Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Analizada | Media (5.5) | 0.20% | — | Openjsf Eslint | 26/1/2026 | 17/6/2026 | Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/shared/serialization.js. The exploit is triggered via the RuleTester.run() method, which validates test cases and checks for duplicates. During validation, the internal function checkDuplicateTestCase()… | |
| Aplazada | Crítica (9.8) | 0.36% | — | Eslint-ban-momentAI | 21/8/2025 | 17/6/2026 | eslint-ban-moment is an Eslint plugin for final assignment in VIHU. In 3.0.0 and earlier, a sensitive Supabase URI is exposed in .env. A valid Supabase URI with embedded username and password will allow an attacker complete unauthorized access and control over database and user data. This could lead to data… | |
| Analizada | Alta (7.5) | 4.5% | ⚠ Explotación activa | Eslint-config-prettierEslint-plugin-prettierUn-ts SynckitUn-ts Pkgr/core+3 | 19/7/2025 | 17/6/2026 | eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows. | |
| Aplazada | Alta (7.7) | 0.51% | — | Eslint Plugin-kitAI | 19/11/2024 | 3/8/2026 | Versions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by exploiting this vulnerability. | |
| Modificada | Media (6.1) | 0.51% | — | Eslint-detailed-reporter Project Eslint-detailed-reporter | 20/4/2023 | 17/6/2026 | A vulnerability was found in mportuga eslint-detailed-reporter up to 0.9.0 and classified as problematic. Affected by this issue is the function renderIssue in the library lib/template-generator.js. The manipulation of the argument message leads to cross site scripting. The attack may be launched remotely. The patch… | |
| Modificada | Crítica (9.8) | 3.0% | — | Eslint-fixer Project Eslint-fixer | 19/3/2021 | 17/6/2026 | The eslint-fixer package through 0.1.5 for Node.js allows command injection via shell metacharacters to the fix function. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. The ozum/eslint-fixer GitHub repository has been intentionally deleted | |
| Modificada | Alta (7.8) | 4.3% | — | Microsoft Eslint | 11/3/2021 | 19/8/2026 | Visual Studio Code ESLint Extension Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 24% | — | Microsoft Eslint | 14/7/2020 | 17/6/2026 | A remote code execution vulnerability exists in the ESLint extension for Visual Studio Code when it validates source code after opening a project, aka 'Visual Studio Code ESLint Extention Remote Code Execution Vulnerability'. | |
| Modificada | Crítica (9.8) | 2.3% | — | Eslint-utils Project Eslint-utils | 26/8/2019 | 17/6/2026 | In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code. |