Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2557▼ 320 respecto a la semana anterior
Críticas / altas1342▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
151 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Broadcom Reactor Netty | 15/11/2023 | 4/9/2026 | In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack. Specifically, an application is vulnerable if Reactor Netty HTTP Server is configured to serve static… | |
| Modificada | Alta (8.8) | 0.32% | — | Wpreactions WP Reactions Lite | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Reactions, LLC WP Reactions Lite plugin <= 1.3.8 versions. | |
| Modificada | Media (6.5) | 0.47% | — | Facebook React-devtools | 19/10/2023 | 17/6/2026 | The React Developer Tools extension registers a message listener with window.addEventListener('message', <listener>) in a content script that is accessible to any webpage that is active in the browser. Within the listener is code that requests a URL derived from the received message via fetch(). The URL is not… | |
| Modificada | Media (5.4) | 0.45% | — | Matrix-react-sdk Project Matrix-react-sdk | 18/7/2023 | 17/6/2026 | matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. The Export Chat feature includes certain attacker-controlled elements in the generated document without sufficient escaping, leading to stored Cross site scripting (XSS). Since the Export Chat feature generates a separate… | |
| Modificada | Media (4.3) | 0.56% | — | Vuukle Comments, Reactions, Share Bar, Revenue | 12/7/2023 | 17/6/2026 | The Vuukle Comments, Reactions, Share Bar, Revenue plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.31. This is due to missing or incorrect nonce validation in the /admin/partials/free-comments-for-wordpress-vuukle-admin-display.php file. This makes it possible for… | |
| Modificada | Media (6.1) | 0.46% | — | Saleor React-storefront | 16/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - DOM in GitHub repository saleor/react-storefront prior to c29aab226f07ca980cc19787dcef101e11b83ef7. | |
| Modificada | Media (5.3) | 0.68% | — | Reactphp Http | 17/5/2023 | 17/6/2026 | react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. Previous versions of ReactPHP's HTTP server component contain a potential DoS vulnerability that can cause high CPU load when processing large HTTP request bodies. This vulnerability has little to no impact on the default… | |
| Modificada | Media (4.7) | 0.62% | — | Matrix-react-sdk Project Matrix-react-sdk | 25/4/2023 | 17/6/2026 | matrix-react-sdk is a react-based SDK for inserting a Matrix chat/VoIP client into a web page. Prior to version 3.71.0, plain text messages containing HTML tags are rendered as HTML in the search results. To exploit this, an attacker needs to trick a user into searching for a specific message containing an HTML… | |
| Modificada | Alta (8.8) | 0.27% | — | Areteit Activity Reactions FOR Buddypress | 23/4/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Paramveer Singh for Arete IT Private Limited Activity Reactions For Buddypress plugin <= 1.0.22 versions. | |
| Modificada | Media (5.3) | 0.43% | — | Discourse Reactions | 19/4/2023 | 17/6/2026 | Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform. In affected versions data about what reactions were performed on a post in a private topic could be leaked. This issue has been addressed in version 0.3. Users are advised to upgrade. Users unable… | |
| Modificada | Media (5.7) | 0.38% | — | Uniswap Web3-react Coinbase-walletUniswap Web3-react Eip1193Uniswap Web3-react MetamaskUniswap Web3-react Walletconnect | 17/4/2023 | 17/6/2026 | @web3-react is a framework for building Ethereum Apps . In affected versions the `chainId` may be outdated if the user changes chains as part of the connection flow. This means that the value of `chainId` returned by `useWeb3React()` may be incorrect. In an application, this means that any data derived from `chainId`… | |
| Modificada | Alta (8.2) | 0.71% | — | Matrix-react-sdk Project Matrix-react-sdk | 28/3/2023 | 17/6/2026 | matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. In certain configurations, data sent by remote servers containing special strings in key locations could cause modifications of the `Object.prototype`, disrupting matrix-react-sdk functionality, causing denial of service and potentially affecting… | |
| Modificada | Media (5.3) | 0.91% | — | Matrix React SDK | 28/3/2023 | 17/6/2026 | matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. Events sent with special strings in key places can temporarily disrupt or impede the matrix-react-sdk from functioning properly, such as by causing room or event tile crashes. The remainder of the application can appear functional, though certain… | |
| Modificada | Alta (8.1) | 0.91% | — | React-native-onesignal | 27/3/2023 | 17/6/2026 | OneSignal is an email, sms, push notification, and in-app message service for mobile apps.The Zapier.yml workflow is triggered on issues (types: [closed]) (i.e., when an Issue is closed). The workflow starts with full write-permissions GitHub repository token since the default workflow permissions on… | |
| Modificada | Media (5.4) | 0.47% | — | React Webcam Project React Webcam | 20/3/2023 | 17/6/2026 | The React Webcam WordPress plugin through 1.2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.69% | — | Marmelab Ra-ui-materialuiMarmelab React-admin | 13/2/2023 | 17/6/2026 | react-admin is a frontend framework for building browser applications on top of REST/GraphQL APIs. react-admin prior to versions 3.19.12 and 4.7.6, along with ra-ui-materialui prior to 3.19.12 and 4.7.6, are vulnerable to cross-site scripting. All React applications built with react-admin and using the… | |
| Modificada | Media (4.3) | 0.66% | — | Broadcom Reactor Netty | 19/10/2022 | 4/9/2026 | Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid HTTP requests where logging at WARN level is enabled. | |
| Modificada | Alta (7.5) | 1.6% | — | Swmansion React Native Reanimated | 30/9/2022 | 17/6/2026 | The package react-native-reanimated before 3.0.0-rc.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper usage of regular expression in the parser of Colors.js. | |
| Modificada | Media (5.3) | 1.0% | — | Reactphp Http | 6/9/2022 | 17/6/2026 | ReactPHP HTTP is a streaming HTTP client and server implementation for ReactPHP. In ReactPHP's HTTP server component versions starting with 0.7.0 and prior to 1.7.0, when ReactPHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like `__Host-` and… | |
| Modificada | Crítica (9.8) | 1.5% | — | React Editable Json Tree Project React Editable Json Tree | 15/8/2022 | 17/6/2026 | This library allows strings to be parsed as functions and stored as a specialized component, [`JsonFunctionValue`](https://github.com/oxyno-zeta/react-editable-json-tree/blob/09a0ca97835b0834ad054563e2fddc6f22bc5d8c/src/components/JsonFunctionValue.js). To do this, Javascript's… | |
| Modificada | Media (6.1) | 0.69% | — | Amazon Awsui/components-react | 24/2/2022 | 17/6/2026 | @awsui/components-react is the main AWS UI package which contains React components, with TypeScript definitions designed for user interface development. Multiple components in versions before 3.0.367 have been found to not properly neutralize user input and may allow for javascript injection. Users are advised to… | |
| Modificada | Media (5.4) | 0.65% | — | Wpreactions WP Reactions Lite | 1/11/2021 | 17/6/2026 | The WP Reactions Lite WordPress plugin before 1.3.6 does not properly sanitize inputs within wp-admin pages, allowing users with sufficient access to inject XSS payloads within /wp-admin/ pages. | |
| Modificada | Media (5.3) | 0.93% | — | Discourse Reactions | 19/10/2021 | 17/6/2026 | Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post. In affected versions reactions given by user to secure topics and private messages are visible. This issue is patched in version 0.2 of discourse-reaction. Users who are unable to update are advised to… | |
| Modificada | Media (6.1) | 1.3% | — | React-bootstrap-table Project React-bootstrap-table | 24/6/2021 | 17/6/2026 | All versions of package react-bootstrap-table are vulnerable to Cross-site Scripting (XSS) via the dataFormat parameter. The problem is triggered when an invalid React element is returned, leading to dangerouslySetInnerHTML being used, which does not sanitize the output. | |
| Modificada | Alta (7.5) | 1.4% | — | Facebook React-native | 1/6/2021 | 17/6/2026 | A regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cause the application to use excessive resources, become unresponsive, or crash. This was introduced in react-native version 0.59.0 and fixed in version 0.64.1. |