Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2567▼ 296 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

90 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.33%—Kylephillips Nested PagesAI30/9/202630/9/2026
Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.
Pendiente de análisisAlta (7.5)0.38%—Nestjs NestAI28/9/202630/9/2026
Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0.2, a single message with a deeply nested object in its pattern can terminate a NestJS microservice using the TCP or RabbitMQ transport. ServerTCP#handleMessage and ServerRMQ#handleMessage pass a client-controlled…
AplazadaMedia (6.4)0.21%—Ashstonestudios Advanced PopupsAI16/9/202616/9/2026
The Advanced Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Notification Button Link' Field in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to…
AplazadaAlta (7.5)0.50%—Flat-to-nestedAI14/9/202630/9/2026
flat-to-nested converts a hierarchy from a flat representation to a nested representation. Prior to 1.1.2, FlatToNested.prototype.convert in index.js uses attacker-influenced id and parent record fields directly as keys in the plain temp and pendingChildOf objects. When parent or id is __proto__, temp[parent] can…
AplazadaMedia (5.1)0.40%—Elenavanengelenmaslova Mocknest-serverlessAI8/9/202623/9/2026
A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC Deployment Helper Script. Performing a manipulation results in improper privilege management. It is…
AnalizadaCrítica (10)0.21%—Google Nest Wifi Router FirmwareGoogle Nest Wifi Point FirmwareGoogle Nest Wifi PRO Firmware24/8/202629/9/2026
Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a denial of service. These issues include triggerable assertion failures and a stack-based buffer overflow.
AplazadaMedia (4.8)0.24%—Kylephillips Nested PagesAI4/8/202626/8/2026
The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML attributes on an administrative listing screen, allowing users with the Editor role (or Contributor/Author when the Nested Pages WordPress plugin before 3.2.15 is enabled for the post type) to inject…
Pendiente de análisisCrítica (10)0.77%—Beproduct Nestjs-authAI20/7/202623/7/2026
@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions of `@beproduct/nestjs-auth` (0.1.2 through 0.1.19). The postinstall…
AplazadaAlta (8.7)0.50%—Nestjs Platform-fastifyAI22/6/202624/6/2026
Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.24, an authentication bypass vulnerability exists in @nestjs/platform-fastify. When middleware is registered through NestJS's MiddlewareConsumer.forRoutes() API on the Fastify adapter, an unauthenticated client can bypass the…
AplazadaAlta (8.2)0.56%—Parse-nested-form-dataAI1/6/202622/7/2026
parse-nested-form-data is a tiny node module for parsing FormData by name into objects and arrays. Prior to version 1.0.1, parseFormData() walks bracket and dot-notation FormData field names into nested objects without filtering reserved property keys. A single FormData field whose name begins with __proto__, or…
AnalizadaCrítica (9.6)1.1%⚠ Explotación activaTanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+16712/5/202617/6/2026
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The…
AplazadaAlta (8.3)0.37%—TwentyAINodejsAINestjsAI5/5/202624/7/2026
Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-server's SecureHttpClientService can be bypassed using IPv4-mapped IPv6 addresses in URL IP literals. Node.js's URL parser normalizes IPv4-mapped IPv6 addresses to compressed hex form (e.g.,…
AnalizadaAlta (7.5)0.46%—Nestjs Nest21/4/202617/6/2026
Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.19, when an attacker sends many small, valid JSON messages in one TCP frame, handleData() recurses once per message; the buffer shrinks each call. maxBufferSize is never reached; call stack overflows instead. A ~47 KB payload is…
AnalizadaMedia (6.3)0.29%—Nestjs Nest7/4/202617/6/2026
Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.18, SseStream._transform() interpolates message.type and message.id directly into Server-Sent Events text protocol output without sanitizing newline characters (\r, \n). Since the SSE protocol treats both \r and \n as field…
AnalizadaAlta (8.7)0.47%—Nestjs Nest20/3/202617/6/2026
Nest is a framework for building scalable Node.js server-side applications. In versions 11.1.15 and below, a NestJS application using @nestjs/platform-fastify GET middleware can be bypassed because Fastify automatically redirects HEAD requests to the corresponding GET handlers (if they exist). As a result: middleware…
ModificadaAlta (8.2)0.68%—Nestjs Nest27/2/202615/7/2026
A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled. This issue affects nest.Js: 11.1.13.
AplazadaCrítica (9.3)0.29%—Teconcetheme Nestbyte CoreAI20/2/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Nestbyte Core nestbyte-core allows Blind SQL Injection.This issue affects Nestbyte Core: from n/a through <= 1.2.
AplazadaCrítica (9.8)0.39%—Boldthemes NestinAI20/2/202617/6/2026
Deserialization of Untrusted Data vulnerability in BoldThemes Nestin nestin allows Object Injection.This issue affects Nestin: from n/a through < 1.2.6.
AnalizadaMedia (5.3)0.27%—Nestersoft Worktime19/2/202617/6/2026
Any unauthenticated user can reset the WorkTime on-prem database configuration by sending a specific HTTP request to the WorkTime server. No authorization check is applied here.
AnalizadaMedia (6.1)0.16%—Nestersoft Worktime19/2/202617/6/2026
The server API endpoint /report/internet/urls reflects received data into the HTML response without applying proper encoding or filtering. This allows an attacker to execute arbitrary JavaScript in the victim's browser if the victim opens a URL prepared by the attacker.
AnalizadaAlta (7.8)0.11%—Nestersoft Worktime19/2/202617/6/2026
An attacker can exploit the update behavior of the WorkTime monitoring daemon to elevate privileges on the local system to NT Authority\SYSTEM. A malicious executable must be named WTWatch.exe and dropped in the C:\ProgramData\wta\ClientExe directory, which is writable by "Everyone". The executable will then be run by…
AnalizadaAlta (8.8)0.26%—Nestersoft Worktime19/2/202617/6/2026
An authenticated attacker with minimal permissions can exploit a SQL injection in the WorkTime server "widget" API endpoint to inject SQL queries. If the Firebird backend is used, attackers are able to retrieve all data from the database backend. If the MSSQL backend is used the attacker can execute arbitrary SQL…
AnalizadaCrítica (9.8)0.46%—Nestersoft Worktime19/2/202617/6/2026
An unauthenticated attacker can inject OS commands when calling a server API endpoint in NesterSoft WorkTime. The server API call to generate and download the WorkTime client from the WorkTime server is vulnerable in the “guid” parameter. This allows an attacker to execute arbitrary commands on the WorkTime server as…
AnalizadaMedia (6.9)0.38%—Nestjs Nest29/12/202517/6/2026
Nest is a framework for building scalable Node.js server-side applications. Versions prior to 11.1.11 have a Fastify URL encoding middleware bypass. A NestJS application is vulnerable if it uses `@nestjs/platform-fastify`; relies on `NestMiddleware` (via `MiddlewareConsumer`) for security checks (authentication,…
AplazadaCrítica (9.3)0.29%—Steelthemes Nest AddonsAI28/8/202525/9/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SteelThemes Nest Addons nest-addons allows SQL Injection.This issue affects Nest Addons: from n/a through <= 1.6.3.