Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2552▼ 400 respecto a la semana anterior
Críticas / altas1318▲ 36 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)97▼ 430 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.51% | — | DeepmergeAI | 18/9/2026 | 23/9/2026 | deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object's prototype,… | |
| Aplazada | Alta (8.2) | 0.52% | — | Deepmerge-tsAI | 20/8/2026 | 18/9/2026 | deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. Prior to 8.0.0, the deepmerge, deepmergeCustom, deepmergeInto, and deepmergeIntoCustom APIs do not track visited objects or object pairs when recursively merging records. When two input values contain self-references at… | |
| Aplazada | Media (5.5) | 0.51% | — | Ts-deepmergeAI | 19/6/2026 | 23/6/2026 | Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of built-in Object.prototype methods (such as toString, valueOf). When user-controlled input contains these keys with non-function values, the resulting merged object becomes broken — any string context… | |
| Modificada | Crítica (9.8) | 1.7% | — | Deepmerge-ts Project Deepmerge-ts | 1/4/2022 | 17/6/2026 | deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. deepmerge-ts is vulnerable to Prototype Pollution via file deepmerge.ts, function defaultMergeRecords(). This issue has been patched in version 4.0.2. There are no known workarounds for this issue. | |
| Modificada | Crítica (9.8) | 1.1% | — | Deepmergefn Project Deepmergefn | 28/7/2021 | 17/6/2026 | All versions of package deepmergefn are vulnerable to Prototype Pollution via deepMerge function. |