Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

265 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.54%—Flowpaper Pdf2json5/2/202117/6/2026
Buffer overflow in pdf2json 0.69 allows local users to execute arbitrary code by converting a crafted PDF file.
ModificadaAlta (7.5)2.1%—Owasp Json-sanitizer13/1/202117/6/2026
OWASP json-sanitizer before 1.2.2 can output invalid JSON or throw an undeclared exception for crafted input. This may lead to denial of service if the application is not prepared to handle these situations.
ModificadaCrítica (9.8)2.1%—Owasp Json-sanitizer13/1/202117/6/2026
OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allows an attacker to inject arbitrary HTML or XML into embedding documents.
ModificadaMedia (6.1)0.70%—Jsoneditoronline Jsoneditor11/1/202117/6/2026
Stored XSS was discovered in the tree mode of jsoneditor before 9.0.2 through injecting and executing JavaScript.
ModificadaAlta (7.5)1.4%—Gjson Project Gjson5/1/202117/6/2026
GJSON <=v1.6.5 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a crafted GET call.
ModificadaAlta (7.5)1.8%—Gjson Project Gjson5/1/202117/6/2026
GJSON <1.6.5 allows attackers to cause a denial of service (remote) via crafted JSON.
ModificadaCrítica (9.8)1.2%—Rest/json Project Rest/json1/1/202117/6/2026
The REST/JSON project 7.x-1.x for Drupal allows user registration bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
ModificadaCrítica (9.8)1.2%—Rest/json Project Rest/json1/1/202117/6/2026
The REST/JSON project 7.x-1.x for Drupal allows field access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
ModificadaAlta (7.5)1.1%—Rest/json Project Rest/json1/1/202117/6/2026
The REST/JSON project 7.x-1.x for Drupal allows user enumeration, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
ModificadaCrítica (9.8)1.2%—Rest/json Project Rest/json1/1/202117/6/2026
The REST/JSON project 7.x-1.x for Drupal allows comment access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
ModificadaCrítica (9.8)1.2%—Rest/json Project Rest/json1/1/202117/6/2026
The REST/JSON project 7.x-1.x for Drupal allows node access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
ModificadaAlta (7.5)1.1%—Rest/json Project Rest/json1/1/202117/6/2026
The REST/JSON project 7.x-1.x for Drupal allows session enumeration, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
ModificadaAlta (7.5)1.0%—Rest/json Project Rest/json1/1/202117/6/2026
The REST/JSON project 7.x-1.x for Drupal allows session name guessing, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
ModificadaAlta (7.5)1.1%—Rest/json Project Rest/json1/1/202117/6/2026
The REST/JSON project 7.x-1.x for Drupal allows blockage of user logins, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
ModificadaCrítica (9.8)1.3%—Struct2json Project Struct2json26/12/202017/6/2026
struct2json before 2020-11-18 is affected by a Buffer Overflow because strcpy is used for S2J_STRUCT_GET_string_ELEMENT.
ModificadaCrítica (9.8)6.4%—Jsonpickle Project Jsonpickle17/12/202017/6/2026
jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and clearly documented behaviour. pickle is known to be capable of causing arbitrary code execution, and must not be used with un-trusted data
ModificadaAlta (7.5)2.3%—Jsonparser Project JsonparserFedoraproject Fedora15/12/202017/6/2026
jsonparser 1.0.0 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a GET call.
ModificadaAlta (7.5)1.5%—Gjson Project Gjson15/12/202017/6/2026
GJSON before 1.6.4 allows attackers to cause a denial of service via crafted JSON.
ModificadaCrítica (9.8)1.9%—Json8 Project Json812/11/202017/6/2026
This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leading to a prototype pollution.
ModificadaCrítica (9.8)1.9%—Json-ptr Project Json-ptr10/11/202017/6/2026
This affects all versions of package json-ptr. The issue occurs in the set operation (https://flitbit.github.io/json-ptr/classes/_src_pointer_.jsonpointer.htmlset) when the force flag is set to true. The function recursively set the property in the target object, however it does not properly check the key being set,…
ModificadaAlta (7.5)1.3%—Json8-merge-patch Project Json8-merge-patch9/11/202017/6/2026
Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.
ModificadaAlta (7.2)1.8%—Manuelstofer Json-pointer5/10/202017/6/2026
This affects the package json-pointer before 0.6.1. Multiple reference of object using slash is supported.
ModificadaAlta (7.5)1.7%—Json-bigint Project Json-bigint18/9/202017/6/2026
Prototype pollution in json-bigint npm package < 1.0.0 may lead to a denial-of-service (DoS) attack.
ModificadaAlta (7.2)3.1%—Joyent JsonOracle Commerce Guided SearchOracle Financial Services Crime AND Compliance Management StudioOracle Financial Services Regulatory Reporting With Agilereporter+130/8/202017/6/2026
This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.
ModificadaCrítica (9.8)2.5%—Json Pattern Validator Project Json Pattern Validator10/8/202017/6/2026
jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array.
Orbitaley — Vulnerabilidades