Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2633▼ 296 respecto a la semana anterior
Críticas / altas1350▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)61▼ 466 respecto a la semana anterior
–

32 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.40%—Elenavanengelenmaslova Mocknest-serverlessAI8/9/202623/9/2026
A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC Deployment Helper Script. Performing a manipulation results in improper privilege management. It is…
AplazadaMedia (6.5)0.48%—MockoonAI9/7/202610/7/2026
Mockoon provides way to design and run mock APIs. Prior to 9.7.0, a FILE response whose filePath embeds request data is confined by getSafeFilePath in packages/commons-server/src/libs/server/server.ts with resolvedPath.startsWith(staticBaseDir). That prefix test has no path-separator boundary, so a ../-escaped path…
AplazadaAlta (8.8)0.26%—MockoonAI9/7/202610/7/2026
Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as user-defined mock routes, enabled by default in shipped runtimes, serves Access-Control-Allow-Origin: * with write methods allowed, and has no…
AnalizadaCrítica (9.1)0.33%—Mock Business\31/3/202617/6/2026
Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key. Business::OnlinePayment::StoredTransaction generates a secret key by using a MD5 hash of a single call to the built-in rand function, which is unsuitable for cryptographic use. This key is intended for encrypting…
AplazadaAlta (7.5)1.8%—MockoonAI10/9/202517/6/2026
Mockoon provides way to design and run mock APIs. Prior to version 9.2.0, a mock API configuration for static file serving follows the same approach presented in the documentation page, where the server filename is generated via templating features from user input is vulnerable to Path Traversal and LFI, allowing an…
AplazadaMedia (5.9)0.47%—Assetview CloudAIHammock AssetviewAI2/4/202517/6/2026
AssetView and AssetView CLOUD contain an issue with acquiring sensitive information from sent data to the developer. If exploited, sensitive information may be obtained by a remote unauthenticated attacker.
AplazadaAlta (8.2)0.51%—Assetview CloudAIHammock AssetviewAI2/4/202517/6/2026
Missing authentication for critical function vulnerability exists in AssetView and AssetView CLOUD. If exploited, the files on the server where the product is running may be obtained and/or deleted by a remote unauthenticated attacker.
AplazadaAlta (7.1)0.38%—Ronan Mockett Staging CDNAI22/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ronan Mockett Staging CDN staging-cdn allows Reflected XSS.This issue affects Staging CDN: from n/a through <= 1.0.0.
AplazadaMedia (6.5)0.37%—Stefano Marra Smart MockupsAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stefano Marra Smart Mockups smart-mockups allows Stored XSS.This issue affects Smart Mockups: from n/a through <= 1.2.0.
ModificadaAlta (8.8)1.1%—Csutils Csmock10/4/202417/6/2026
A vulnerability was found in csmock where a regular user of the OSH service (anyone with a valid Kerberos ticket) can use the vulnerability to disclose the confidential Snyk authentication token and to run arbitrary commands on OSH workers.
ModificadaCrítica (9.8)1.6%—Rpm-software-management MockFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora16/1/202417/6/2026
The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary code with root user privileges. This weakness stems from the absence of proper sandboxing during the expansion and execution of Jinja2 templates, which may be included in…
ModificadaMedia (6.1)0.44%—Wiremock29/12/202317/6/2026
WireMock with GUI versions 3.2.0.0 through 3.0.4.0 are vulnerable to stored cross-site scripting (SXSS) through the recording feature. An attacker can host a malicious payload and perform a test mapping pointing to the attacker's file, and the result will render on the Matched page in the Body area, resulting in the…
ModificadaAlta (8.2)0.80%—Mockjs Mock.js8/12/202317/6/2026
All versions of the package mockjs are vulnerable to Prototype Pollution via the Util.extend function due to missing check if the attribute resolves to the object prototype. By adding or modifying attributes of an object prototype, it is possible to create attributes that exist on every object, or replace critical…
ModificadaMedia (6.6)0.63%—Python WiremockWiremock StudioWiremockWiremock Docker6/9/202317/6/2026
WireMock is a tool for mocking HTTP services. The proxy mode of WireMock, can be protected by the network restrictions configuration, as documented in Preventing proxying to and recording from specific target addresses. These restrictions can be configured using the domain names, and in such a case the configuration…
ModificadaMedia (5.4)0.50%—Wiremock StudioWiremock6/9/202317/6/2026
WireMock is a tool for mocking HTTP services. WireMock can be configured to only permit proxying (and therefore recording) to certain addresses. This is achieved via a list of allowed address rules and a list of denied address rules, where the allowed list is evaluated first. Until WireMock Webhooks Extension…
ModificadaCrítica (10)1.0%—Wiremock Studio6/9/202317/6/2026
WireMock is a tool for mocking HTTP services. When certain request URLs like “@127.0.0.1:1234" are used in WireMock Studio configuration fields, the request might be forwarded to an arbitrary service reachable from WireMock’s instance. There are 3 identified potential attack vectors: via “TestRequester” functionality,…
ModificadaCrítica (9.8)1.3%—Mockery Project Mockery12/10/202217/6/2026
Prototype pollution vulnerability in function enable in mockery.js in mfncooper mockery commit 822f0566fd6d72af8c943ae5ca2aa92e516aa2cf via the key variable in mockery.js.
ModificadaCrítica (9.8)4.7%—Hammock Assetview28/4/202217/6/2026
Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the system configuration to upload a crafted configuration file to the managing server, which may result in the managed clients to execute arbitrary code with the administrative…
ModificadaAlta (8.8)2.0%—Easy-mock Project Easy Mock5/4/202217/6/2026
easy-mock v1.5.0-v1.6.0 allows remote attackers to bypass the vm2 sandbox and execute arbitrary system commands through special js code.
ModificadaCrítica (9.6)2.2%—Mock-server MockserverOracle Communications Cloud Native Core Policy16/8/202117/6/2026
MockServer is open source software which enables easy mocking of any system you integrate with via HTTP or HTTPS. An attacker that can trick a victim into visiting a malicious site while running MockServer locally, will be able to run arbitrary code on the MockServer machine. With an overly broad default CORS…
ModificadaMedia (5.3)1.8%—SAP Commerce Cloud (accelerator Payment Mock)10/11/202017/6/2026
SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL which will be processed without further interaction, the crafted request leads to Server Side Request Forgery attack…
ModificadaAlta (7.5)1.1%—SAP Commerce Cloud (accelerator Payment Mock)10/11/202017/6/2026
SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL which will be processed without further interaction, the crafted request can render the SAP Commerce service itself…
ModificadaCrítica (9.8)2.0%—Mock2easy Project Mock2easy29/7/202017/6/2026
—
ModificadaMedia (5.3)1.3%—Express-mock-middleware Project Express-mock-middleware7/4/202017/6/2026
express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the `Object.prototype`. Exploitation of this vulnerability requires creation of a new directory where an attack code can be placed which will then be…
ModificadaAlta (8.8)1.8%—Python-dbusmock Project Python-dbusmock22/4/201917/6/2026
python-dbusmock before version 0.15.1 AddTemplate() D-Bus method call or DBusTestCase.spawn_server_template() method could be tricked into executing malicious code if an attacker supplies a .pyc file.