Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2537▼ 360 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
1343 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.21% | — | Auth0 Node-jws | 4/12/2025 | 24/7/2026 | auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditions. Applications are affected when they use the jws.createVerify() function for… | |
| Aplazada | Media (5.1) | 0.18% | — | Kaspersky Endpoint Security FOR LinuxAIKaspersky Industrial Cybersecurity FOR Linux NodesAIKaspersky Endpoint Security FOR MACAI | 20/11/2025 | 17/6/2026 | Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Linux (any version with anti-virus databases prior to 18.11.2025), Kaspersky Industrial CyberSecurity for Linux Nodes (any version with anti-virus databases prior to 18.11.2025), and Kaspersky Endpoint Security for Mac (12.0.0.325, 12.1.0.553, and… | |
| Analizada | Media (5.3) | 0.41% | — | Nodeca Js-yaml | 13/11/2025 | 17/6/2026 | js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml documents may be impacted. The problem is patched in js-yaml 4.1.1… | |
| Aplazada | Alta (8.6) | 0.45% | — | Amazon Aurora PostgresqlAIAmazon Jdbc WrapperAIAmazon GO WrapperAIAmazon Nodejs WrapperAI+2 | 10/11/2025 | 17/6/2026 | An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users. We recommend customers upgrade to the… | |
| Aplazada | Media (6.1) | 0.13% | — | Node-tarAI | 30/10/2025 | 17/6/2026 | node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uninitialized memory contents if tar file was changed on disk to a smaller size while being read. This vulnerability is fixed in 7.5.2. | |
| Aplazada | Alta (7.5) | 0.52% | — | Node-staticAINubosoftware Node-staticAI | 30/9/2025 | 17/6/2026 | This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception when user input includes null bytes. This allows attackers to access http://host/%00 and crash the server. | |
| Analizada | Media (6.5) | 0.41% | — | Node-cube | 24/9/2025 | 17/6/2026 | The node-cube package (prior to version 5.0.0) contains a vulnerability in its handling of prototype chain initialization, which could allow an attacker to inject properties into the prototype of built-in objects. This issue, categorized under CWE-1321, arises from improper validation of user-supplied input in the… | |
| Aplazada | Baja (3.2) | 0.13% | — | Node-ipAI | 16/9/2025 | 17/6/2026 | The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 0 is improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2024-29415. NOTE: in current versions of several applications, connection attempts to the IP… | |
| Aplazada | Baja (3.2) | 0.13% | — | IP Project Node-ipAI | 16/9/2025 | 17/6/2026 | The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 017700000001 is improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2024-29415. | |
| Aplazada | Baja (1.2) | 0.19% | — | GrandnodeAI | 10/9/2025 | 17/6/2026 | A vulnerability was detected in GrandNode up to 2.3.0. The impacted element is an unknown function of the file /checkout/ConfirmOrder/ of the component Voucher Handler. The manipulation of the argument giftvouchercouponcode results in race condition. The attack may be launched remotely. The attack requires a high… | |
| Aplazada | Alta (8.6) | 0.37% | — | DuckdbAIDuckdb Node-apiAIDuckdb Node-bindingsAIDuckdb-wasmAI | 9/9/2025 | 17/6/2026 | DuckDB is an analytical in-process SQL database management system. On 08 September 2025, the DuckDB distribution for Node.js on npm was compromised with malware (along with several other packages). An attacker published new versions of four of DuckDB's packages that included malicious code to interfere with cryptocoin… | |
| Aplazada | Alta (7.5) | 0.61% | — | Plone VoltoAINodejsAI | 28/8/2025 | 25/9/2026 | Volto is a React based frontend for the Plone Content Management System. In versions from 19.0.0-alpha.1 to before 19.0.0-alpha.4, 18.0.0 to before 18.24.0, 17.0.0 to before 17.22.1, and prior to 16.34.0, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL.… | |
| Analizada | Alta (8.6) | 8.5% | — | Nodebb | 27/8/2025 | 17/6/2026 | NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not properly sanitized, allowing unauthenticated, remote attackers to inject boolean-based blind and PostgreSQL error-based payloads. | |
| Aplazada | Media (5.3) | 0.39% | — | OAKAIDenoAIDeno DeployAINodejsAI+2 | 9/8/2025 | 17/6/2026 | oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. In versions 17.1.5 and below, it's possible to significantly slow down an oak server with specially crafted values of the x-forwarded-proto or x-forwarded-for headers. | |
| Aplazada | Crítica (10) | 0.36% | — | Node-samlAI | 28/7/2025 | 17/6/2026 | A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from the (unsigned) original response document. This is different than the parts that are verified when checking signature. This allows an attacker to modify authentication details within a valid SAML… | |
| Analizada | Alta (8.3) | 0.50% | — | PSU Haxcms-nodejsPSU Haxcms-php | 26/7/2025 | 17/6/2026 | HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of haxcms-nodejs and versions 11.0.8 and below of haxcms-php, API endpoints do not perform authorization checks when interacting with a resource. Both the JS and PHP versions of the CMS do not verify that a… | |
| Aplazada | Crítica (9.3) | 0.55% | — | Node-samlAI | 24/7/2025 | 17/6/2026 | Node-SAML is a SAML library not dependent on any frameworks that runs in Node. In versions 5.0.1 and below, Node-SAML loads the assertion from the (unsigned) original response document. This is different than the parts that are verified when checking signature. This allows an attacker to modify authentication details… | |
| Analizada | Media (6.1) | 0.31% | — | PSU Haxcms-nodejsPSU Haxcms-php | 23/7/2025 | 17/6/2026 | HAX CMS allows users to manage their microsite universe with a NodeJS or PHP backend. In haxcms-nodejs versions 11.0.12 and below and in haxcms-php versions 11.0.7 and below, all pages within the HAX CMS application do not contain headers to prevent other websites from loading the site within an iframe. This applies… | |
| Analizada | Alta (7.3) | 0.34% | — | PSU Haxcms-nodejs | 22/7/2025 | 17/6/2026 | HAX CMS NodeJS allows users to manage their microsite universe with a NodeJS backend. Versions 11.0.9 and below were distributed with hardcoded default credentials for the user and superuser accounts. Additionally, the application has default private keys for JWTs. Users aren't prompted to change credentials or… | |
| Analizada | Alta (7.1) | 0.41% | — | PSU Haxcms-nodejs | 21/7/2025 | 17/6/2026 | HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the HAX CMS NodeJS application crashes when an authenticated attacker provides an API request lacking required URL parameters. This vulnerability affects the listFiles and saveFiles endpoints. This… | |
| Analizada | Alta (7.2) | 0.20% | — | PSU Haxcms-nodejs | 21/7/2025 | 17/6/2026 | HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.7 and below, the NodeJS version of HAX CMS has a disabled Content Security Policy (CSP). This configuration is insecure for a production application because it does not protect against cross-site-scripting attacks.… | |
| Analizada | Crítica (9.3) | 0.40% | — | PSU Haxcms-nodejs | 21/7/2025 | 17/6/2026 | HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and below, the NodeJS version of HAXcms uses an insecure default configuration designed for local development. The default configuration does not perform authorization or authentication checks. If a user… | |
| Aplazada | Alta (7.5) | 15% | — | Nodejs Node.jsAI | 18/7/2025 | 17/6/2026 | An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users of `path.join` API. | |
| Aplazada | Alta (7.5) | 1.2% | — | NodejsAI | 18/7/2025 | 17/6/2026 | The V8 release used in Node.js v24.0.0 has changed how string hashes are computed using rapidhash. This implementation re-introduces the HashDoS vulnerability as an attacker who can control the strings to be hashed can generate many hash collisions - an attacker can generate collisions even without knowing the… | |
| Aplazada | Alta (8.9) | 1.4% | — | Github Kanban MCP ServerAINodejsAIGithub GHAI | 14/7/2025 | 17/6/2026 | GitHub Kanban MCP Server is a Model Context Protocol (MCP) server for managing GitHub issues in Kanban board format and streamlining LLM task management. Version 0.3.0 of the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition… |