Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 1.2% | — | Vercel Next.js | 14/5/2024 | 17/6/2026 | Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsistent interpretation of a crafted HTTP request meant that requests are treated as both a single request, and two separate requests by Next.js, leading to desynchronized responses. This led to a response… | |
| Modificada | Alta (7.8) | 0.23% | — | Vercel PKG | 9/2/2024 | 17/6/2026 | pkg is tool design to bundle Node.js projects into an executables. Any native code packages built by `pkg` are written to a hardcoded directory. On unix systems, this is `/tmp/pkg/*` which is a shared directory for all users on the same local system. There is no uniqueness to the package names within this directory,… | |
| Modificada | Crítica (9.8) | 1.6% | 💥 PoC | Vercel Hyper | 28/1/2024 | 17/6/2026 | An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings. | |
| Modificada | Alta (7.5) | 1.3% | — | Vercel Next.js | 22/10/2023 | 17/6/2026 | Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a denial of service to all users requesting the same URL via that CDN. | |
| Modificada | Media (5.3) | 0.99% | — | Vercel MS | 5/1/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in vercel ms up to 1.x. This issue affects the function parse of the file index.js. The manipulation of the argument str leads to inefficient regular expression complexity. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Media (5.3) | 1.2% | — | Vercel Next.js | 31/8/2022 | 17/6/2026 | Next.js is a React framework that can provide building blocks to create web applications. All of the following must be true to be affected by this CVE: Next.js version 12.2.3, Node.js version above v15.0.0 being used with strict `unhandledRejection` exiting AND using next start or a [custom… | |
| Modificada | Alta (7.5) | 1.8% | — | Vercel Next.js | 17/2/2022 | 17/6/2026 | Next.js is a React framework. Starting with version 10.0.0 and prior to version 12.1.0, Next.js is vulnerable to User Interface (UI) Misrepresentation of Critical Information. In order to be affected, the `next.config.js` file must have an `images.domains` array assigned and the image host assigned in `images.domains`… | |
| Modificada | Alta (7.5) | 2.2% | — | Vercel Next.js | 28/1/2022 | 17/6/2026 | Next.js is a React framework. Starting with version 12.0.0 and prior to version 12.0.9, vulnerable code could allow a bad actor to trigger a denial of service attack for anyone using i18n functionality. In order to be affected by this CVE, one must use next start or a custom server and the built-in i18n support.… | |
| Modificada | Alta (7.5) | 47% | — | Vercel Next.js | 10/12/2021 | 17/6/2026 | Next.js is a React framework. In versions of Next.js prior to 12.0.5 or 11.1.3, invalid or malformed URLs could lead to a server crash. In order to be affected by this issue, the deployment must use Next.js versions above 11.1.0 and below 12.0.5, Node.js above 15.0.0, and next start or a custom server. Deployments on… | |
| Modificada | Media (6.1) | 1.1% | — | Vercel Next.js | 31/8/2021 | 17/6/2026 | Next.js is a React framework. Versions of Next.js between 10.0.0 and 11.0.0 contain a cross-site scripting vulnerability. In order for an instance to be affected by the vulnerability, the `next.config.js` file must have `images.domains` array assigned and the image host assigned in `images.domains` must allow… | |
| Modificada | Media (6.1) | 1.0% | — | Vercel Next.js | 12/8/2021 | 17/6/2026 | Next.js is an open source website development framework to be used with the React library. In affected versions specially encoded paths could be used when pages/_error.js was statically generated allowing an open redirect to occur to an external site. In general, this redirect does not directly harm users although can… | |
| Modificada | Media (6.1) | 0.77% | — | Vercel Next.js | 8/10/2020 | 17/6/2026 | Next.js versions >=9.5.0 and <9.5.4 are vulnerable to an Open Redirect. Specially encoded paths could be used with the trailing slash redirect to allow an open redirect to occur to an external site. In general, this redirect does not directly harm users although can allow for phishing attacks by redirecting to an… | |
| Modificada | Alta (7.5) | 6.8% | — | Vercel MS | 23/1/2017 | 17/6/2026 | The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)." |