Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2630▼ 215 respecto a la semana anterior
Críticas / altas1379▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.82% | — | Toml C99AIToml C17AIModdable XSAI | 24/7/2026 | 27/7/2026 | TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The tomlc99 library is no longer maintained, and has an uncontrolled recursion vulnerability publicly reported in the issue tracker. Any caller that passes untrusted TOML to from_toml risks a stack overflow from a… | |
| Aplazada | Alta (7.5) | 0.61% | — | Moddable XSAI | 29/6/2026 | 30/6/2026 | JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory growth. In JsMinify (XS.xs) the cleanup frees only the NodeSet structures and never the per-token contents buffers allocated in JsSetNodeContents; JsDiscardNode unlinks nodes without freeing their… | |
| Aplazada | Crítica (9.8) | 0.61% | — | Moddable XSAIMongodb LibbsonAI | 16/5/2025 | 17/6/2026 | BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities. Those include CVE-2017-14227, CVE-2018-16790, CVE-2023-0437, CVE-2024-6381, CVE-2024-6383, and CVE-2025-0755. BSON-XS was the official Perl XS implementation of MongoDB's BSON serialization, but this… | |
| Modificada | Alta (7.1) | 0.92% | — | Moddable | 12/5/2022 | 17/6/2026 | Moddable commit before 135aa9a4a6a9b49b60aa730ebc3bcc6247d75c45 was discovered to contain an out-of-bounds read via the function fxUint8Getter at /moddable/xs/sources/xsDataView.c. | |
| Modificada | Media (5.5) | 0.78% | — | Moddable SDK | 20/1/2022 | 17/6/2026 | Moddable SDK v11.5.0 was discovered to contain a NULL pointer dereference in the component fx_Function_prototype_hasInstance. | |
| Modificada | Alta (7.8) | 0.83% | — | Moddable SDK | 20/1/2022 | 17/6/2026 | Moddable SDK v11.5.0 was discovered to contain a stack buffer overflow via the component __interceptor_strcat. | |
| Modificada | Media (5.5) | 0.72% | — | Moddable SDK | 20/1/2022 | 17/6/2026 | Moddable SDK v11.5.0 was discovered to contain an invalid memory access vulnerability via the component __asan_memmove. | |
| Modificada | Alta (7.8) | 0.95% | — | Moddable SDK | 20/1/2022 | 17/6/2026 | Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via xs/sources/xsDataView.c in fxUint8Getter. | |
| Modificada | Media (5.5) | 0.72% | — | Moddable SDK | 20/1/2022 | 17/6/2026 | Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsProxy.c in fxProxyGetPrototype. | |
| Modificada | Media (5.5) | 0.72% | — | Moddable SDK | 20/1/2022 | 17/6/2026 | Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsDataView.c in fx_ArrayBuffer_prototype_concat. | |
| Modificada | Media (5.5) | 0.72% | — | Moddable SDK | 20/1/2022 | 17/6/2026 | Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via the component _fini. | |
| Modificada | Alta (7.8) | 0.77% | — | Moddable SDK | 20/1/2022 | 17/6/2026 | Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via the component __libc_start_main. | |
| Modificada | Media (5.5) | 0.72% | — | Moddable SDK | 20/1/2022 | 17/6/2026 | Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsArray.c in fx_Array_prototype_sort. | |
| Modificada | Alta (7.8) | 0.87% | — | Moddable SDK | 20/1/2022 | 17/6/2026 | Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via the component __asan_memcpy. | |
| Modificada | Alta (7.8) | 0.76% | — | Moddable | 19/11/2021 | 17/6/2026 | OpenSource Moddable v10.5.0 was discovered to contain a stack overflow in the fxBinaryExpressionNodeDistribute function at /moddable/xs/sources/xsTree.c. | |
| Modificada | Alta (7.1) | 0.73% | — | Moddable | 19/11/2021 | 17/6/2026 | OpenSource Moddable v10.5.0 was discovered to contain buffer over-read in the fxDebugThrow function at /moddable/xs/sources/xsDebug.c. | |
| Modificada | Alta (7.8) | 0.76% | — | Moddable | 19/11/2021 | 17/6/2026 | OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fx_ArrayBuffer function at /moddable/xs/sources/xsDataView.c. | |
| Modificada | Alta (7.8) | 0.76% | — | Moddable | 19/11/2021 | 17/6/2026 | OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fxIDToString function at /moddable/xs/sources/xsSymbol.c. | |
| Modificada | Alta (7.8) | 0.76% | — | Moddable | 19/11/2021 | 17/6/2026 | OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fx_String_prototype_repeat function at /moddable/xs/sources/xsString.c. | |
| Modificada | Alta (7.8) | 0.76% | — | Moddable | 19/11/2021 | 17/6/2026 | OpenSource Moddable v10.5.0 was discovered to contain a stack overflow via the component /moddable/xs/sources/xsScript.c. | |
| Modificada | Media (5.5) | 0.63% | — | Moddable | 19/11/2021 | 17/6/2026 | OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow via the component /modules/network/wifi/esp/modwifi.c. | |
| Modificada | Alta (7.5) | 1.2% | — | Moddable | 13/7/2021 | 17/6/2026 | Issue was discovered in the fxParserTree function in moddable, allows attackers to cause denial of service via a crafted payload. Fixed in commit 723816ab9b52f807180c99fc69c7d08cf6c6bd61. | |
| Modificada | Alta (7.5) | 1.6% | — | Moddable | 4/12/2020 | 17/6/2026 | Null Pointer Dereference. in xObjectBindingFromExpression at moddable/xs/sources/xsSyntaxical.c:3419 in Moddable SDK before OS200908 causes a denial of service (SEGV). | |
| Modificada | Alta (7.5) | 1.1% | — | Moddable | 4/12/2020 | 17/6/2026 | Heap buffer overflow at moddable/xs/sources/xsDebug.c in Moddable SDK before before 20200903. The top stack frame is only partially initialized because the stack overflowed while creating the frame. This leads to a crash in the code sending the stack frame to the debugger. | |
| Modificada | Alta (7.5) | 1.3% | — | Moddable | 4/12/2020 | 17/6/2026 | Invalid Memory Access in fxUTF8Decode at moddable/xs/sources/xsCommon.c:916 in Moddable SDK before OS200908 causes a denial of service (SEGV). |