Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
265 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.1% | — | Json-pointer Project Json-pointer | 26/12/2022 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in json-pointer up to 0.6.1. Affected by this issue is the function set of the file index.js. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack may be launched remotely.… | |
| Modificada | Crítica (9.8) | 1.1% | — | Starcounter-jack Json-patch | 25/12/2022 | 17/6/2026 | A vulnerability has been found in Starcounter-Jack JSON-Patch up to 3.1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack can be initiated remotely. The exploit has… | |
| Modificada | Alta (8.8) | 9.2% | 💥 PoC | Json5Fedoraproject Fedora | 24/12/2022 | 17/6/2026 | JSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain by hand (e.g. for config files). The `parse` method of the JSON5 library before and including versions 1.0.1 and 2.2.1 does not restrict parsing of keys named `__proto__`, allowing specially crafted strings to pollute… | |
| Modificada | Alta (8.1) | 0.50% | — | Auth0 Jsonwebtoken | 23/12/2022 | 17/6/2026 | Versions `<=8.5.1` of `jsonwebtoken` library could be misconfigured so that legacy, insecure key types are used for signature verification. For example, DSA keys could be used with the RS256 algorithm. You are affected if you are using an algorithm and a key type other than a combination listed in the GitHub Security… | |
| Modificada | Alta (7.6) | 0.55% | — | Auth0 Jsonwebtoken | 22/12/2022 | 17/6/2026 | In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to signature validation bypass due to defaulting to the `none` algorithm for signature verification. Users are affected if you do not specify algorithms in the `jwt.verify()` function. This issue has… | |
| Modificada | Media (6.3) | 0.77% | — | Auth0 Jsonwebtoken | 22/12/2022 | 17/6/2026 | jsonwebtoken is an implementation of JSON Web Tokens. Versions `<= 8.5.1` of `jsonwebtoken` library can be misconfigured so that passing a poorly implemented key retrieval function referring to the `secretOrPublicKey` argument from the readme link will result in incorrect verification of tokens. There is a possibility… | |
| Modificada | Crítica (9.8) | 0.99% | — | Pdftojson Project Pdftojson | 19/12/2022 | 17/6/2026 | pdftojson commit 94204bb was discovered to contain a stack overflow via the component Stream::makeFilter(char*, Stream*, Object*, int). | |
| Modificada | Crítica (9.8) | 0.99% | — | Pdftojson Project Pdftojson | 19/12/2022 | 17/6/2026 | pdftojson commit 94204bb was discovered to contain a stack overflow via the component Object::copy(Object*):Object.cc. | |
| Analizada | Alta (7.5) | 0.97% | — | Stleary Json-javaHutool | 13/12/2022 | 17/6/2026 | A stack overflow in the org.json.JSONTokener.nextValue::JSONTokener.java component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data. | |
| Modificada | Alta (7.5) | 1.2% | 💥 PoC | HutoolStleary Json-java | 13/12/2022 | 17/6/2026 | A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data. | |
| Modificada | Media (5.3) | 0.64% | — | Deep-parse-json Project Deep-parse-json | 3/11/2022 | 17/6/2026 | deep-parse-json version 1.0.2 allows an external attacker to edit or add new properties to an object. This is possible because the application does not correctly validate the incoming JSON keys, thus allowing the '__proto__' property to be edited. | |
| Modificada | Media (5.3) | 0.64% | — | Fastest-json-copy Project Fastest-json-copy | 3/11/2022 | 17/6/2026 | fastest-json-copy version 1.0.1 allows an external attacker to edit or add new properties to an object. This is possible because the application does not correctly validate the incoming JSON keys, thus allowing the '__proto__' property to be edited. | |
| Modificada | Alta (7.5) | 0.99% | — | Jsonlint Project Jsonlint C++ | 19/10/2022 | 17/6/2026 | jsonlint 1.0 is vulnerable to heap-buffer-overflow via /home/hjsz/jsonlint/src/lexer. | |
| Modificada | Crítica (9.8) | 1.3% | — | Democritus D8s-json | 11/10/2022 | 17/6/2026 | The d8s-json package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0. | |
| Modificada | Crítica (9.8) | 1.7% | — | D8s-json Project D8s-json | 19/9/2022 | 17/6/2026 | The d8s-json for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0. | |
| Modificada | Crítica (9.8) | 1.4% | — | Morgan-json Project Morgan-json | 29/8/2022 | 17/6/2026 | All versions of package morgan-json are vulnerable to Arbitrary Code Execution due to missing sanitization of input passed to the Function constructor. | |
| Modificada | Alta (7.5) | 0.71% | — | Hjiang Json++ | 19/8/2022 | 17/6/2026 | Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx json parsing may lead to stack exhaustion in an address sanitized (ASAN) build. This issue may lead to Denial of Service if the program using the jsonxx library crashes. This issue exists on the current commit of the… | |
| Modificada | Crítica (9.8) | 0.95% | — | Hjiang Json++ | 19/8/2022 | 17/6/2026 | Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx use of the Value class may lead to memory corruption via a double free or via a use after free. The value class has a default assignment operator which may be used with pointer types which may point to alterable data… | |
| Modificada | Crítica (9.8) | 1.5% | — | React Editable Json Tree Project React Editable Json Tree | 15/8/2022 | 17/6/2026 | This library allows strings to be parsed as functions and stored as a specialized component, [`JsonFunctionValue`](https://github.com/oxyno-zeta/react-editable-json-tree/blob/09a0ca97835b0834ad054563e2fddc6f22bc5d8c/src/components/JsonFunctionValue.js). To do this, Javascript's… | |
| Modificada | Media (5.9) | 1.9% | — | Ultrajson Project UltrajsonFedoraproject Fedora | 5/7/2022 | 17/6/2026 | UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. In versions prior to 5.4.0 an error occurring while reallocating a buffer for string decoding can cause the buffer to get freed twice. Due to how UltraJSON uses the internal decoder, this double free is impossible to trigger… | |
| Modificada | Alta (7.5) | 2.5% | — | Ultrajson Project UltrajsonFedoraproject Fedora | 5/7/2022 | 17/6/2026 | UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Affected versions were found to improperly decode certain characters. JSON strings that contain escaped surrogate characters not part of a proper surrogate pair were decoded incorrectly. Besides corrupting strings, this… | |
| Modificada | Crítica (9.8) | 19% | 💥 PoC | Alibaba FastjsonOracle Communications Cloud Native Core Unified Data Repository | 10/6/2022 | 17/6/2026 | The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable… | |
| Modificada | Media (6.1) | 0.71% | — | Jquery Json-viewer Project Jquery Json-viewer | 4/5/2022 | 17/6/2026 | The jquery.json-viewer library through 1.4.0 for Node.js does not properly escape characters such as < in a JSON object, as demonstrated by a SCRIPT element. | |
| Modificada | Crítica (9.8) | 2.3% | — | Blitzjs BlitzBlitzjs Superjson | 9/2/2022 | 17/6/2026 | superjson is a program to allow JavaScript expressions to be serialized to a superset of JSON. In versions prior to 1.8.1 superjson allows input to run arbitrary code on any server using superjson input without prior authentication or knowledge. The only requirement is that the server implements at least one endpoint… | |
| Modificada | Media (5.5) | 1.6% | — | Ultrajson Project UltrajsonDebian LinuxFedoraproject Fedora | 1/1/2022 | 17/6/2026 | UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation. |