Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

123 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.9%—Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+3719/2/202117/6/2026
Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3…
ModificadaMedia (4.3)0.73%—Socket.io19/1/202117/6/2026
The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.
ModificadaAlta (7.5)2.7%—Socket.io-parser8/1/202117/6/2026
socket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a concatenation approach is used.
ModificadaAlta (7.5)3.3%—Socket Engine.io8/1/202117/6/2026
Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.
ModificadaMedia (5.5)0.40%—Rust-lang Socket231/12/202017/6/2026
An issue was discovered in the socket2 crate before 0.3.16 for Rust. It has false expectations about the std::net::SocketAddr memory representation.
ModificadaCrítica (9.8)3.2%—Valvesoftware Game Networking Sockets3/12/202017/6/2026
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegment() when configured to support plain-text messages, leading to a Heap-Based Buffer Overflow and resulting in a memory corruption and possibly even a remote code execution.
ModificadaCrítica (9.8)3.2%—Valvesoftware Game Networking Sockets2/12/202017/6/2026
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_DecryptContext::Decrypt() when compiled using libsodium, leading to a Stack-Based Buffer Overflow and resulting in a memory corruption and possibly even a remote code execution.
ModificadaAlta (7.5)2.1%—Gorillatoolkit WebsocketDebian Linux2/12/202017/6/2026
An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.
ModificadaCrítica (9.8)6.0%—Valvesoftware Game Networking Sockets18/11/202017/6/2026
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in function SNP_ReceiveUnreliableSegment(), leading to a Heap-Based Buffer Underflow and a free() of memory not from the heap, resulting in a memory corruption and probably even a remote code execution.
ModificadaAlta (7.5)2.8%—Valvesoftware Game Networking Sockets13/11/202017/6/2026
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function CConnectionTransportUDPBase::Received_Data(), leading to an exception thrown from libprotobuf and resulting in a crash.
ModificadaAlta (7.8)2.1%—Socket.io-file Project Socket.io-file6/10/202017/6/2026
The socket.io-file package through 2.0.31 for Node.js relies on client-side validation of file types, which allows remote attackers to execute arbitrary code by uploading an executable file via a modified JSON name field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
ModificadaAlta (8.7)1.1%—Faye-websocket Project Faye-websocket31/7/202017/6/2026
In faye-websocket before version 0.11.0, there is a lack of certification validation in TLS handshakes. The `Faye::WebSocket::Client` class uses the `EM::Connection#start_tls` method in EventMachine to implement the TLS handshake whenever a `wss:` URL is used for the connection. This method does not implement…
ModificadaAlta (7.5)1.6%—Socket.io-file Project Socket.io-file15/7/202017/6/2026
A Path Traversal issue was discovered in the socket.io-file package through 2.0.31 for Node.js. The socket.io-file::createFile message uses path.join with ../ in the name option, and the uploadDir and rename options determine the path.
ModificadaAlta (7.5)4.5%—Websocket-extensions Project Websocket-extensionsDebian LinuxCanonical Ubuntu Linux2/6/202017/6/2026
websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be…
ModificadaAlta (7.5)3.0%—Websocket-extensions Project Websocket-extensions2/6/202017/6/2026
websocket-extensions npm module prior to 0.1.4 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be…
ModificadaAlta (8.1)0.79%—Java-websocket Project Java-websocket7/5/202017/6/2026
In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0.
ModificadaAlta (7.5)1.8%—Websockets Project Websockets26/6/201817/6/2026
aaugustin websockets version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clients, unless configured with compression=None that can result in Denial of Service by memory exhaustion. This attack appear to be exploitable via Sending a specially…
ModificadaAlta (7.5)2.0%—Pooledwebsocket Project Pooledwebsocket7/6/201817/6/2026
pooledwebsocket is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaAlta (7.5)2.0%—Socket.io4/6/201817/6/2026
Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on `Math.random()` to create socket IDs, the IDs are predictable. An attacker is able to guess the socket ID and gain access to socket.io servers, potentially obtaining sensitive…
ModificadaAlta (8.1)1.8%—Marionette-socket-host Project Marionette-socket-host4/6/201817/6/2026
marionette-socket-host is a marionette-js-runner host for sending actions over a socket. marionette-socket-host downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled…
ModificadaMedia (5.9)1.0%—Socket Engine.io-client31/5/201817/6/2026
engine.io-client is the client for engine.io, the implementation of a transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. The vulnerability is related to the way that node.js handles the `rejectUnauthorized` setting. If the value is something that evaluates to false,…
ModificadaAlta (7.5)1.9%—Kaazing GatewayTenefit Kaazing Websocket Gateway12/4/201817/6/2026
The HTTP and WebSocket engine components in the server in Kaazing Gateway before 4.5.3 hotfix-1, Gateway - JMS Edition before 4.0.5 hotfix-15, 4.0.6 before hotfix-4, 4.0.7, 4.0.9 before hotfix-19, 4.4.x before 4.4.2 hotfix-1, 4.5.x before 4.5.3 hotfix-1, and Gateway Community and Enterprise Editions before 5.6.0 allow…
ModificadaAlta (7.5)1.5%—Tenefit Kaazing Websocket Gateway12/4/201817/6/2026
The HTTP and WebSocket engine components in the server in Kaazing Gateway 4.0.2, 4.0.3, and 4.0.4 and Gateway - JMS Edition 4.0.2, 4.0.3, and 4.0.4 allow remote attackers to obtain sensitive information via vectors related to HTTP request handling.
ModificadaMedia (5.9)0.66%—Nv-websocket-client Project Nv-websocket-client17/11/201717/6/2026
The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL/TLS servers via an arbitrary valid certificate.
ModificadaMedia (5.3)3.5%—Microsoft Asp.net Model View ControllerMicrosoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorerMicrosoft.aspnetcore.mvc.cors+1412/5/201717/6/2026
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.