Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 1.2% | — | Hapijs Hoek | 23/9/2022 | 17/6/2026 | hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function. | |
| Modificada | Media (5.9) | 1.9% | — | Hapijs NES | 4/6/2018 | 17/6/2026 | Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denial of service vulnerability via an invalid Cookie header. This is only present when websocket authentication is set to `cookie`. Submitting an invalid cookie on the websocket upgrade request will… | |
| Modificada | Alta (7.5) | 1.6% | — | Hapijs Hapi | 4/6/2018 | 17/6/2026 | hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` header an uncaught exception is thrown. This may cause hapi to crash or to hang the client connection until the timeout period is reached. | |
| Modificada | Media (5.3) | 1.5% | — | Hapijs Hapi | 31/5/2018 | 17/6/2026 | Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsistent headers and at worst allowed cross-origin activities that were expected to be forbidden. If the connection has CORS enabled but one route has it off, and the route is not GET, the OPTIONS… | |
| Modificada | Media (5.9) | 1.0% | — | Hapijs Hapi | 29/5/2018 | 17/6/2026 | When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined and when a higher level config included security restrictions (like origin), a higher level config that included security restrictions (like origin) would have those restrictions overridden by less… | |
| Modificada | Alta (7.5) | 2.1% | — | Hapijs Hapi | 29/5/2018 | 17/6/2026 | Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be raised. Instead of sending a HTTP 500 error back to the sender, hapi node module before 11.1.3 will continue to hold the socket open until timed out (default node timeout is 2 minutes). | |
| Modificada | Alta (8.8) | 4.2% | — | Hapijs Hoek | 30/3/2018 | 17/6/2026 | hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge' and 'applyToDefaults' functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that… |