Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2550▼ 376 respecto a la semana anterior
Críticas / altas1325▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
–

17 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.9)0.99%—Webreflection Flatted20/3/20264/9/2026
flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, accessing it with the key "__proto__"…
ModificadaAlta (7.5)0.99%—Webreflection Flatted12/3/20264/9/2026
flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential $ indices, the recursion depth is unbounded, causing a stack overflow that crashes the…
AnalizadaAlta (8)0.14%—Jmlepisto Clatter28/1/202617/6/2026
Clatter is a no_std compatible, pure Rust implementation of the Noise protocol framework with post-quantum support. Versiosn prior to2.2.0 have a protocol compliance vulnerability. The library allowed post-quantum handshake patterns that violated the PSK validity rule (Noise Protocol Framework Section 9.3). This could…
AnalizadaMedia (6.6)0.52%—Flattern Project Flattern31/3/202517/6/2026
Vulnerability in Drupal Flattern – Multipurpose Bootstrap Business Profile.This issue affects Flattern – Multipurpose Bootstrap Business Profile: *.*.
AplazadaMedia (6.3)0.42%—Flatten-jsonAI17/6/202417/6/2026
A Prototype Pollution issue in flatten-json 1.0.1 allows an attacker to execute arbitrary code via module.exports.unflattenJSON (flatten-json/index.js:42)
ModificadaMedia (6.1)0.82%—Nette Latte4/1/202217/6/2026
Latte is an open source template engine for PHP. Versions since 2.8.0 Latte has included a template sandbox and in affected versions it has been found that a sandbox escape exists allowing for injection into web pages generated from Latte. This may lead to XSS attacks. The issue is fixed in the versions 2.8.8, 2.9.6…
ModificadaCrítica (9.8)1.6%—Nette Latte17/12/202117/6/2026
This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When the template is set to allow/disallow the use of certain functions, adding control characters (x00-x08) after the function will bypass these restrictions.
ModificadaCrítica (9.8)3.1%—Flattenizer Project Flattenizer29/12/202017/6/2026
Prototype pollution vulnerability in 'flattenizer' versions 0.0.5 through 1.0.5 allows an attacker to cause a denial of service and may lead to remote code execution.
ModificadaCrítica (9.8)1.9%—Arr-flatten-unflatten Project Arr-flatten-unflatten1/9/202017/6/2026
All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor.
ModificadaMedia (6.3)0.73%—Component-flatten Project Component-flatten18/2/202017/6/2026
All versions of component-flatten are vulnerable to Prototype Pollution. The a function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
ModificadaAlta (7.5)4.3%—PDF Tools AG PDF Form Filling AND Flattening Tool24/5/200616/6/2026
Stack-based buffer overflow in PDF Form Filling and Flattening Tool before 3.1.0.12 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via long field names.
ModificadaMedia (4.3)1.2%—Michael Dean Double Choco Latte2/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in functions.inc.php for Double Choco Latte 0.9.4.3 allow remote attackers to inject arbitrary web script or HTML via the (1) class or (2) method name.
ModificadaAlta (7.5)2.7%—Michael Dean Double Choco Latte24/3/200516/6/2026
Eval injection vulnerability in Double Choco Latte before 0.9.4.3 allows remote attackers to execute arbitrary PHP code via the menuAction variable in (1) functions.inc.php or (2) main.php, which causes code to be injected into an eval statement.
ModificadaMedia (5)1.9%—Michael Dean Double Choco Latte4/10/200216/6/2026
Cross-site scripting vulnerability in Double Choco Latte (DCL) before 20020706 allows remote attackers to inject arbitrary HTML, including script, into web pages via the (1) Ticket# Find, (2) Priorities, (3) Severities, (4) Projects, (5) WO# Find, (6) Departments and (7) Users features.
ModificadaMedia (5)1.5%—Michael Dean Double Choco Latte4/10/200216/6/2026
Double Choco Latte (DCL) before 20020706 does not properly verify if a file was uploaded, which allows remote attackers to conduct certain operations on arbitrary files via the (1) Projects: Upload File Attachment or (2) Work Orders: Import features.
ModificadaMedia (5)1.9%—Michael Dean Double Choco Latte4/10/200216/6/2026
Directory traversal vulnerability in Double Choco Latte (DCL) before 20020706 allows remote attackers to read arbitrary files via .. (dot dot) sequences when downloading files from the Projects: Attachments feature.
ModificadaMedia (5)6.5%—Silverplatter Webspirs2/6/200116/6/2026
Directory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the sp.nextform parameter.