Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2550▼ 376 respecto a la semana anterior
Críticas / altas1325▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.41% | — | MorganAI | 11/9/2026 | 16/9/2026 | morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does not escape the double quote character, which delimits the quoted fields of the Apache combined log format that morgan emits. An unauthenticated remote attacker who controls a value written to a quoted… | |
| Analizada | Media (5.3) | 0.29% | — | Morgan Project Morgan | 28/8/2026 | 31/8/2026 | morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line Separator), and U+2029 (Paragraph Separator). An unauthenticated remote client can place… | |
| Analizada | Media (5.3) | 0.41% | — | Morgan Project Morgan | 3/6/2026 | 22/7/2026 | Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and writes it to the log stream without neutralizing control characters. An unauthenticated attacker can send a crafted Authorization Basic header containing CR or LF bytes to inject forged… | |
| Aplazada | Alta (7.1) | 0.24% | — | Morganrichards Auction FeedAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in morganrichards Auction Feed auction-feed allows Stored XSS.This issue affects Auction Feed: from n/a through <= 1.1.4. | |
| Aplazada | Media (6.5) | 0.39% | — | Morgan KAY Chamber Dashboard Business DirectoryAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Morgan Kay Chamber Dashboard Business Directory allows DOM-Based XSS. This issue affects Chamber Dashboard Business Directory: from n/a through 3.3.11. | |
| Aplazada | Media (5.9) | 0.37% | — | Morganf Weather LayerAI | 24/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MorganF Weather Layer weather-layer allows Stored XSS.This issue affects Weather Layer: from n/a through <= 4.2.1. | |
| Modificada | Crítica (9.8) | 1.4% | — | Morgan-json Project Morgan-json | 29/8/2022 | 17/6/2026 | All versions of package morgan-json are vulnerable to Arbitrary Code Execution due to missing sanitization of input passed to the Function constructor. | |
| Modificada | Crítica (9.8) | 2.1% | — | Morganstanley Hobbes | 12/6/2020 | 17/6/2026 | In Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an out-of-bounds (OOB) read/write vulnerability that leads to both local and remote code (via RPC) execution. | |
| Modificada | Crítica (9.8) | 3.4% | — | Morgan Project Morgan | 21/3/2019 | 17/6/2026 | An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1. | |
| Modificada | Media (5.9) | 0.43% | — | Jpmorganchase Chase Mobile | 4/11/2012 | 16/6/2026 | The Chase mobile banking application for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to overriding the… | |
| Modificada | Alta (7.5) | 1.7% | — | Morgan IDS Next GEN Portfolio Manager | 8/8/2007 | 16/6/2026 | SQL injection vulnerability in default.asp in Next Gen Portfolio Manager allows remote attackers to execute arbitrary SQL commands via the (1) Users_Email or (2) Users_Password parameter in an ExecuteTheLogin action. | |
| Modificada | Alta (7.2) | 0.40% | — | Andrew Morgan Linux PAM | 23/1/2007 | 16/6/2026 | pam_unix.so in Linux-PAM 0.99.7.0 allows context-dependent attackers to log into accounts whose password hash, as stored in /etc/passwd or /etc/shadow, has only two characters. | |
| Modificada | Media (4.6) | 0.90% | — | Andrew Morgan Linux PAM | 24/7/2003 | 16/6/2026 | pam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid option disabled, allows local users to spoof log entries and gain privileges by causing getlogin() to return a spoofed user name. |