Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 0.66% | — | I18next-http-middleware | 15/6/2026 | 18/6/2026 | i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. In versions prior to 3.9.7, the missingKeyHandler blocked the literal request-body keys __proto__, constructor, and prototype (added in 3.9.3, see GHSA-5fgg-jcpf-8jjw), but did not reject dotted… | |
| Analizada | Crítica (9.1) | 0.66% | — | I18next-fs-backend | 15/6/2026 | 17/6/2026 | Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. via i18next-http-middleware's missingKeyHandler exposed to untrusted input). Backend.writeFile() splits each queued missing-key string on the configured keySeparator… | |
| Aplazada | Alta (8.2) | 0.44% | — | I18next-http-middlewareAI | 8/5/2026 | 17/6/2026 | i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18next-http-middleware passes the user-controlled lng and ns values from getResourcesHandler directly into i18next.services.backendConnector.load(languages, namespaces, …)… | |
| Aplazada | Media (6.5) | 0.33% | — | I18next-locize-backendAI | 8/5/2026 | 17/6/2026 | i18next-locize-backend is a simple i18next backend for locize.com which can be used in Node.js, in the browser and for Deno. Prior to version 9.0.2, i18next-locize-backend interpolates lng, ns, projectId, and version directly into the configured loadPath / privatePath / addPath / updatePath / getLanguagesPath URL… | |
| Aplazada | Alta (8.2) | 0.43% | — | I18next-fs-backendAI | 8/5/2026 | 17/6/2026 | i18next-fs-backend is a backend layer for i18next using in Node.js and for Deno to load translations from the filesystem. Prior to version 2.6.4, i18next-fs-backend substitutes the lng and ns options directly into the configured loadPath / addPath templates and then read / write the resulting file from disk. The… | |
| Aplazada | Alta (8.6) | 0.40% | — | I18next-http-middlewareAII18nextAI | 8/5/2026 | 17/6/2026 | i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18next-http-middleware wrote user-controlled language values into the Content-Language response header after passing them through utils.escape(), which is an HTML-entity… | |
| Analizada | Media (4.7) | 0.22% | — | I18nextify | 7/5/2026 | 17/6/2026 | i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes. Versions prior to 4.0.8 substitute {{key}} interpolation tokens inside src and href attribute values with the raw string returned by i18next.t(). The substitution logic in src/localize.js (the… | |
| Analizada | Crítica (9.1) | 0.39% | — | I18next-http-backend | 7/5/2026 | 17/6/2026 | Copilot said: i18nextify is a JavaScript library that adds i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes. Versions prior to 3.0.5 interpolate the lng and ns values directly into the configured loadPath / addPath URL template without any… | |
| Aplazada | Media (5.3) | 0.70% | — | VUE I18nAI | 16/7/2025 | 17/6/2026 | Vue I18n is the internationalization plugin for Vue.js. The escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, starting in version 9.0.0 and prior to versions 9.14.5, 10.0.8, and 11.1.0, this setting fails to prevent execution… | |
| Aplazada | Alta (8.9) | 0.63% | — | Intlify Message ResolverAIIntlify VUE I18n CoreAIVuejs VUE I18nAI | 7/3/2025 | 17/6/2026 | Vue I18n is the internationalization plugin for Vue.js. @intlify/message-resolver and @intlify/vue-i18n-core are vulnerable to Prototype Pollution through the entry function: handleFlatJson. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype… | |
| Aplazada | Media (5.3) | 0.67% | — | Vue-i18nAI | 29/11/2024 | 17/6/2026 | vue-i18n is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `createI18n` or `useI18n`. When locale message ASTs are generated in development mode there is a possibility of Cross-site Scripting attack. This issue has been addressed in versions 9.14.2, and… | |
| Modificada | Media (6.5) | 1.1% | — | Apache Sling I18n | 23/2/2023 | 17/6/2026 | Privilege Escalation vulnerability in Apache Software Foundation Apache Sling. Any content author is able to create i18n dictionaries in the repository in a location the author has write access to. As these translations are used across the whole product, it allows an author to change any text or dialog in the product.… | |
| Modificada | Media (6.1) | 0.52% | — | Wikimedia Mediawiki-extensions-i18ntags | 5/1/2023 | 17/6/2026 | A vulnerability was found in Wikimedia mediawiki-extensions-I18nTags and classified as problematic. This issue affects some unknown processing of the file I18nTags_body.php of the component Unlike Parser. The manipulation leads to cross site scripting. The attack may be initiated remotely. The identifier of the patch… | |
| Modificada | Media (6.1) | 0.62% | — | Go-macaron I18n | 25/12/2022 | 17/6/2026 | A vulnerability was found in Macaron i18n. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file i18n.go. The manipulation leads to open redirect. The attack can be launched remotely. Upgrading to version 0.5.0 is able to address this issue. The name of the patch… | |
| Modificada | Alta (7.5) | 3.0% | — | I18n Project I18n | 11/12/2020 | 17/6/2026 | This affects the package i18n before 2.1.15. Vulnerability arises out of insufficient handling of erroneous language tags in src/i18n/Concrete/TextLocalizer.cs and src/i18n/LocalizedApplication.cs. | |
| Modificada | Alta (7.5) | 3.4% | — | I18n Project I18nDebian Linux | 6/11/2018 | 17/6/2026 | Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attackers to cause a denial of service (application crash) via a call in a situation where :some_key is present in keep_keys but not present in the hash. | |
| Modificada | Media (6.1) | 0.86% | — | I18next | 4/6/2018 | 17/6/2026 | i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from the dictionary one at a time, untrusted user input can use the name of one of the dictionary keys to inject script into the browser. This affects i18next <=1.10.2. | |
| Modificada | Alta (8.2) | 0.80% | — | I18n-node-angular Project I18n-node-angular | 31/5/2018 | 17/6/2026 | i18n-node-angular is a module used to interact between i18n and angular without using additional resources. A REST API endpoint that is used for development in i18n-node-angular before 1.4.0 was not disabled in production environments a malicious user could fill up the server causing a Denial of Service or content… | |
| Modificada | Media (6.1) | 1.0% | — | I18next | 29/5/2018 | 17/6/2026 | i18next is a language translation framework. When using the .init method, passing interpolation options without passing an escapeValue will default to undefined rather than the assumed true. This can result in a cross-site scripting vulnerability because user input is assumed to be escaped, but is not. This… | |
| Modificada | Media (4.3) | 2.2% | — | I18n Project I18n | 7/12/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem before 0.6.6 for Ruby allows remote attackers to inject arbitrary web script or HTML via a crafted I18n::MissingTranslationData.new call. | |
| Modificada | Baja (2.1) | 0.86% | — | Reyero I18n | 26/4/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Internationalization module 6.x before 6.x-1.4 for Drupal allow remote authenticated users, with translate interface or administer blocks privileges, to inject arbitrary web script or HTML via (1) strings used in block translation or (2) the untranslated input. |