Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.53% | — | Davegamble CjsonAI | 10/9/2026 | 10/9/2026 | A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue… | |
| Pendiente de análisis | Alta (8.7) | 0.44% | — | CjsonAI | 11/8/2026 | 24/9/2026 | cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations to target wrong object keys by supplying crafted JSON Pointer escape sequences (~0 or… | |
| Analizada | Media (6.9) | 0.43% | — | Davegamble Cjson | 29/7/2026 | 4/8/2026 | cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved, the existing target member is detached and deleted before the operation is fully… | |
| Analizada | Alta (8.2) | 0.65% | — | Davegamble Cjson | 29/7/2026 | 4/8/2026 | cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the running time exponential in nesting depth. A small, deeply nested document of a few hundred… | |
| Analizada | Alta (8.7) | 0.70% | — | Davegamble Cjson | 29/7/2026 | 4/8/2026 | cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the… | |
| Analizada | Media (5.1) | 0.29% | — | Davegamble Cjson | 27/7/2026 | 26/8/2026 | cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit size_t, can wrap around when processing strings containing approximately 858,993,460 or more control characters, causing the output buffer to be allocated based… | |
| Aplazada | Crítica (10) | 0.48% | — | Apache KvrocksAIRedis LUAAICjsonAI | 25/6/2026 | 25/6/2026 | Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.0.4 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue. | |
| Modificada | Crítica (9.8) | 0.74% | — | Davegamble Cjson | 3/9/2025 | 17/6/2026 | cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing alphanumeric characters. | |
| Modificada | Media (5.5) | 0.27% | — | Cjson Project Cjson | 23/5/2025 | 17/6/2026 | parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called. | |
| Modificada | Baja (2.9) | 0.23% | — | Cjson Project Cjson | 19/4/2025 | 17/6/2026 | cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}. | |
| Analizada | Alta (7.6) | 0.65% | — | Cjson Project Cjson | 26/4/2024 | 17/6/2026 | cJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of function cJSON_SetValuestring at cJSON.c. | |
| Modificada | Alta (7.5) | 0.97% | — | Davegamble Cjson | 14/12/2023 | 17/6/2026 | cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c. | |
| Modificada | Alta (7.5) | 1.5% | — | Davegamble Cjson | 14/12/2023 | 17/6/2026 | cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c. | |
| Modificada | Alta (7.5) | 2.4% | — | Davegamble CjsonOracle Timesten In-memory Database | 19/7/2019 | 17/6/2026 | DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions. The impact is: Null dereference, so attack can cause denial of service. The component is: cJSON_GetObjectItemCaseSensitive() function. The attack vector is: crafted json file. The fixed version is: 1.7.9 and later. | |
| Modificada | Crítica (9.8) | 2.6% | — | Davegamble CjsonOracle Timesten In-memory Database | 9/5/2019 | 17/6/2026 | cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments. | |
| Modificada | Crítica (9.8) | 2.5% | — | Davegamble CjsonOracle Timesten In-memory Database | 9/5/2019 | 17/6/2026 | cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal. | |
| Modificada | Crítica (9.8) | 2.5% | — | Davegamble Cjson | 29/4/2019 | 17/6/2026 | parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a \ character. | |
| Modificada | Crítica (9.8) | 1.8% | — | Davegamble Cjson | 20/8/2018 | 17/6/2026 | Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible crash, corruption of data or even RCE. This attack appear to be exploitable via Depends on how application uses cJSON library. If application provides network interface then can be… | |
| Modificada | Alta (8.8) | 1.5% | — | Davegamble Cjson | 20/8/2018 | 17/6/2026 | Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE. This attack appear to be exploitable via Attacker must be able to force victim to print JSON data, depending on how cJSON library is used this could be either local or… | |
| Modificada | Alta (7.5) | 1.7% | — | Davegamble Cjson | 20/8/2018 | 17/6/2026 | Dave Gamble cJSON version 1.7.6 and earlier contains a CWE-772 vulnerability in cJSON library that can result in Denial of Service (DoS). This attack appear to be exploitable via If the attacker can force the data to be printed and the system is in low memory it can force a leak of memory. This vulnerability appears… | |
| Modificada | Media (4.3) | 1.4% | — | DAN Pascu Python-cjson | 2/7/2010 | 16/6/2026 | Dan Pascu python-cjson 1.0.5 does not properly handle a ['/'] argument to cjson.encode, which makes it easier for remote attackers to conduct certain cross-site scripting (XSS) attacks involving Firefox and the end tag of a SCRIPT element. | |
| Modificada | Media (6.8) | 1.7% | — | DAN Pascu Python-cjson | 2/7/2010 | 16/6/2026 | Buffer overflow in Dan Pascu python-cjson 1.0.5, when UCS-4 encoding is enabled, allows context-dependent attackers to cause a denial of service (application crash) or possibly have unspecified other impact via vectors involving crafted Unicode input to the cjson.encode function. |