Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
151 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.24% | — | React Draft WysiwygAI | 4/4/2025 | 17/6/2026 | All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the <iframe> tag. | |
| Aplazada | Alta (7.5) | 1.2% | — | RemixAIReact RouterAI | 1/4/2025 | 17/6/2026 | React Router is a multi-strategy router for React bridging the gap from React 18 to React 19. There is a vulnerability in Remix/React Router that affects all Remix 2 and React Router 7 consumers using the Express adapter. Basically, this vulnerability allows anyone to spoof the URL used in an incoming Request by… | |
| Aplazada | Media (6.5) | 0.22% | — | Afzal DU Reactive Mortgage CalculatorAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in afzal_du Reactive Mortgage Calculator reactive-mortgage-calculator allows Stored XSS.This issue affects Reactive Mortgage Calculator: from n/a through <= 1.1. | |
| Analizada | Media (4.8) | 0.25% | — | Jakob42 Reaction Buttons | 18/2/2025 | 17/6/2026 | The Reaction Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Analizada | Alta (7.2) | 0.69% | — | Progress Kendoreact | 12/2/2025 | 17/6/2026 | In Progress® Telerik® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection. | |
| Aplazada | Alta (7.1) | 0.32% | — | Areteit Post AND Page ReactionsAI | 13/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arete-it Post And Page Reactions post-and-page-reactions allows Reflected XSS.This issue affects Post And Page Reactions: from n/a through <= 1.0.5. | |
| Aplazada | Media (6.1) | 0.46% | — | Reactflow Visitor Recording AND HeatmapsAI | 21/12/2024 | 17/6/2026 | The Reactflow Visitor Recording and Heatmaps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_wpnonce' parameter in all versions up to, and including, 1.0.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (5) | 0.50% | — | Element WEBAIElement Matrix React SDKAIElement DesktopAI | 12/11/2024 | 17/6/2026 | Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over federation which can prevent Element Web and Desktop from rendering single messages or the entire room containing them. This was patched in Element Web and Desktop 1.11.85. | |
| Aplazada | Baja (3.5) | 0.34% | — | Element WEBAIElement Matrix React SDKAIElement DesktopAI | 12/11/2024 | 17/6/2026 | Element is a Matrix web client built using the Matrix React SDK. Versions of Element Web and Desktop earlier than 1.11.85 do not check if thumbnails for attachments, stickers and images are coherent. It is possible to add thumbnails to events trigger a file download once clicked. Fixed in element-web 1.11.85. | |
| Aplazada | Media (6.5) | 0.25% | — | Daniele Alessandra DA ReactionsAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniele Alessandra Da Reactions da-reactions allows Stored XSS.This issue affects Da Reactions: from n/a through <= 5.1.5. | |
| Aplazada | Alta (8.7) | 0.66% | — | Matrix-react-sdkAI | 15/10/2024 | 17/6/2026 | matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starting in version 3.18.0 and before 3.102.0, matrix-react-sdk allows a malicious homeserver to potentially steal message keys for a room when a user invites another user to that room, via injection of a… | |
| Analizada | Media (6.5) | 0.43% | — | Matrix-react-sdk | 6/8/2024 | 17/6/2026 | matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server. This was… | |
| Aplazada | Alta (7.1) | 1.1% | — | React-pdfAIMozilla Pdf.jsAI | 7/5/2024 | 17/6/2026 | react-pdf displays PDFs in React apps. If PDF.js is used to load a malicious PDF, and PDF.js is configured with `isEvalSupported` set to `true` (which is the default value), unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain. This vulnerability is fixed in 7.7.3 and 8.0.2. | |
| Aplazada | Media (5.3) | 0.73% | — | Redhat QuarkusAIResteasy ReactiveAI | 25/4/2024 | 5/8/2026 | A flaw was discovered in the RESTEasy Reactive implementation in Quarkus. Due to security checks for some JAX-RS endpoints being performed after serialization, more processing resources are consumed while the HTTP request is checked. In certain configurations, if an attacker has knowledge of any POST, PUT, or PATCH… | |
| Aplazada | Media (6.5) | 0.46% | — | QuarkusAIQuarkus Resteasy ClassicAIQuarkus Resteasy ReactiveAI | 25/4/2024 | 17/6/2026 | A flaw was found in Quarkus. When a Quarkus RestEasy Classic or Reactive JAX-RS endpoint has its methods declared in the abstract Java class or customized by Quarkus extensions using the annotation processor, the authorization of these methods will not be enforced if it is enabled by either… | |
| Analizada | Media (5.3) | 0.48% | — | Dev4press Coreactivity | 17/4/2024 | 17/6/2026 | The coreActivity: Activity Logging plugin for WordPress plugin before 2.1 retrieved IP addresses of requests via headers such X-FORWARDED to log them, allowing users to spoof them by providing an arbitrary value | |
| Aplazada | Media (4.3) | 0.40% | — | Discourse ReactionsAI | 15/4/2024 | 17/6/2026 | Discourse-reactions is a plugin that allows user to add their reactions to the post. When whispers are enabled on a site via `whispers_allowed_groups` and reactions are made on whispers on public topics, the contents of the whisper and the reaction data are shown on the `/u/:username/activity/reactions` endpoint. | |
| Analizada | Media (5.3) | 0.26% | — | Kyivstar React Native SMS User Consent | 7/4/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in kyivstarteam react-native-sms-user-consent up to 1.1.4 on Android. Affected by this issue is the function registerReceiver of the file android/src/main/java/ua/kyivstar/reactnativesmsuserconsent/SmsUserConsentModule.kt. The manipulation leads to… | |
| Analizada | Media (6.5) | 0.57% | — | Saleor React-storefront | 20/3/2024 | 17/6/2026 | Saleor Storefront is software for building e-commerce experiences. Prior to commit 579241e75a5eb332ccf26e0bcdd54befa33f4783, when any user authenticates in the storefront, anonymous users are able to access their data. The session is leaked through cache and can be accessed by anyone. Users should upgrade to a version… | |
| Analizada | Alta (7.8) | 0.53% | — | React-native-documents Document Picker | 16/2/2024 | 17/6/2026 | Directory Traversal vulnerability in React Native Document Picker before v.9.1.1 and fixed in v.9.1.1 allows a local attacker to execute arbitrary code via a crafted script to the Android library component. | |
| Modificada | Media (6.1) | 0.39% | — | Tanstack React-query-next-experimental | 30/1/2024 | 17/6/2026 | TanStack Query supplies asynchronous state management, server-state utilities and data fetching for the web. The `@tanstack/react-query-next-experimental` NPM package is vulnerable to a cross-site scripting vulnerability. To exploit this, an attacker would need to either inject malicious input or arrange to have… | |
| Modificada | Alta (8.2) | 0.46% | — | Flatlogic React Dashboard | 30/1/2024 | 17/6/2026 | react-dashboard 1.4.0 is vulnerable to Cross Site Scripting (XSS) as httpOnly is not set. | |
| Modificada | Baja (3.5) | 0.31% | — | Discourse Reactions | 12/1/2024 | 17/6/2026 | Discourse-reactions is a plugin that allows user to add their reactions to the post. Data about a user's reaction notifications could be exposed. This vulnerability was patched in commit 2c26939. | |
| Modificada | Media (4.9) | 0.38% | — | Mrousavy React-native-mmkv | 9/1/2024 | 17/6/2026 | react-native-mmkv is a library that allows easy use of MMKV inside React Native applications. Before version 2.11.0, the react-native-mmkv logged the optional encryption key for the MMKV database into the Android system log. The key can be obtained by anyone with access to the Android Debugging Bridge (ADB) if it is… | |
| Modificada | Alta (7.5) | 0.91% | — | Broadcom Reactor Netty | 28/11/2023 | 4/9/2026 | In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable if Reactor Netty HTTP Server built-in integration with… |