Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2544▼ 345 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
151 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.37% | — | Matrix-react-sdk Project Matrix-react-sdk | 17/5/2021 | 17/6/2026 | Matrix-React-SDK is a react-based SDK for inserting a Matrix chat/voip client into a web page. Before version 3.21.0, when uploading a file, the local file preview can lead to execution of scripts embedded in the uploaded file. This can only occur after several user interactions to open the preview in a separate tab.… | |
| Modificada | Media (5.4) | 0.79% | — | React Draft Wysiwyg Project React Draft Wysiwyg | 24/4/2021 | 17/6/2026 | react-draft-wysiwyg (aka React Draft Wysiwyg) before 1.14.6 allows a javascript: URi in a Link Target of the link decorator in decorators/Link/index.js when a draft is shared across users, leading to XSS. | |
| Modificada | Media (5.6) | 3.3% | — | Facebook React-dev-utils | 9/3/2021 | 17/6/2026 | react-dev-utils prior to v11.0.4 exposes a function, getProcessForPort, where an input argument is concatenated into a command string to be executed. This function is typically used from react-scripts (in Create React App projects), where the usage is safe. Only when this function is manually invoked with… | |
| Modificada | Media (4.3) | 0.92% | — | Matrix-react-sdk Project Matrix-react-sdk | 2/3/2021 | 17/6/2026 | matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0, the user content sandbox can be abused to trick users into opening unexpected documents. The content is opened with a `blob` origin that cannot access Matrix user data, so messages and secrets are… | |
| Modificada | Alta (8.2) | 1.3% | — | React-adal Project React-adal | 9/12/2020 | 17/6/2026 | This affects all versions of package react-adal. It is possible for a specially crafted JWT token and request URL can cause the nonce, session and refresh values to be incorrectly validated, causing the application to treat an attacker-generated JWT token as authentic. The logical defect is caused by how the nonce,… | |
| Modificada | Media (5.3) | 1.6% | — | React-native-fast-image Project React-native-fast-image | 17/7/2020 | 17/6/2026 | This affects all versions of package react-native-fast-image. When an image with source={{uri: "...", headers: { host: "somehost.com", authorization: "..." }} is loaded, all other subsequent images will use the same headers, this can lead to signing credentials or other session tokens being leaked to other servers. | |
| Modificada | Alta (7.5) | 1.1% | — | Broadcom Reactor Netty | 3/3/2020 | 4/9/2026 | Reactor Netty HttpServer, versions 0.9.3 and 0.9.4, is exposed to a URISyntaxException that causes the connection to be closed prematurely instead of producing a 400 response. | |
| Modificada | Media (5.9) | 0.65% | — | Broadcom Reactor Netty | 3/3/2020 | 4/9/2026 | The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects. | |
| Modificada | Alta (8.6) | 0.89% | — | Broadcom Reactor Netty | 17/10/2019 | 4/9/2026 | Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to. | |
| Modificada | Crítica (9.8) | 4.1% | — | Status React Native Desktop | 23/7/2019 | 17/6/2026 | ubuntu-server.js in Status React Native Desktop before v0.57.8_mobile_ui allows Remote Code Execution. | |
| Modificada | Crítica (9.1) | 2.0% | — | Realobjects Pdfreactor | 11/6/2019 | 17/6/2026 | XXE in the XML parser library in RealObjects PDFreactor before 10.1.10722 allows attackers to supply malicious XML content in externally referenced resources, leading to disclosure of local file contents and/or denial of service conditions. | |
| Modificada | Crítica (10) | 1.7% | — | Realobjects Pdfreactor | 11/6/2019 | 17/6/2026 | Lack of validation in the HTML parser in RealObjects PDFreactor before 10.1.10722 leads to SSRF, allowing attackers to access network or file resources on behalf of the server by supplying malicious HTML content. | |
| Modificada | Crítica (9.8) | 2.8% | — | Facebook React-dev-utils | 31/12/2018 | 17/6/2026 | react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an editor. The input to that command was not properly sanitized, allowing an attacker who can make a network request to the server (either via CSRF or by direct request) to execute… | |
| Modificada | Media (6.1) | 3.4% | — | Facebook React | 31/12/2018 | 17/6/2026 | React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and 16.4.x. It was fixed in 16.0.1, 16.1.2,… | |
| Modificada | Alta (8.1) | 1.8% | — | React-native-baidu-voice-synthesizer Project React-native-baidu-voice-synthesizer | 4/6/2018 | 17/6/2026 | react-native-baidu-voice-synthesizer is a baidu voice speech synthesizer for react native. react-native-baidu-voice-synthesizer downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker… | |
| Modificada | Alta (7.5) | 2.7% | — | ABB Vsn300 FirmwareABB Vsn300 FOR React Firmware | 7/8/2017 | 17/6/2026 | An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access internal information about status and… | |
| Modificada | Media (6.5) | 1.5% | — | ABB Vsn300 FirmwareABB Vsn300 FOR React Firmware | 7/8/2017 | 17/6/2026 | A Permissions, Privileges, and Access Controls issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. The web application does not properly restrict privileges of the Guest account. A malicious user may be able to gain access to… | |
| Modificada | Media (6.8) | 1.2% | — | Phpreactor | 18/9/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in php(Reactor) 1.2.7pl1 allow remote attackers to execute arbitrary PHP code via a URL in the pathtohomedir parameter to (1) ekilat.com-int.tpl.php, (2) phpreactor.org-top.tpl.php, or (3) ekilat.com-top.tpl.php in examples/. NOTE: this issue has been disputed by CVE,… | |
| Modificada | Alta (7.5) | 7.8% | — | Joomla J Reactions | 8/8/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in langset.php in J! Reactions (com_jreactions) 1.8.1 and earlier, a Joomla! component, allows remote attackers to execute arbitrary PHP code via a URL in the comPath parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Phpreactor | 6/6/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in php(Reactor) 1.2.7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the pathtohomedir parameter to (1) view.inc.php, (2) users.inc.php, (3) updatecms.inc.php, and (4) polls.inc.php in inc/; and other unspecified files, different vectors… | |
| Modificada | Alta (10) | 1.2% | — | Reactos | 28/3/2007 | 16/6/2026 | Unspecified vulnerability in ReactOS 0.3.1 has unknown impact and attack vectors, related to a fix for "dozens of win32k bugs and failures," in which the fix itself introduces a vulnerability, possibly related to user-mode and kernel-mode copy failures. | |
| Modificada | Alta (10) | 7.8% | — | Daansystems Newsreactor | 21/3/2007 | 16/6/2026 | Stack-based buffer overflow in DaanSystems NewsReactor 20070220.21 allows remote attackers to execute arbitrary code via a yEnc (yEncode) encoded article with a long filename. | |
| Modificada | Alta (7.5) | 2.5% | — | Ekilat LLC Php(reactor) | 5/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in editprofile.php in php(Reactor) 1.27pl1 allows remote attackers to execute arbitrary PHP code via a URL in the pathtohomedir parameter. | |
| Modificada | Media (4.3) | 1.4% | — | Ekilat LLC Php(reactor) | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PHP(Reactor) 1.2.7 pl1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the style attribute of an HTML tag. | |
| Modificada | Media (5.5) | 0.19% | — | Daansystems Newsreactor | 31/12/2002 | 16/6/2026 | NewsReactor 1.0 uses a weak encryption scheme, which could allow local users to decrypt the passwords and gain access to other users' newsgroup accounts. |