Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.24% | — | Hester CoreAI | 26/6/2026 | 26/6/2026 | Author Cross Site Scripting (XSS) in Hester Core <= 1.1.8 versions. | |
| Aplazada | Alta (8.2) | 1.1% | — | Dchester JsonpathAI | 9/2/2026 | 25/8/2026 | Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JSON Path input, which is not designed to handle untrusted data safely. An attacker can exploit this… | |
| Analizada | Crítica (9.8) | 0.51% | — | Dchester Jsonpath | 28/1/2026 | 7/9/2026 | The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution. | |
| Aplazada | Media (6.5) | 0.22% | — | Peregrinethemes HesterAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in peregrinethemes Hester hester allows Stored XSS.This issue affects Hester: from n/a through <= 1.1.10. | |
| Aplazada | Media (6.5) | 0.33% | — | Bamboo Manchester Bamboo EnquiriesAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bamboo Manchester Bamboo Enquiries bamboo-enquiries allows Stored XSS.This issue affects Bamboo Enquiries: from n/a through <= 1.9.3. |