Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2550▼ 376 respecto a la semana anterior
Críticas / altas1325▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.9) | 0.99% | — | Webreflection Flatted | 20/3/2026 | 4/9/2026 | flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, accessing it with the key "__proto__"… | |
| Modificada | Alta (7.5) | 0.99% | — | Webreflection Flatted | 12/3/2026 | 4/9/2026 | flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential $ indices, the recursion depth is unbounded, causing a stack overflow that crashes the… | |
| Analizada | Alta (8) | 0.14% | — | Jmlepisto Clatter | 28/1/2026 | 17/6/2026 | Clatter is a no_std compatible, pure Rust implementation of the Noise protocol framework with post-quantum support. Versiosn prior to2.2.0 have a protocol compliance vulnerability. The library allowed post-quantum handshake patterns that violated the PSK validity rule (Noise Protocol Framework Section 9.3). This could… | |
| Analizada | Media (6.6) | 0.52% | — | Flattern Project Flattern | 31/3/2025 | 17/6/2026 | Vulnerability in Drupal Flattern – Multipurpose Bootstrap Business Profile.This issue affects Flattern – Multipurpose Bootstrap Business Profile: *.*. | |
| Aplazada | Media (6.3) | 0.42% | — | Flatten-jsonAI | 17/6/2024 | 17/6/2026 | A Prototype Pollution issue in flatten-json 1.0.1 allows an attacker to execute arbitrary code via module.exports.unflattenJSON (flatten-json/index.js:42) | |
| Modificada | Media (6.1) | 0.82% | — | Nette Latte | 4/1/2022 | 17/6/2026 | Latte is an open source template engine for PHP. Versions since 2.8.0 Latte has included a template sandbox and in affected versions it has been found that a sandbox escape exists allowing for injection into web pages generated from Latte. This may lead to XSS attacks. The issue is fixed in the versions 2.8.8, 2.9.6… | |
| Modificada | Crítica (9.8) | 1.6% | — | Nette Latte | 17/12/2021 | 17/6/2026 | This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When the template is set to allow/disallow the use of certain functions, adding control characters (x00-x08) after the function will bypass these restrictions. | |
| Modificada | Crítica (9.8) | 3.1% | — | Flattenizer Project Flattenizer | 29/12/2020 | 17/6/2026 | Prototype pollution vulnerability in 'flattenizer' versions 0.0.5 through 1.0.5 allows an attacker to cause a denial of service and may lead to remote code execution. | |
| Modificada | Crítica (9.8) | 1.9% | — | Arr-flatten-unflatten Project Arr-flatten-unflatten | 1/9/2020 | 17/6/2026 | All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor. | |
| Modificada | Media (6.3) | 0.73% | — | Component-flatten Project Component-flatten | 18/2/2020 | 17/6/2026 | All versions of component-flatten are vulnerable to Prototype Pollution. The a function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload. | |
| Modificada | Alta (7.5) | 4.3% | — | PDF Tools AG PDF Form Filling AND Flattening Tool | 24/5/2006 | 16/6/2026 | Stack-based buffer overflow in PDF Form Filling and Flattening Tool before 3.1.0.12 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via long field names. | |
| Modificada | Media (4.3) | 1.2% | — | Michael Dean Double Choco Latte | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in functions.inc.php for Double Choco Latte 0.9.4.3 allow remote attackers to inject arbitrary web script or HTML via the (1) class or (2) method name. | |
| Modificada | Alta (7.5) | 2.7% | — | Michael Dean Double Choco Latte | 24/3/2005 | 16/6/2026 | Eval injection vulnerability in Double Choco Latte before 0.9.4.3 allows remote attackers to execute arbitrary PHP code via the menuAction variable in (1) functions.inc.php or (2) main.php, which causes code to be injected into an eval statement. | |
| Modificada | Media (5) | 1.9% | — | Michael Dean Double Choco Latte | 4/10/2002 | 16/6/2026 | Cross-site scripting vulnerability in Double Choco Latte (DCL) before 20020706 allows remote attackers to inject arbitrary HTML, including script, into web pages via the (1) Ticket# Find, (2) Priorities, (3) Severities, (4) Projects, (5) WO# Find, (6) Departments and (7) Users features. | |
| Modificada | Media (5) | 1.5% | — | Michael Dean Double Choco Latte | 4/10/2002 | 16/6/2026 | Double Choco Latte (DCL) before 20020706 does not properly verify if a file was uploaded, which allows remote attackers to conduct certain operations on arbitrary files via the (1) Projects: Upload File Attachment or (2) Work Orders: Import features. | |
| Modificada | Media (5) | 1.9% | — | Michael Dean Double Choco Latte | 4/10/2002 | 16/6/2026 | Directory traversal vulnerability in Double Choco Latte (DCL) before 20020706 allows remote attackers to read arbitrary files via .. (dot dot) sequences when downloading files from the Projects: Attachments feature. | |
| Modificada | Media (5) | 6.5% | — | Silverplatter Webspirs | 2/6/2001 | 16/6/2026 | Directory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the sp.nextform parameter. |