Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2537▼ 360 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

1343 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.21%—Auth0 Node-jws4/12/202524/7/2026
auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditions. Applications are affected when they use the jws.createVerify() function for…
AplazadaMedia (5.1)0.18%—Kaspersky Endpoint Security FOR LinuxAIKaspersky Industrial Cybersecurity FOR Linux NodesAIKaspersky Endpoint Security FOR MACAI20/11/202517/6/2026
Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Linux (any version with anti-virus databases prior to 18.11.2025), Kaspersky Industrial CyberSecurity for Linux Nodes (any version with anti-virus databases prior to 18.11.2025), and Kaspersky Endpoint Security for Mac (12.0.0.325, 12.1.0.553, and…
AnalizadaMedia (5.3)0.41%—Nodeca Js-yaml13/11/202517/6/2026
js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml documents may be impacted. The problem is patched in js-yaml 4.1.1…
AplazadaAlta (8.6)0.45%—Amazon Aurora PostgresqlAIAmazon Jdbc WrapperAIAmazon GO WrapperAIAmazon Nodejs WrapperAI+210/11/202517/6/2026
An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users. We recommend customers upgrade to the…
AplazadaMedia (6.1)0.13%—Node-tarAI30/10/202517/6/2026
node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uninitialized memory contents if tar file was changed on disk to a smaller size while being read. This vulnerability is fixed in 7.5.2.
AplazadaAlta (7.5)0.52%—Node-staticAINubosoftware Node-staticAI30/9/202517/6/2026
This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception when user input includes null bytes. This allows attackers to access http://host/%00 and crash the server.
AnalizadaMedia (6.5)0.41%—Node-cube24/9/202517/6/2026
The node-cube package (prior to version 5.0.0) contains a vulnerability in its handling of prototype chain initialization, which could allow an attacker to inject properties into the prototype of built-in objects. This issue, categorized under CWE-1321, arises from improper validation of user-supplied input in the…
AplazadaBaja (3.2)0.13%—Node-ipAI16/9/202517/6/2026
The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 0 is improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2024-29415. NOTE: in current versions of several applications, connection attempts to the IP…
AplazadaBaja (3.2)0.13%—IP Project Node-ipAI16/9/202517/6/2026
The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 017700000001 is improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2024-29415.
AplazadaBaja (1.2)0.19%—GrandnodeAI10/9/202517/6/2026
A vulnerability was detected in GrandNode up to 2.3.0. The impacted element is an unknown function of the file /checkout/ConfirmOrder/ of the component Voucher Handler. The manipulation of the argument giftvouchercouponcode results in race condition. The attack may be launched remotely. The attack requires a high…
AplazadaAlta (8.6)0.37%—DuckdbAIDuckdb Node-apiAIDuckdb Node-bindingsAIDuckdb-wasmAI9/9/202517/6/2026
DuckDB is an analytical in-process SQL database management system. On 08 September 2025, the DuckDB distribution for Node.js on npm was compromised with malware (along with several other packages). An attacker published new versions of four of DuckDB's packages that included malicious code to interfere with cryptocoin…
AplazadaAlta (7.5)0.61%—Plone VoltoAINodejsAI28/8/202525/9/2026
Volto is a React based frontend for the Plone Content Management System. In versions from 19.0.0-alpha.1 to before 19.0.0-alpha.4, 18.0.0 to before 18.24.0, 17.0.0 to before 17.22.1, and prior to 16.34.0, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL.…
AnalizadaAlta (8.6)8.5%—Nodebb27/8/202517/6/2026
NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not properly sanitized, allowing unauthenticated, remote attackers to inject boolean-based blind and PostgreSQL error-based payloads.
AplazadaMedia (5.3)0.39%—OAKAIDenoAIDeno DeployAINodejsAI+29/8/202517/6/2026
oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. In versions 17.1.5 and below, it's possible to significantly slow down an oak server with specially crafted values of the x-forwarded-proto or x-forwarded-for headers.
AplazadaCrítica (10)0.36%—Node-samlAI28/7/202517/6/2026
A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from the (unsigned) original response document. This is different than the parts that are verified when checking signature. This allows an attacker to modify authentication details within a valid SAML…
AnalizadaAlta (8.3)0.50%—PSU Haxcms-nodejsPSU Haxcms-php26/7/202517/6/2026
HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of haxcms-nodejs and versions 11.0.8 and below of haxcms-php, API endpoints do not perform authorization checks when interacting with a resource. Both the JS and PHP versions of the CMS do not verify that a…
AplazadaCrítica (9.3)0.55%—Node-samlAI24/7/202517/6/2026
Node-SAML is a SAML library not dependent on any frameworks that runs in Node. In versions 5.0.1 and below, Node-SAML loads the assertion from the (unsigned) original response document. This is different than the parts that are verified when checking signature. This allows an attacker to modify authentication details…
AnalizadaMedia (6.1)0.31%—PSU Haxcms-nodejsPSU Haxcms-php23/7/202517/6/2026
HAX CMS allows users to manage their microsite universe with a NodeJS or PHP backend. In haxcms-nodejs versions 11.0.12 and below and in haxcms-php versions 11.0.7 and below, all pages within the HAX CMS application do not contain headers to prevent other websites from loading the site within an iframe. This applies…
AnalizadaAlta (7.3)0.34%—PSU Haxcms-nodejs22/7/202517/6/2026
HAX CMS NodeJS allows users to manage their microsite universe with a NodeJS backend. Versions 11.0.9 and below were distributed with hardcoded default credentials for the user and superuser accounts. Additionally, the application has default private keys for JWTs. Users aren't prompted to change credentials or…
AnalizadaAlta (7.1)0.41%—PSU Haxcms-nodejs21/7/202517/6/2026
HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the HAX CMS NodeJS application crashes when an authenticated attacker provides an API request lacking required URL parameters. This vulnerability affects the listFiles and saveFiles endpoints. This…
AnalizadaAlta (7.2)0.20%—PSU Haxcms-nodejs21/7/202517/6/2026
HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.7 and below, the NodeJS version of HAX CMS has a disabled Content Security Policy (CSP). This configuration is insecure for a production application because it does not protect against cross-site-scripting attacks.…
AnalizadaCrítica (9.3)0.40%—PSU Haxcms-nodejs21/7/202517/6/2026
HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and below, the NodeJS version of HAXcms uses an insecure default configuration designed for local development. The default configuration does not perform authorization or authentication checks. If a user…
AplazadaAlta (7.5)15%—Nodejs Node.jsAI18/7/202517/6/2026
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users of `path.join` API.
AplazadaAlta (7.5)1.2%—NodejsAI18/7/202517/6/2026
The V8 release used in Node.js v24.0.0 has changed how string hashes are computed using rapidhash. This implementation re-introduces the HashDoS vulnerability as an attacker who can control the strings to be hashed can generate many hash collisions - an attacker can generate collisions even without knowing the…
AplazadaAlta (8.9)1.4%—Github Kanban MCP ServerAINodejsAIGithub GHAI14/7/202517/6/2026
GitHub Kanban MCP Server is a Model Context Protocol (MCP) server for managing GitHub issues in Kanban board format and streamlining LLM task management. Version 0.3.0 of the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition…