Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.5) | 0.21% | — | Cyclonedx-npmAI | 17/9/2026 | 30/9/2026 | @cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. Prior to version 6.0.0, the Windows fallback path in src/npmRunner.ts, used when npm_execpath does not provide the npm CLI path, can construct a shell command containing an untrusted value from the --workspace option. When an… | |
| Pendiente de análisis | Alta (8.5) | 0.24% | — | Cyclonedx-npmAI | 8/7/2026 | 10/7/2026 | @cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. From 2.1.0 before 5.0.0, the CLI passes user-supplied --workspace values to a subshell without proper sanitization when npm_execpath is unset or empty, allowing arbitrary OS command execution with the privileges of the invoking… | |
| Aplazada | Alta (7.5) | 0.37% | — | Cyclonedx-core-javaAI | 10/11/2025 | 17/6/2026 | The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Starting in version 2.1.0 and prior to version 11.0.1, the XML `Validator` used by cyclonedx-core-java was not configured securely, making the library vulnerable to XML… | |
| Aplazada | Media (5.4) | 0.24% | — | Cyclonedx SunshineAI | 13/8/2025 | 17/6/2026 | CycloneDX Sunshine v0.9 is vulnerable to CSV Formula Injection via a crafted JSON file | |
| Aplazada | Alta (7.2) | 0.85% | — | Cyclonedx CdxgenAI | 27/10/2024 | 17/6/2026 | CycloneDX cdxgen through 10.10.7, when run against an untrusted codebase, may execute code contained within build-related files such as build.gradle.kts, a similar issue to CVE-2022-24441. cdxgen is used by, for example, OWASP dep-scan. NOTE: this has been characterized as a design limitation, rather than an… | |
| Aplazada | Alta (7.5) | 0.59% | — | Cyclonedx Core JavaAI | 28/6/2024 | 17/6/2026 | The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Before deserializing CycloneDX Bill of Materials in XML format, _cyclonedx-core-java_ leverages XPath expressions to determine the schema version of the BOM. The… | |
| Aplazada | Alta (8.1) | 0.92% | — | Owasp CyclonedxAICyclonedx JavascriptAI | 14/5/2024 | 17/6/2026 | The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were possible, when running the provided XML Validator on arbitrary input. This issue was fixed in version 6.7.1. | |
| Modificada | Alta (8.1) | 1.5% | — | Cyclonedx Bill OF Materials Repository Server | 22/3/2022 | 17/6/2026 | CycloneDX BOM Repository Server is a bill of materials (BOM) repository server for distributing CycloneDX BOMs. CycloneDX BOM Repository Server before version 2.0.1 has an improper input validation vulnerability leading to path traversal. A malicious user may potentially exploit this vulnerability to create arbitrary… |