Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
150 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.73% | — | Cesanta MJS | 27/1/2022 | 17/6/2026 | Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via mjs_array_length at src/mjs_array.c. | |
| Modificada | Alta (7.8) | 0.73% | — | Cesanta MJS | 27/1/2022 | 17/6/2026 | Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via mjs_disown at src/mjs_core.c. | |
| Modificada | Media (5.5) | 0.61% | — | Cesanta MJS | 27/1/2022 | 17/6/2026 | There is an Assertion `mjs_stack_size(&mjs->scopes) > 0' failed at src/mjs_exec.c in Cesanta MJS v2.20.0. | |
| Modificada | Media (5.5) | 0.61% | — | Cesanta MJS | 27/1/2022 | 17/6/2026 | Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_stack_size at mjs/src/mjs_core.c. This vulnerability can lead to a Denial of Service (DoS). | |
| Modificada | Media (5.5) | 0.61% | — | Cesanta MJS | 27/1/2022 | 17/6/2026 | There is an Assertion `mjs_stack_size(&mjs->scopes) >= scopes_len' failed at src/mjs_exec.c in Cesanta MJS v2.20.0. | |
| Modificada | Media (5.5) | 0.61% | — | Cesanta MJS | 27/1/2022 | 17/6/2026 | There is an Assertion 'ppos != NULL && mjs_is_number(*ppos)' failed at src/mjs_core.c in Cesanta MJS v2.20.0. | |
| Modificada | Alta (7.8) | 0.74% | — | Cesanta MJS | 27/1/2022 | 17/6/2026 | Cesanta MJS v2.20.0 was discovered to contain a global buffer overflow via mjs_mk_string at mjs/src/mjs_string.c. | |
| Modificada | Media (5.5) | 0.61% | — | Cesanta MJS | 27/1/2022 | 17/6/2026 | Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_apply at src/mjs_exec.c. This vulnerability can lead to a Denial of Service (DoS). | |
| Modificada | Media (5.5) | 0.61% | — | Cesanta MJS | 27/1/2022 | 17/6/2026 | There is an Assertion `m->len >= sizeof(v)' failed at src/mjs_core.c in Cesanta MJS v2.20.0. | |
| Modificada | Media (5.5) | 0.61% | — | Cesanta MJS | 27/1/2022 | 17/6/2026 | There is an Assertion `s < mjs->owned_strings.buf + mjs->owned_strings.len' failed at src/mjs_gc.c in Cesanta MJS v2.20.0. | |
| Modificada | Alta (7.8) | 0.74% | — | Cesanta MJS | 27/1/2022 | 17/6/2026 | Cesanta MJS v2.20.0 was discovered to contain a stack overflow via snquote at mjs/src/mjs_json.c. | |
| Modificada | Media (5.5) | 0.61% | — | Cesanta MJS | 27/1/2022 | 17/6/2026 | There is an Assertion `i < parts_cnt' failed at src/mjs_bcode.c in Cesanta MJS v2.20.0. | |
| Modificada | Media (5.5) | 0.82% | — | Cesanta MJS | 28/5/2021 | 17/6/2026 | Stack overflow vulnerability in parse_equality Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file. | |
| Modificada | Media (5.5) | 0.82% | — | Cesanta MJS | 28/5/2021 | 17/6/2026 | Stack overflow vulnerability in parse_comparison Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file. | |
| Modificada | Media (5.5) | 0.82% | — | Cesanta MJS | 28/5/2021 | 17/6/2026 | Stack overflow vulnerability in parse_shifts Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file. | |
| Modificada | Media (5.5) | 0.82% | — | Cesanta MJS | 28/5/2021 | 17/6/2026 | Stack overflow vulnerability in parse_plus_minus Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file. | |
| Modificada | Media (5.5) | 0.82% | — | Cesanta MJS | 28/5/2021 | 17/6/2026 | Stack overflow vulnerability in parse_mul_div_rem Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file. | |
| Modificada | Media (5.5) | 0.82% | — | Cesanta MJS | 28/5/2021 | 17/6/2026 | Stack overflow vulnerability in parse_unary Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file. | |
| Modificada | Media (5.5) | 0.82% | — | Cesanta MJS | 28/5/2021 | 17/6/2026 | Stack overflow vulnerability in parse_statement_list Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file. | |
| Modificada | Media (5.5) | 0.82% | — | Cesanta MJS | 28/5/2021 | 17/6/2026 | Stack overflow vulnerability in parse_statement Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file. | |
| Modificada | Media (5.5) | 0.82% | — | Cesanta MJS | 28/5/2021 | 17/6/2026 | Stack overflow vulnerability in parse_block Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file. | |
| Modificada | Media (5.5) | 0.82% | — | Cesanta MJS | 28/5/2021 | 17/6/2026 | Stack overflow vulnerability in parse_value Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file. | |
| Modificada | Media (5.5) | 0.94% | — | Cesanta MJS | 28/5/2021 | 17/6/2026 | Stack overflow vulnerability in parse_array Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file. | |
| Modificada | Crítica (9.8) | 2.2% | — | Cesanta Mongooseos MJS | 29/4/2021 | 17/6/2026 | In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_json_parse, which can potentially lead to redirection of control flow. NOTE: the original reporter disputes the significance of this finding because "there isn’t very much of an… | |
| Modificada | Crítica (9.1) | 1.5% | — | Cesanta Mongoose | 8/2/2021 | 17/6/2026 | The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 (compiled with OpenSSL support) is vulnerable to remote OOB write attack via connection request after exhausting memory pool. |