Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
265 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.8% | — | Json-schema Project Json-schemaDebian Linux | 13/11/2021 | 17/6/2026 | json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Modificada | Alta (7.5) | 1.4% | — | Flowpaper Pdf2json | 10/11/2021 | 17/6/2026 | pdf2json v0.71 was discovered to contain a NULL pointer dereference in the component ObjectStream::getObject. | |
| Modificada | Crítica (9.8) | 1.8% | — | Flowpaper Pdf2json | 10/11/2021 | 17/6/2026 | pdf2json v0.71 was discovered to contain a stack buffer overflow in the component XRef::fetch. | |
| Analizada | Crítica (9.8) | 1.9% | — | Manuelstofer Json-pointer | 3/11/2021 | 17/6/2026 | This affects all versions of package json-pointer. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 when the pointer components are arrays. | |
| Modificada | Crítica (9.8) | 2.7% | — | Janl Jsonpointer | 3/11/2021 | 17/6/2026 | This affects the package jsonpointer before 5.0.0. A type confusion vulnerability can lead to a bypass of a previous Prototype Pollution fix when the pointer components are arrays. | |
| Modificada | Crítica (9.8) | 1.8% | — | Json-ptr Project Json-ptr | 3/11/2021 | 17/6/2026 | This affects the package json-ptr before 3.0.0. A type confusion vulnerability can lead to a bypass of CVE-2020-7766 when the user-provided keys used in the pointer parameter are arrays. | |
| Modificada | Alta (7.5) | 2.4% | — | Gjson Project Gjson | 22/10/2021 | 17/6/2026 | GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack. | |
| Modificada | Alta (7.5) | 1.4% | — | Jsoneditoronline Jsoneditor | 27/9/2021 | 17/6/2026 | jsoneditor is vulnerable to Inefficient Regular Expression Complexity | |
| Modificada | Media (5.5) | 0.63% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function CCITTFaxStream::lookChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid write of size 2 . | |
| Modificada | Media (5.5) | 0.67% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function Gfx::doShowText in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an Use After Free . | |
| Modificada | Media (5.5) | 0.63% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an uncaught floating point exception. | |
| Modificada | Media (5.5) | 0.63% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function DCTStream::readHuffSym in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 2 . | |
| Modificada | Media (5.5) | 0.63% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 4 . | |
| Modificada | Media (5.5) | 0.63% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function DCTStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a NULL pointer dereference (invalid read of size 1) . | |
| Modificada | Media (5.5) | 0.63% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function DCTStream::reset in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid write of size 8 . | |
| Modificada | Media (5.5) | 0.63% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function EmbedStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a null pointer derefenrece (invalid read of size 8) . | |
| Modificada | Media (5.5) | 0.66% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an Illegal Use After Free . | |
| Modificada | Media (5.5) | 0.63% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 1 . | |
| Modificada | Media (5.5) | 0.63% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function ObjectStream::getObject in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 4 . | |
| Modificada | Media (5.5) | 0.74% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function XRef::fetch in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow . | |
| Modificada | Media (5.5) | 0.74% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function vfprintf in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow. | |
| Modificada | Alta (7.5) | 2.3% | — | Json-smart Project Json-smart-v1Json-smart Project Json-smart-v2Oracle Utilities Framework | 1/6/2021 | 17/6/2026 | A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request. | |
| Modificada | Media (5.3) | 1.2% | — | Is-my-json-valid Project Is-my-json-valid | 30/3/2021 | 17/6/2026 | It was discovered that the is-my-json-valid JavaScript library used an inefficient regular expression to validate JSON fields defined to have email format. A specially crafted JSON file could cause it to consume an excessive amount of CPU time when validated. | |
| Modificada | Crítica (9.8) | 63% | 💥 Exploit | Geojson2kml Project Geojson2kml | 23/2/2021 | 17/6/2026 | All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){}) | |
| Modificada | Media (5.9) | 2.9% | 💥 PoC | Json-smart Project Json-smart-v1Json-smart Project Json-smart-v2Oracle Communications Cloud Native Core PolicyOracle OSS Support Tools+3 | 23/2/2021 | 17/6/2026 | An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information. |