Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

265 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.88%—Richardrodger Jsonic1/7/202417/6/2026
rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
AplazadaAlta (7.5)0.43%—Datadog Dd-trace-cppAINlohmann JsonAI28/6/202417/6/2026
dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malformed unicode, it logs the list of audited headers and their values using the `nlohmann` JSON library. However, due to the way the JSON library is invoked, it throws an uncaught exception, which results…
AplazadaMedia (6.3)0.42%—Flatten-jsonAI17/6/202417/6/2026
A Prototype Pollution issue in flatten-json 1.0.1 allows an attacker to execute arbitrary code via module.exports.unflattenJSON (flatten-json/index.js:42)
AplazadaAlta (8.1)0.80%—Json-schema-ref-parserAI20/5/202417/6/2026
A Prototype Pollution issue in API Dev Tools json-schema-ref-parser v.11.0.0 and v.11.1.0 allows a remote attacker to execute arbitrary code via the bundle()`, `parse()`, `resolve()`, `dereference() functions.
AnalizadaAlta (7.6)0.65%—Cjson Project Cjson26/4/202417/6/2026
cJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of function cJSON_SetValuestring at cJSON.c.
AplazadaAlta (7.8)0.37%—Flowpaper Pdf2jsonAI22/4/20249/7/2026
A buffer overflow vulnerability in pdf2json v0.70 allows a local attacker to execute arbitrary code via the GString::copy() and ImgOutputDev::ImgOutputDev function.
AnalizadaCrítica (9.8)1.4%—Jsonata6/3/202417/6/2026
JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the transform operator to override properties on the `Object` constructor and prototype. This may lead to denial of service, remote code execution or other unexpected…
ModificadaAlta (8.6)1.8%—Ibireme YyjsonFedoraproject Fedora29/2/202417/6/2026
yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part of the pool series allocator, along with pool_malloc and pool_realloc.)
AnalizadaAlta (8.4)0.23%—Json-jwt Project Json-jwt29/2/202417/6/2026
The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode.
AnalizadaAlta (7.5)1.2%—IJL Orjson26/2/202417/6/2026
orjson.loads in orjson before 3.9.15 does not limit recursion for deeply nested JSON documents.
AnalizadaAlta (8)0.77%—Grafana Json API Data Source14/2/202417/6/2026
The JSON datasource plugin ( https://grafana.com/grafana/plugins/marcusolsson-json-datasource/ ) is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing JSON data from a remote endpoint (including a specific sub-path) configured by an administrator. Due to inadequate sanitization of…
ModificadaAlta (7.5)33%—Newtonsoft Json.net3/1/202414/7/2026
Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote…
AnalizadaMedia (5.3)0.68%—Json-path Jayway Jsonpath27/12/202317/6/2026
json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.
ModificadaMedia (6.1)0.42%—Json-content-importer Json Content Importer26/12/202317/6/2026
The JSON Content Importer WordPress plugin before 1.5.4 does not sanitise and escape the tab parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaAlta (7.5)0.97%—Davegamble Cjson14/12/202317/6/2026
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.
ModificadaAlta (7.5)1.5%—Davegamble Cjson14/12/202317/6/2026
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.
ModificadaMedia (4.3)0.35%—Jenkins Dingding Json Pusher13/12/202317/6/2026
Jenkins Dingding JSON Pusher Plugin 2.0 and earlier does not mask access tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
ModificadaMedia (4.3)0.35%—Jenkins Dingding Json Pusher13/12/202317/6/2026
Jenkins Dingding JSON Pusher Plugin 2.0 and earlier stores access tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
ModificadaAlta (7.5)0.31%—Joaquimserafim Json WEB Token17/11/202317/6/2026
joaquimserafim/json-web-token is a javascript library use to interact with JSON Web Tokens (JWT) which are a compact URL-safe means of representing claims to be transferred between two parties. Versions prior to 4.0.0 are vulnerable to a JWT algorithm confusion attack. On line 86 of the 'index.js' file, the algorithm…
ModificadaAlta (7.5)1.4%—Stleary Json-java12/10/202317/6/2026
Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.
ModificadaAlta (8.8)0.26%—Nikunjsoni Easy WP Cleaner10/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Nikunj Soni Easy WP Cleaner plugin <= 1.9 versions.
ModificadaAlta (7.5)0.89%—Hjson1/9/202317/6/2026
An issue in hjson-java up to v3.0.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted JSON string.
ModificadaAlta (7.5)1.3%—Vinitkumar Json2xml22/8/202317/6/2026
The json2xml package through 3.12.0 for Python allows an error in typecode decoding enabling a remote attack that can lead to an exception, causing a denial of service.
AnalizadaCrítica (9.8)1.3%—Netapp Active IQ Unified ManagerJson-c22/8/202317/6/2026
An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit.
ModificadaAlta (7.5)0.77%—Jjson Project Jjson14/6/202317/6/2026
An issue was discovered jjson thru 0.1.7 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.