Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 314 respecto a la semana anterior
Críticas / altas1340▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
305 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.49% | — | Nodejs Undici | 12/3/2026 | 17/6/2026 | Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-length). This produces malformed HTTP/1.1 requests with multiple conflicting Content-Length values on the wire. Who is impacted: Potential consequences: | |
| Aplazada | Media (5.1) | 0.29% | — | Igniterealtime OpenfireAIOpenfire Nodejs PluginAI | 26/1/2026 | 17/6/2026 | Openfire 4.6.0 contains a stored cross-site scripting vulnerability in the nodejs plugin that allows attackers to inject malicious scripts through the 'path' parameter. Attackers can craft a payload with script tags to execute arbitrary JavaScript in the context of administrative users viewing the nodejs configuration… | |
| Analizada | Alta (7.5) | 1.1% | — | Nodejs Node.js | 20/1/2026 | 17/6/2026 | A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process… | |
| Analizada | Crítica (10) | 0.88% | — | Nodejs Node.js | 20/1/2026 | 17/6/2026 | A flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--permission` is enabled. Even without `--allow-net`, attacker-controlled inputs (such as URLs or socketPath options) can connect to arbitrary local sockets via net, tls, or undici/fetch. This breaks… | |
| Analizada | Alta (7.5) | 0.69% | — | Nodejs Node.js | 20/1/2026 | 17/6/2026 | We have identified a bug in Node.js error handling where "Maximum call stack size exceeded" errors become uncatchable when `async_hooks.createHook()` is enabled. Instead of reaching `process.on('uncaughtException')`, the process terminates, making the crash unrecoverable. Applications that rely on `AsyncLocalStorage`… | |
| Modificada | Alta (7.5) | 4.0% | — | Nodejs Node.js | 20/1/2026 | 15/7/2026 | — | |
| Analizada | Alta (7.5) | 0.27% | — | Nodejs Node.js | 20/1/2026 | 17/6/2026 | A memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freeing the allocated buffer. When applications call `socket.getPeerCertificate(true)`, each certificate field leaks memory, allowing remote clients to trigger steady memory growth through repeated TLS… | |
| Analizada | Media (5.3) | 0.26% | — | Nodejs Node.js | 20/1/2026 | 17/6/2026 | A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories.… | |
| Aplazada | Alta (7.1) | 3.5% | — | Nodejs Node.jsAI | 20/1/2026 | 15/7/2026 | A flaw in Node.js's buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using the `vm` module with the timeout option. Under specific timing conditions, buffers allocated with `Buffer.alloc` and other `TypedArray` instances like `Uint8Array` may contain leftover data from… | |
| Modificada | Crítica (9.1) | 1.7% | — | Nodejs Node.js | 20/1/2026 | 15/7/2026 | A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the… | |
| Modificada | Alta (7.5) | 0.46% | — | Nodejs Undici | 14/1/2026 | 17/6/2026 | Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation. This vulnerability is fixed in… | |
| Analizada | Media (5.4) | 1.0% | — | PSU Haxcms-nodejs | 10/1/2026 | 17/6/2026 | HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead to account takeover. This issue has been patched in version 25.0.0. | |
| Aplazada | Alta (8.6) | 0.45% | — | Amazon Aurora PostgresqlAIAmazon Jdbc WrapperAIAmazon GO WrapperAIAmazon Nodejs WrapperAI+2 | 10/11/2025 | 17/6/2026 | An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users. We recommend customers upgrade to the… | |
| Aplazada | Alta (7.5) | 0.61% | — | Plone VoltoAINodejsAI | 28/8/2025 | 25/9/2026 | Volto is a React based frontend for the Plone Content Management System. In versions from 19.0.0-alpha.1 to before 19.0.0-alpha.4, 18.0.0 to before 18.24.0, 17.0.0 to before 17.22.1, and prior to 16.34.0, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL.… | |
| Aplazada | Media (5.3) | 0.39% | — | OAKAIDenoAIDeno DeployAINodejsAI+2 | 9/8/2025 | 17/6/2026 | oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. In versions 17.1.5 and below, it's possible to significantly slow down an oak server with specially crafted values of the x-forwarded-proto or x-forwarded-for headers. | |
| Analizada | Alta (8.3) | 0.50% | — | PSU Haxcms-nodejsPSU Haxcms-php | 26/7/2025 | 17/6/2026 | HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of haxcms-nodejs and versions 11.0.8 and below of haxcms-php, API endpoints do not perform authorization checks when interacting with a resource. Both the JS and PHP versions of the CMS do not verify that a… | |
| Analizada | Media (6.1) | 0.31% | — | PSU Haxcms-nodejsPSU Haxcms-php | 23/7/2025 | 17/6/2026 | HAX CMS allows users to manage their microsite universe with a NodeJS or PHP backend. In haxcms-nodejs versions 11.0.12 and below and in haxcms-php versions 11.0.7 and below, all pages within the HAX CMS application do not contain headers to prevent other websites from loading the site within an iframe. This applies… | |
| Analizada | Alta (7.3) | 0.34% | — | PSU Haxcms-nodejs | 22/7/2025 | 17/6/2026 | HAX CMS NodeJS allows users to manage their microsite universe with a NodeJS backend. Versions 11.0.9 and below were distributed with hardcoded default credentials for the user and superuser accounts. Additionally, the application has default private keys for JWTs. Users aren't prompted to change credentials or… | |
| Analizada | Alta (7.1) | 0.41% | — | PSU Haxcms-nodejs | 21/7/2025 | 17/6/2026 | HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the HAX CMS NodeJS application crashes when an authenticated attacker provides an API request lacking required URL parameters. This vulnerability affects the listFiles and saveFiles endpoints. This… | |
| Analizada | Alta (7.2) | 0.20% | — | PSU Haxcms-nodejs | 21/7/2025 | 17/6/2026 | HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.7 and below, the NodeJS version of HAX CMS has a disabled Content Security Policy (CSP). This configuration is insecure for a production application because it does not protect against cross-site-scripting attacks.… | |
| Analizada | Crítica (9.3) | 0.40% | — | PSU Haxcms-nodejs | 21/7/2025 | 17/6/2026 | HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and below, the NodeJS version of HAXcms uses an insecure default configuration designed for local development. The default configuration does not perform authorization or authentication checks. If a user… | |
| Aplazada | Alta (7.5) | 15% | — | Nodejs Node.jsAI | 18/7/2025 | 17/6/2026 | An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users of `path.join` API. | |
| Aplazada | Alta (7.5) | 1.2% | — | NodejsAI | 18/7/2025 | 17/6/2026 | The V8 release used in Node.js v24.0.0 has changed how string hashes are computed using rapidhash. This implementation re-introduces the HashDoS vulnerability as an attacker who can control the strings to be hashed can generate many hash collisions - an attacker can generate collisions even without knowing the… | |
| Aplazada | Alta (8.9) | 1.4% | — | Github Kanban MCP ServerAINodejsAIGithub GHAI | 14/7/2025 | 17/6/2026 | GitHub Kanban MCP Server is a Model Context Protocol (MCP) server for managing GitHub issues in Kanban board format and streamlining LLM task management. Version 0.3.0 of the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition… | |
| Analizada | Media (6.5) | 0.18% | — | PSU Haxcms-nodejsPSU Haxcms-php | 11/7/2025 | 17/6/2026 | haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the application issues a refresh token when logging out. This vulnerability is fixed in 11.0.6. |