Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.6)1.1%⚠ Explotación activaTanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+16712/5/202617/6/2026
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The…
AnalizadaMedia (5.5)0.20%—Openjsf Eslint26/1/202617/6/2026
Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/shared/serialization.js. The exploit is triggered via the RuleTester.run() method, which validates test cases and checks for duplicates. During validation, the internal function checkDuplicateTestCase()…
AplazadaCrítica (9.8)0.36%—Eslint-ban-momentAI21/8/202517/6/2026
eslint-ban-moment is an Eslint plugin for final assignment in VIHU. In 3.0.0 and earlier, a sensitive Supabase URI is exposed in .env. A valid Supabase URI with embedded username and password will allow an attacker complete unauthorized access and control over database and user data. This could lead to data…
AnalizadaAlta (7.5)4.5%⚠ Explotación activaEslint-config-prettierEslint-plugin-prettierUn-ts SynckitUn-ts Pkgr/core+319/7/202517/6/2026
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
AplazadaAlta (7.7)0.51%—Eslint Plugin-kitAI19/11/20243/8/2026
Versions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by exploiting this vulnerability.
ModificadaMedia (6.1)0.51%—Eslint-detailed-reporter Project Eslint-detailed-reporter20/4/202317/6/2026
A vulnerability was found in mportuga eslint-detailed-reporter up to 0.9.0 and classified as problematic. Affected by this issue is the function renderIssue in the library lib/template-generator.js. The manipulation of the argument message leads to cross site scripting. The attack may be launched remotely. The patch…
ModificadaCrítica (9.8)3.0%—Eslint-fixer Project Eslint-fixer19/3/202117/6/2026
The eslint-fixer package through 0.1.5 for Node.js allows command injection via shell metacharacters to the fix function. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. The ozum/eslint-fixer GitHub repository has been intentionally deleted
ModificadaAlta (7.8)4.3%—Microsoft Eslint11/3/202119/8/2026
Visual Studio Code ESLint Extension Remote Code Execution Vulnerability
ModificadaAlta (8.8)24%—Microsoft Eslint14/7/202017/6/2026
A remote code execution vulnerability exists in the ESLint extension for Visual Studio Code when it validates source code after opening a project, aka 'Visual Studio Code ESLint Extention Remote Code Execution Vulnerability'.
ModificadaCrítica (9.8)2.3%—Eslint-utils Project Eslint-utils26/8/201917/6/2026
In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code.