | 1.6% | — | Papermerge | 2/12/2020 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Papermerge before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the rename, tag, upload, or create folder function. The payload can be in a folder, a tag, or a document's filename. If email consumption is configured in Papermerge, a… | |
| Modificada | Alta (7.5) | 3.6% | — | Controlled-merge Project Controlled-merge | 15/11/2020 | 17/6/2026 | Prototype pollution vulnerability in 'controlled-merge' versions 1.0.0 through 1.2.0 allows attacker to cause a denial of service and may lead to remote code execution. | |
| Modificada | Alta (7.5) | 1.3% | — | Json8-merge-patch Project Json8-merge-patch | 9/11/2020 | 17/6/2026 | Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor. | |
| Modificada | Media (4.8) | 0.62% | — | Cisco Emergency Responder | 23/9/2020 | 17/6/2026 | A vulnerability in the web framework of Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of some parameters that are passed to the web server… | |
| Modificada | Media (5.4) | 0.67% | — | IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics | 28/7/2020 | 17/6/2026 | IBM Intelligent Operations Center for Emergency Management, Intelligent Operations Center (IOC), and IBM Water Operations for Waternamics are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading… | |
| Modificada | Media (5.4) | 0.56% | — | IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics | 28/7/2020 | 17/6/2026 | IBM Intelligent Operations Center for Emergency Management, Intelligent Operations Center (IOC), and IBM Water Operations for Waternamics are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading… |