Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2748▲ 37 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.63% | — | HL7 Hapi FhirAI | 16/9/2026 | 30/9/2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can enter an infinite loop while processing attacker-controlled Smart Health Card JWT content whose… | |
| Pendiente de análisis | Alta (7.5) | 0.63% | — | HL7 Hapi FhirAI | 16/9/2026 | 30/9/2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can consume attacker-controlled Smart Health Card JWT content whose header contains zip: "DEF" and… | |
| Aplazada | Baja (3.7) | 0.39% | — | JOIAIHapi JOIAI | 1/9/2026 | 9/9/2026 | joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.6 and 18.2.5, the @hapi/joi package through 17.1.1 and the successor joi package contain prototype pollution in lib/messages.js, where exports.compile() and exports.merge() reuse inherited objects for attacker-controlled… | |
| Aplazada | Alta (7.5) | 0.49% | — | Hapifhir Hapi FhirAI | 7/8/2026 | 9/9/2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth, so a deeply nested text.div narrative triggers unbounded recursion between parseElementInner() and parseElement(), raising a… | |
| Aplazada | Alta (7.5) | 0.49% | — | HL7 Hapi FhirAI | 7/8/2026 | 9/9/2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arrays or objects. As a result, a small but deeply nested, syntactically valid FHIR… | |
| Aplazada | Media (5) | 0.17% | — | Hapifhir Hapi FhirAI | 7/8/2026 | 9/9/2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the hidden scan command concatenates attacker-controlled Implementation Guide titles, profile titles, and source references into scan.html without escaping in Scanner.java. As a result, a user who… | |
| Pendiente de análisis | Alta (7.5) | 0.68% | — | HL7 Hapi FhirAI | 17/7/2026 | 23/7/2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.9 and 6.9.4.2, all implementations of FHIRPathEngine accept arbitrary FHIRPath expressions and evaluate them without input validation, and the FHIRPath functions matches(), matchesFull(), and… | |
| Aplazada | Media (5.3) | 0.59% | — | Hapi InertAI | 17/7/2026 | 23/7/2026 | @hapi/inert provides static file and directory handlers for hapi.js. From 4.0.0 to 7.1.0, @hapi/inert serves static files from a directory configured with path in the directory or file handlers or relativeTo for h.file(), with confinement enforced by the confine option, but the confinement check compared the resolved… | |
| Aplazada | Media (6.5) | 0.18% | — | Hapi WreckAI | 17/7/2026 | 23/7/2026 | @hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie, and Proxy-Authorization before following a cross-origin redirect, but the origin check compares hostnames only and ignores scheme and port, so credentials are forwarded intact across same-host port… | |
| Aplazada | Media (6.3) | 0.42% | — | Hapi WreckAI | 17/7/2026 | 23/7/2026 | @hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname, only the Authorization and Cookie headers are stripped, and the standard credential header Proxy-Authorization is forwarded intact to the redirect target, potentially exposing forward-proxy… | |
| Aplazada | Alta (7.7) | 0.47% | — | Hapi ContentAI | 17/7/2026 | 23/7/2026 | @hapi/content provided HTTP Content-* headers parsing. Prior to 6.0.2, Content.disposition() retained the last occurrence of each duplicate parameter while Content.type() retained the first occurrence of duplicate charset and boundary parameters, creating a parameter-smuggling primitive when another component in the… | |
| Pendiente de análisis | Alta (7.5) | 0.68% | — | Hapifhir Hapi FhirAI | 16/7/2026 | 18/7/2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.7, the FHIRPathEngine implementation passes user-controlled regular expressions from matches(), matchesFull(), and replaceMatches() to Java regex operations without effective timeouts, allowing… | |
| Analizada | Alta (8.7) | 0.57% | — | Hapifhir HL7 Fhir Core | 8/7/2026 | 16/7/2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.XsltUtilities saxonTransform(...) overloads instantiated a bare net.sf.saxon.TransformerFactoryImpl() without ACCESS_EXTERNAL_DTD or ACCESS_EXTERNAL_STYLESHEET restrictions,… | |
| Analizada | Alta (7.5) | 0.68% | — | Hapifhir HL7 Fhir Core | 8/7/2026 | 16/7/2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, the fix for CVE-2026-45367 incompletely patched the DSTU2 module, leaving FHIRPathEngine.matches() in org.hl7.fhir.dstu2/utils/FHIRPathEngine.java to call raw String.matches(sw) without… | |
| Analizada | Crítica (9.3) | 0.42% | — | Hapifhir HL7 Fhir Core | 31/3/2026 | 24/7/2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that makes outbound HTTP requests to attacker-controlled URLs. Combined with a startsWith() URL prefix matching… | |
| Analizada | Media (5.8) | 0.32% | — | Hapifhir HL7 Fhir Core | 31/3/2026 | 24/7/2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the /loadIG HTTP endpoint in the FHIR Validator HTTP service accepts a user-supplied URL via JSON body and makes server-side HTTP requests to it without any hostname, scheme, or domain… | |
| Analizada | Crítica (9.1) | 0.20% | — | Hapifhir HL7 Fhir Core | 31/3/2026 | 24/7/2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, ManagedWebAccessUtils.getServer() uses String.startsWith() to match request URLs against configured server URLs for authentication credential dispatch. Because configured server URLs (e.g.,… | |
| Aplazada | Media (6.4) | 0.19% | — | Jeremyshapiro FusedeskAI | 21/3/2026 | 17/6/2026 | The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fusedesk_newcase shortcode in all versions up to, and including, 6.8 due to insufficient input sanitization and output escaping on the 'emailtext' attribute. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.5) | 0.47% | — | Hapifhir Hapi FhirAI | 20/3/2026 | 15/7/2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.0, when setting headers in HTTP requests, the internal HTTP client sends headers first to the host in the initial URL but also, if asked to follow redirects and a 30X HTTP response code is… | |
| Aplazada | Media (6.4) | 0.31% | — | Jeremyshapiro FusedeskAI | 24/4/2025 | 17/6/2026 | The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘successredirect’ parameter in all versions up to, and including, 6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Modificada | Media (5.4) | 0.29% | — | Jeremyshapiro Fusedesk | 12/2/2025 | 17/6/2026 | The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fusedesk_newcase' shortcode in all versions up to, and including, 6.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.6) | 0.90% | — | HL7 Hapi FhirAIHL7 Fhir CoreAI | 8/11/2024 | 17/6/2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag ( <!DOCTYPE foo [<!ENTITY example SYSTEM "/etc/passwd"> ]> could produce… | |
| Aplazada | Crítica (9.8) | 1.9% | — | HapifhirAI | 5/11/2024 | 17/6/2026 | An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities. | |
| Modificada | Alta (7.5) | 1.3% | — | Hapifhir HL7 Fhir Core | 12/12/2023 | 17/6/2026 | The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain directories via directory traversal, if an allowed directory name is a substring of the directory name chosen by the attacker. NOTE: this issue exists because of an… | |
| Analizada | Media (5.4) | 0.50% | — | Jeremyshapiro URL Params | 16/8/2023 | 17/6/2026 | The URL Params WordPress plugin before 2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. |