Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

265 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.78%—Hjson Project Hjson14/6/202317/6/2026
An issue was discovered hjson thru 3.0.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
ModificadaAlta (7.5)0.73%—Pbjson Project Pbjson14/6/202317/6/2026
An issue was discovered pbjson thru 0.4.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
ModificadaAlta (7.5)0.73%—Pwall Jsonutil14/6/202317/6/2026
An issue was discovered JSONUtil thru 5.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
ModificadaAlta (7.5)0.84%—Jsonij Project Jsonij14/6/202317/6/2026
An issue was discovered jmarsden/jsonij thru 0.5.2 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
ModificadaAlta (7.5)0.77%—Ph-json Project Ph-json14/6/202317/6/2026
An issue was discovered ph-json thru 9.5.5 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
ModificadaAlta (7.5)0.74%—Mjson Project Mjson14/6/202317/6/2026
An issue was discovered mjson thru 1.4.1 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
ModificadaAlta (7.5)0.81%—Json-io Project Json-io14/6/202317/6/2026
An issue was discovered json-io thru 4.14.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
ModificadaAlta (7.5)1.2%—Flexjson Project Flexjson14/6/202317/6/2026
An issue was discovered flexjson thru 3.3 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
ModificadaAlta (7.5)0.71%—Cloudflare Lua-resty-json14/6/202317/6/2026
A debug function in the lua-resty-json package, up to commit id 3ef9492bd3a44d9e51301d6adc3cd1789c8f534a (merged in PR #14) contained an out of bounds access bug that could have allowed an attacker to launch a DoS if the function was used to parse untrusted input data. It is important to note that because this debug…
ModificadaCrítica (9.8)2.2%—Apache Sling Commons Json15/5/202317/6/2026
Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted input. The org.apache.sling.commons.json bundle has been deprecated as of March 2017 and should not be used anymore. Consumers are encouraged to consider the Apache Sling…
ModificadaMedia (4.8)0.37%—Json-content-importer Json Content Importer25/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bernhard Kux JSON Content Importer plugin <= 1.3.15 versions.
ModificadaCrítica (9.8)1.8%—Rails-routes-to-json Project Rails-routes-to-json24/4/202317/6/2026
rails-routes-to-json v1.0.0 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.
ModificadaAlta (7.5)1.1%—Json-smart Project Json-smart22/3/202317/6/2026
[Json-smart](https://netplex.github.io/json-smart/) is a performance focused, JSON processor lib. When reaching a ‘[‘ or ‘{‘ character in the JSON input, the code parses an array or an object respectively. It was discovered that the code does not have any limit to the nesting of such arrays or objects. Since the…
ModificadaCrítica (9.8)2.2%—Json-logic-js Project Json-logic-js5/3/202317/6/2026
A vulnerability, which was classified as critical, has been found in json-logic-js 2.0.0. Affected by this issue is some unknown functionality of the file logic.js. The manipulation leads to command injection. Upgrading to version 2.0.1 is able to address this issue. The patch is identified as…
ModificadaMedia (5.4)0.47%—Terakoya Markup (json-ld) Structured IN Schema.org21/2/202317/6/2026
The Markup (JSON-LD) structured in schema.org WordPress plugin through 4.8.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaAlta (7.8)0.56%—Json.h Project Json.h3/2/202317/6/2026
Buffer overflow vulnerability in function json_parse_string in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc81fdadf41 (November 14, 2022) allows attackers to code arbitrary code and gain escalated privileges.
ModificadaAlta (7.8)0.19%—Json.h Project Json.h3/2/202317/6/2026
Buffer overflow vulnerability in function json_parse_key in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc81fdadf41 (November 14, 2022) allows attackers to code arbitrary code and gain escalated privileges.
ModificadaAlta (7.8)0.21%—Json.h Project Json.h3/2/202317/6/2026
Buffer overflow vulnerability in function json_parse_number in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc81fdadf41 (November 14, 2022) allows attackers to code arbitrary code and gain escalated privileges.
ModificadaAlta (7.8)0.26%—Json.h Project Json.h3/2/202317/6/2026
Buffer overflow vulnerability in function json_parse_value in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc81fdadf41 (November 14, 2022) allows attackers to code arbitrary code and gain escalated privileges.
ModificadaCrítica (9.8)1.00%—Json-parser Project Json-parser3/2/202317/6/2026
Buffer OverFlow Vulnerability in Barenboim json-parser master and v1.1.0 fixed in v1.1.1 allows an attacker to execute arbitrary code via the json_value_parse function.
ModificadaCrítica (9.8)0.86%—Mojojson Project Mojojson3/2/202317/6/2026
An issue was found in MojoJson v1.2.3 allows attackers to execute arbitary code via the destroy function.
ModificadaCrítica (9.8)0.95%—Mojojson Project Mojojson3/2/202317/6/2026
Buffer OverFlow Vulnerability in MojoJson v1.2.3 allows an attacker to execute arbitrary code via the SkipString function.
ModificadaAlta (7.8)0.41%—Json.h Project Json.h31/1/202317/6/2026
Buffer overflow vulnerability in function json_parse_object in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc81fdadf41 (November 14, 2022) allows attackers to code arbitrary code and gain escalated privileges.
ModificadaMedia (6.1)0.53%—Json2html28/12/202217/6/2026
A vulnerability was found in moappi Json2html up to 1.1.x and classified as problematic. This issue affects some unknown processing of the file json2html.js. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 1.2.0 is able to address this issue. The name of the…
ModificadaAlta (7.5)0.75%—Json WEB Token Project Json WEB Token27/12/202217/6/2026
Token validation methods are susceptible to a timing side-channel during HMAC comparison. With a large enough number of requests over a low latency connection, an attacker may use this to determine the expected HMAC.