Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
123 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.9% | — | Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+37 | 19/2/2021 | 17/6/2026 | Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3… | |
| Modificada | Media (4.3) | 0.73% | — | Socket.io | 19/1/2021 | 17/6/2026 | The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default. | |
| Modificada | Alta (7.5) | 2.7% | — | Socket.io-parser | 8/1/2021 | 17/6/2026 | socket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a concatenation approach is used. | |
| Modificada | Alta (7.5) | 3.3% | — | Socket Engine.io | 8/1/2021 | 17/6/2026 | Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport. | |
| Modificada | Media (5.5) | 0.40% | — | Rust-lang Socket2 | 31/12/2020 | 17/6/2026 | An issue was discovered in the socket2 crate before 0.3.16 for Rust. It has false expectations about the std::net::SocketAddr memory representation. | |
| Modificada | Crítica (9.8) | 3.2% | — | Valvesoftware Game Networking Sockets | 3/12/2020 | 17/6/2026 | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegment() when configured to support plain-text messages, leading to a Heap-Based Buffer Overflow and resulting in a memory corruption and possibly even a remote code execution. | |
| Modificada | Crítica (9.8) | 3.2% | — | Valvesoftware Game Networking Sockets | 2/12/2020 | 17/6/2026 | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_DecryptContext::Decrypt() when compiled using libsodium, leading to a Stack-Based Buffer Overflow and resulting in a memory corruption and possibly even a remote code execution. | |
| Modificada | Alta (7.5) | 2.1% | — | Gorillatoolkit WebsocketDebian Linux | 2/12/2020 | 17/6/2026 | An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections. | |
| Modificada | Crítica (9.8) | 6.0% | — | Valvesoftware Game Networking Sockets | 18/11/2020 | 17/6/2026 | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in function SNP_ReceiveUnreliableSegment(), leading to a Heap-Based Buffer Underflow and a free() of memory not from the heap, resulting in a memory corruption and probably even a remote code execution. | |
| Modificada | Alta (7.5) | 2.8% | — | Valvesoftware Game Networking Sockets | 13/11/2020 | 17/6/2026 | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function CConnectionTransportUDPBase::Received_Data(), leading to an exception thrown from libprotobuf and resulting in a crash. | |
| Modificada | Alta (7.8) | 2.1% | — | Socket.io-file Project Socket.io-file | 6/10/2020 | 17/6/2026 | The socket.io-file package through 2.0.31 for Node.js relies on client-side validation of file types, which allows remote attackers to execute arbitrary code by uploading an executable file via a modified JSON name field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Alta (8.7) | 1.1% | — | Faye-websocket Project Faye-websocket | 31/7/2020 | 17/6/2026 | In faye-websocket before version 0.11.0, there is a lack of certification validation in TLS handshakes. The `Faye::WebSocket::Client` class uses the `EM::Connection#start_tls` method in EventMachine to implement the TLS handshake whenever a `wss:` URL is used for the connection. This method does not implement… | |
| Modificada | Alta (7.5) | 1.6% | — | Socket.io-file Project Socket.io-file | 15/7/2020 | 17/6/2026 | A Path Traversal issue was discovered in the socket.io-file package through 2.0.31 for Node.js. The socket.io-file::createFile message uses path.join with ../ in the name option, and the uploadDir and rename options determine the path. | |
| Modificada | Alta (7.5) | 4.5% | — | Websocket-extensions Project Websocket-extensionsDebian LinuxCanonical Ubuntu Linux | 2/6/2020 | 17/6/2026 | websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be… | |
| Modificada | Alta (7.5) | 3.0% | — | Websocket-extensions Project Websocket-extensions | 2/6/2020 | 17/6/2026 | websocket-extensions npm module prior to 0.1.4 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be… | |
| Modificada | Alta (8.1) | 0.79% | — | Java-websocket Project Java-websocket | 7/5/2020 | 17/6/2026 | In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0. | |
| Modificada | Alta (7.5) | 1.8% | — | Websockets Project Websockets | 26/6/2018 | 17/6/2026 | aaugustin websockets version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clients, unless configured with compression=None that can result in Denial of Service by memory exhaustion. This attack appear to be exploitable via Sending a specially… | |
| Modificada | Alta (7.5) | 2.0% | — | Pooledwebsocket Project Pooledwebsocket | 7/6/2018 | 17/6/2026 | pooledwebsocket is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Alta (7.5) | 2.0% | — | Socket.io | 4/6/2018 | 17/6/2026 | Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on `Math.random()` to create socket IDs, the IDs are predictable. An attacker is able to guess the socket ID and gain access to socket.io servers, potentially obtaining sensitive… | |
| Modificada | Alta (8.1) | 1.8% | — | Marionette-socket-host Project Marionette-socket-host | 4/6/2018 | 17/6/2026 | marionette-socket-host is a marionette-js-runner host for sending actions over a socket. marionette-socket-host downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled… | |
| Modificada | Media (5.9) | 1.0% | — | Socket Engine.io-client | 31/5/2018 | 17/6/2026 | engine.io-client is the client for engine.io, the implementation of a transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. The vulnerability is related to the way that node.js handles the `rejectUnauthorized` setting. If the value is something that evaluates to false,… | |
| Modificada | Alta (7.5) | 1.9% | — | Kaazing GatewayTenefit Kaazing Websocket Gateway | 12/4/2018 | 17/6/2026 | The HTTP and WebSocket engine components in the server in Kaazing Gateway before 4.5.3 hotfix-1, Gateway - JMS Edition before 4.0.5 hotfix-15, 4.0.6 before hotfix-4, 4.0.7, 4.0.9 before hotfix-19, 4.4.x before 4.4.2 hotfix-1, 4.5.x before 4.5.3 hotfix-1, and Gateway Community and Enterprise Editions before 5.6.0 allow… | |
| Modificada | Alta (7.5) | 1.5% | — | Tenefit Kaazing Websocket Gateway | 12/4/2018 | 17/6/2026 | The HTTP and WebSocket engine components in the server in Kaazing Gateway 4.0.2, 4.0.3, and 4.0.4 and Gateway - JMS Edition 4.0.2, 4.0.3, and 4.0.4 allow remote attackers to obtain sensitive information via vectors related to HTTP request handling. | |
| Modificada | Media (5.9) | 0.66% | — | Nv-websocket-client Project Nv-websocket-client | 17/11/2017 | 17/6/2026 | The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL/TLS servers via an arbitrary valid certificate. | |
| Modificada | Media (5.3) | 3.5% | — | Microsoft Asp.net Model View ControllerMicrosoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorerMicrosoft.aspnetcore.mvc.cors+14 | 12/5/2017 | 17/6/2026 | A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. |