Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2534▼ 399 respecto a la semana anterior
Críticas / altas1321▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
80 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.47% | — | Josephchuks Php-file-manager-with-code-editorAI | 22/9/2026 | 22/9/2026 | A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.php of the component Save Handler. The manipulation of the argument filename/content leads to unrestricted upload. The attack is possible to be carried out… | |
| Aplazada | Media (6.9) | 0.47% | — | Josephchuks Php-file-manager-with-code-editorAI | 22/9/2026 | 22/9/2026 | A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.php. Executing a manipulation of the argument files can lead to unrestricted upload. The attack can be executed remotely. The vendor was contacted early about… | |
| Aplazada | Crítica (9.1) | 0.28% | — | JoseAIOcamlAI | 10/9/2026 | 22/9/2026 | In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key. | |
| Pendiente de análisis | Crítica (9.1) | 0.24% | — | Cisco CjoseAI | 9/9/2026 | 10/9/2026 | OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A256CBC-HS512`) together with any key-management algorithm that generates… | |
| Pendiente de análisis | Alta (8.2) | 0.24% | — | Openidc CjoseAI | 9/9/2026 | 10/9/2026 | OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) does not validate the length of the attacker-supplied `encrypted_key` (JWE Encrypted… | |
| Aplazada | Crítica (9.3) | 0.35% | — | Python-joseAI | 3/9/2026 | 24/9/2026 | python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verification when algorithms are not explicitly restricted. This is an… | |
| Aplazada | Media (6.5) | 0.12% | — | Hsiaoming JoserfcAI | 24/8/2026 | 9/9/2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership matching to list-valued iss and sub claims, allowing an array-valued iss that contains the expected issuer to pass an intended… | |
| Aplazada | Baja (2.3) | 0.14% | — | Hsiaoming JoserfcAI | 29/7/2026 | 30/7/2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. in versions 1.7.1 and prior, joserfc accepts JWTs with trailing padding (==) which are not conforming to the JOSE specifications. This leads to malleability of the JWTs when consumed by joserfc.… | |
| Aplazada | Alta (8.7) | 0.19% | — | Hsiaoming JoserfcAI | 17/7/2026 | 23/7/2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to 1.6.8, joserfc.jwt.decode accepts attacker-forged HMAC-signed tokens when the caller-supplied verification key is the empty string or None, because HMACAlgorithm.sign and… | |
| Aplazada | Media (4.9) | 0.33% | — | Josevega Woocommerce Bulk Edit Products WP Sheet EditorAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in Jose Vega WooCommerce Bulk Edit Products – WP Sheet Editor woo-bulk-edit-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Bulk Edit Products – WP Sheet Editor: from n/a through <= 1.8.21. | |
| Aplazada | Media (5.3) | 0.27% | — | Hsiaoming JoserfcAI | 17/6/2026 | 23/6/2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions 1.3.4 through 1.6.5, joserfc accepts oversized RFC7797 b64=false JWS payloads without applying JWSRegistry.max_payload_length, which can lead to resource exhaustion. The normal JWS… | |
| Modificada | Alta (7.5) | 0.65% | — | Go-jose Project Go-jose | 6/4/2026 | 18/9/2026 | Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field… | |
| Analizada | Alta (7.5) | 0.19% | — | Appsup-dart Jose | 31/3/2026 | 24/7/2026 | JOSE is a Javascript Object Signing and Encryption (JOSE) library. Prior to version 0.3.5+1, a vulnerability in jose could allow an unauthenticated, remote attacker to forge valid JWS/JWT tokens by using a key embedded in the JOSE header (jwk). The vulnerability exists because key selection could treat header-provided… | |
| Analizada | Alta (7.5) | 0.35% | — | Hsiaoming Joserfc | 3/3/2026 | 17/6/2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In 1.6.2 and earlier, a resource exhaustion vulnerability in joserfc allows an unauthenticated attacker to cause a Denial of Service (DoS) via CPU exhaustion. When the library decrypts a JSON Web… | |
| Modificada | Alta (7.5) | 0.26% | — | Jose4j Project Jose4j | 17/12/2025 | 17/6/2026 | In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression. | |
| Analizada | Media (5.3) | 0.19% | — | Python-jose Project Python-jose | 17/12/2025 | 17/6/2026 | In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation… | |
| Analizada | Crítica (9.2) | 0.41% | — | Hsiaoming Joserfc | 18/11/2025 | 17/6/2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions from 1.3.3 to before 1.3.5 and from 1.4.0 to before 1.4.2, the ExceededSizeError exception messages are embedded with non-decoded JWT token parts and may cause Python logging to… | |
| Analizada | Alta (7.5) | 0.24% | — | Dvsekhvalnov Jose2go | 12/11/2025 | 17/6/2026 | An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS) via crafted JSON Web Encryption (JWE) token with an exceptionally high compression ratio. | |
| Aplazada | Media (4.3) | 0.25% | — | Joby Joseph SEO Meta Description UpdaterAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Joby Joseph SEO Meta Description Updater seo-meta-description-updater allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEO Meta Description Updater: from n/a through <= 1.2.0. | |
| Aplazada | Media (6.5) | 0.32% | — | Python-joseAI | 10/10/2025 | 17/6/2026 | python-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature verification. A malicious actor can craft a forged token with arbitrary claims (e.g., is_admin=true) and bypass authentication checks, leading to privilege escalation or unauthorized access in… | |
| Aplazada | Media (6.5) | 0.28% | — | Josevega WP Frontend AdminAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Vega WP Frontend Admin display-admin-page-on-frontend allows Stored XSS.This issue affects WP Frontend Admin: from n/a through <= 1.22.7. | |
| Aplazada | Media (6.5) | 0.17% | — | Josepsitjar WP StorymapAI | 5/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in josepsitjar StoryMap wp-storymap allows DOM-Based XSS.This issue affects StoryMap: from n/a through <= 2.1. | |
| Aplazada | Alta (8.2) | 0.15% | — | Josepsitjar Wp-storymapAI | 14/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in josepsitjar StoryMap wp-storymap allows SQL Injection.This issue affects StoryMap: from n/a through <= 2.1. | |
| Aplazada | Alta (7) | 0.15% | — | JoseAI | 1/8/2025 | 17/6/2026 | jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do not meet recommended security standards" does not reflect guidance in a final publication. | |
| Aplazada | Media (5.8) | 0.91% | — | Connect2id Nimbus Jose JWTAI | 11/7/2025 | 17/6/2026 | Connect2id Nimbus JOSE + JWT 10.0.x before 10.0.2 and 9.37.x before 9.37.4 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion. NOTE: this is independent of the Gson 2.11.0 issue because the Connect2id product could have… |