Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 1.1% | — | Dchester JsonpathAI | 9/2/2026 | 25/8/2026 | Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JSON Path input, which is not designed to handle untrusted data safely. An attacker can exploit this… | |
| Analizada | Crítica (9.8) | 0.51% | — | Dchester Jsonpath | 28/1/2026 | 7/9/2026 | The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution. | |
| Aplazada | Alta (8.9) | 10% | — | Jsonpath-plusAI | 15/2/2025 | 17/6/2026 | Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode. **Note:** This is caused by an incomplete fix for… | |
| Aplazada | Crítica (9.8) | 9.0% | — | Jsonpath-plusAI | 11/10/2024 | 17/6/2026 | All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** There were several attempts to fix it in versions… | |
| Analizada | Media (5.3) | 0.68% | — | Json-path Jayway Jsonpath | 27/12/2023 | 17/6/2026 | json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method. |