Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

265 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.8%—Json-schema Project Json-schemaDebian Linux13/11/202117/6/2026
json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
ModificadaAlta (7.5)1.4%—Flowpaper Pdf2json10/11/202117/6/2026
pdf2json v0.71 was discovered to contain a NULL pointer dereference in the component ObjectStream::getObject.
ModificadaCrítica (9.8)1.8%—Flowpaper Pdf2json10/11/202117/6/2026
pdf2json v0.71 was discovered to contain a stack buffer overflow in the component XRef::fetch.
AnalizadaCrítica (9.8)1.9%—Manuelstofer Json-pointer3/11/202117/6/2026
This affects all versions of package json-pointer. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 when the pointer components are arrays.
ModificadaCrítica (9.8)2.7%—Janl Jsonpointer3/11/202117/6/2026
This affects the package jsonpointer before 5.0.0. A type confusion vulnerability can lead to a bypass of a previous Prototype Pollution fix when the pointer components are arrays.
ModificadaCrítica (9.8)1.8%—Json-ptr Project Json-ptr3/11/202117/6/2026
This affects the package json-ptr before 3.0.0. A type confusion vulnerability can lead to a bypass of CVE-2020-7766 when the user-provided keys used in the pointer parameter are arrays.
ModificadaAlta (7.5)2.4%—Gjson Project Gjson22/10/202117/6/2026
GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.
ModificadaAlta (7.5)1.4%—Jsoneditoronline Jsoneditor27/9/202117/6/2026
jsoneditor is vulnerable to Inefficient Regular Expression Complexity
ModificadaMedia (5.5)0.63%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function CCITTFaxStream::lookChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid write of size 2 .
ModificadaMedia (5.5)0.67%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function Gfx::doShowText in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an Use After Free .
ModificadaMedia (5.5)0.63%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an uncaught floating point exception.
ModificadaMedia (5.5)0.63%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function DCTStream::readHuffSym in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 2 .
ModificadaMedia (5.5)0.63%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 4 .
ModificadaMedia (5.5)0.63%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function DCTStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a NULL pointer dereference (invalid read of size 1) .
ModificadaMedia (5.5)0.63%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function DCTStream::reset in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid write of size 8 .
ModificadaMedia (5.5)0.63%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function EmbedStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a null pointer derefenrece (invalid read of size 8) .
ModificadaMedia (5.5)0.66%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an Illegal Use After Free .
ModificadaMedia (5.5)0.63%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 1 .
ModificadaMedia (5.5)0.63%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function ObjectStream::getObject in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 4 .
ModificadaMedia (5.5)0.74%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function XRef::fetch in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow .
ModificadaMedia (5.5)0.74%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function vfprintf in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow.
ModificadaAlta (7.5)2.3%—Json-smart Project Json-smart-v1Json-smart Project Json-smart-v2Oracle Utilities Framework1/6/202117/6/2026
A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.
ModificadaMedia (5.3)1.2%—Is-my-json-valid Project Is-my-json-valid30/3/202117/6/2026
It was discovered that the is-my-json-valid JavaScript library used an inefficient regular expression to validate JSON fields defined to have email format. A specially crafted JSON file could cause it to consume an excessive amount of CPU time when validated.
ModificadaCrítica (9.8)63%💥 ExploitGeojson2kml Project Geojson2kml23/2/202117/6/2026
All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){})
ModificadaMedia (5.9)2.9%💥 PoCJson-smart Project Json-smart-v1Json-smart Project Json-smart-v2Oracle Communications Cloud Native Core PolicyOracle OSS Support Tools+323/2/202117/6/2026
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.
Orbitaley — Vulnerabilidades