Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
265 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.88% | — | Richardrodger Jsonic | 1/7/2024 | 17/6/2026 | rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. | |
| Aplazada | Alta (7.5) | 0.43% | — | Datadog Dd-trace-cppAINlohmann JsonAI | 28/6/2024 | 17/6/2026 | dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malformed unicode, it logs the list of audited headers and their values using the `nlohmann` JSON library. However, due to the way the JSON library is invoked, it throws an uncaught exception, which results… | |
| Aplazada | Media (6.3) | 0.42% | — | Flatten-jsonAI | 17/6/2024 | 17/6/2026 | A Prototype Pollution issue in flatten-json 1.0.1 allows an attacker to execute arbitrary code via module.exports.unflattenJSON (flatten-json/index.js:42) | |
| Aplazada | Alta (8.1) | 0.80% | — | Json-schema-ref-parserAI | 20/5/2024 | 17/6/2026 | A Prototype Pollution issue in API Dev Tools json-schema-ref-parser v.11.0.0 and v.11.1.0 allows a remote attacker to execute arbitrary code via the bundle()`, `parse()`, `resolve()`, `dereference() functions. | |
| Analizada | Alta (7.6) | 0.65% | — | Cjson Project Cjson | 26/4/2024 | 17/6/2026 | cJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of function cJSON_SetValuestring at cJSON.c. | |
| Aplazada | Alta (7.8) | 0.37% | — | Flowpaper Pdf2jsonAI | 22/4/2024 | 9/7/2026 | A buffer overflow vulnerability in pdf2json v0.70 allows a local attacker to execute arbitrary code via the GString::copy() and ImgOutputDev::ImgOutputDev function. | |
| Analizada | Crítica (9.8) | 1.4% | — | Jsonata | 6/3/2024 | 17/6/2026 | JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the transform operator to override properties on the `Object` constructor and prototype. This may lead to denial of service, remote code execution or other unexpected… | |
| Modificada | Alta (8.6) | 1.8% | — | Ibireme YyjsonFedoraproject Fedora | 29/2/2024 | 17/6/2026 | yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part of the pool series allocator, along with pool_malloc and pool_realloc.) | |
| Analizada | Alta (8.4) | 0.23% | — | Json-jwt Project Json-jwt | 29/2/2024 | 17/6/2026 | The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. | |
| Analizada | Alta (7.5) | 1.2% | — | IJL Orjson | 26/2/2024 | 17/6/2026 | orjson.loads in orjson before 3.9.15 does not limit recursion for deeply nested JSON documents. | |
| Analizada | Alta (8) | 0.77% | — | Grafana Json API Data Source | 14/2/2024 | 17/6/2026 | The JSON datasource plugin ( https://grafana.com/grafana/plugins/marcusolsson-json-datasource/ ) is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing JSON data from a remote endpoint (including a specific sub-path) configured by an administrator. Due to inadequate sanitization of… | |
| Modificada | Alta (7.5) | 33% | — | Newtonsoft Json.net | 3/1/2024 | 14/7/2026 | Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote… | |
| Analizada | Media (5.3) | 0.68% | — | Json-path Jayway Jsonpath | 27/12/2023 | 17/6/2026 | json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method. | |
| Modificada | Media (6.1) | 0.42% | — | Json-content-importer Json Content Importer | 26/12/2023 | 17/6/2026 | The JSON Content Importer WordPress plugin before 1.5.4 does not sanitise and escape the tab parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Alta (7.5) | 0.97% | — | Davegamble Cjson | 14/12/2023 | 17/6/2026 | cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c. | |
| Modificada | Alta (7.5) | 1.5% | — | Davegamble Cjson | 14/12/2023 | 17/6/2026 | cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c. | |
| Modificada | Media (4.3) | 0.35% | — | Jenkins Dingding Json Pusher | 13/12/2023 | 17/6/2026 | Jenkins Dingding JSON Pusher Plugin 2.0 and earlier does not mask access tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them. | |
| Modificada | Media (4.3) | 0.35% | — | Jenkins Dingding Json Pusher | 13/12/2023 | 17/6/2026 | Jenkins Dingding JSON Pusher Plugin 2.0 and earlier stores access tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. | |
| Modificada | Alta (7.5) | 0.31% | — | Joaquimserafim Json WEB Token | 17/11/2023 | 17/6/2026 | joaquimserafim/json-web-token is a javascript library use to interact with JSON Web Tokens (JWT) which are a compact URL-safe means of representing claims to be transferred between two parties. Versions prior to 4.0.0 are vulnerable to a JWT algorithm confusion attack. On line 86 of the 'index.js' file, the algorithm… | |
| Modificada | Alta (7.5) | 1.4% | — | Stleary Json-java | 12/10/2023 | 17/6/2026 | Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used. | |
| Modificada | Alta (8.8) | 0.26% | — | Nikunjsoni Easy WP Cleaner | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nikunj Soni Easy WP Cleaner plugin <= 1.9 versions. | |
| Modificada | Alta (7.5) | 0.89% | — | Hjson | 1/9/2023 | 17/6/2026 | An issue in hjson-java up to v3.0.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted JSON string. | |
| Modificada | Alta (7.5) | 1.3% | — | Vinitkumar Json2xml | 22/8/2023 | 17/6/2026 | The json2xml package through 3.12.0 for Python allows an error in typecode decoding enabling a remote attack that can lead to an exception, causing a denial of service. | |
| Analizada | Crítica (9.8) | 1.3% | — | Netapp Active IQ Unified ManagerJson-c | 22/8/2023 | 17/6/2026 | An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit. | |
| Modificada | Alta (7.5) | 0.77% | — | Jjson Project Jjson | 14/6/2023 | 17/6/2026 | An issue was discovered jjson thru 0.1.7 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies. |