Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 296 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
90 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.33% | — | Kylephillips Nested PagesAI | 30/9/2026 | 30/9/2026 | Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions. | |
| Pendiente de análisis | Alta (7.5) | 0.38% | — | Nestjs NestAI | 28/9/2026 | 30/9/2026 | Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0.2, a single message with a deeply nested object in its pattern can terminate a NestJS microservice using the TCP or RabbitMQ transport. ServerTCP#handleMessage and ServerRMQ#handleMessage pass a client-controlled… | |
| Aplazada | Media (6.4) | 0.21% | — | Ashstonestudios Advanced PopupsAI | 16/9/2026 | 16/9/2026 | The Advanced Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Notification Button Link' Field in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to… | |
| Aplazada | Alta (7.5) | 0.50% | — | Flat-to-nestedAI | 14/9/2026 | 30/9/2026 | flat-to-nested converts a hierarchy from a flat representation to a nested representation. Prior to 1.1.2, FlatToNested.prototype.convert in index.js uses attacker-influenced id and parent record fields directly as keys in the plain temp and pendingChildOf objects. When parent or id is __proto__, temp[parent] can… | |
| Aplazada | Media (5.1) | 0.40% | — | Elenavanengelenmaslova Mocknest-serverlessAI | 8/9/2026 | 23/9/2026 | A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC Deployment Helper Script. Performing a manipulation results in improper privilege management. It is… | |
| Analizada | Crítica (10) | 0.21% | — | Google Nest Wifi Router FirmwareGoogle Nest Wifi Point FirmwareGoogle Nest Wifi PRO Firmware | 24/8/2026 | 29/9/2026 | Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a denial of service. These issues include triggerable assertion failures and a stack-based buffer overflow. | |
| Aplazada | Media (4.8) | 0.24% | — | Kylephillips Nested PagesAI | 4/8/2026 | 26/8/2026 | The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML attributes on an administrative listing screen, allowing users with the Editor role (or Contributor/Author when the Nested Pages WordPress plugin before 3.2.15 is enabled for the post type) to inject… | |
| Pendiente de análisis | Crítica (10) | 0.77% | — | Beproduct Nestjs-authAI | 20/7/2026 | 23/7/2026 | @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions of `@beproduct/nestjs-auth` (0.1.2 through 0.1.19). The postinstall… | |
| Aplazada | Alta (8.7) | 0.50% | — | Nestjs Platform-fastifyAI | 22/6/2026 | 24/6/2026 | Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.24, an authentication bypass vulnerability exists in @nestjs/platform-fastify. When middleware is registered through NestJS's MiddlewareConsumer.forRoutes() API on the Fastify adapter, an unauthenticated client can bypass the… | |
| Aplazada | Alta (8.2) | 0.56% | — | Parse-nested-form-dataAI | 1/6/2026 | 22/7/2026 | parse-nested-form-data is a tiny node module for parsing FormData by name into objects and arrays. Prior to version 1.0.1, parseFormData() walks bracket and dot-notation FormData field names into nested objects without filtering reserved property keys. A single FormData field whose name begins with __proto__, or… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Aplazada | Alta (8.3) | 0.37% | — | TwentyAINodejsAINestjsAI | 5/5/2026 | 24/7/2026 | Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-server's SecureHttpClientService can be bypassed using IPv4-mapped IPv6 addresses in URL IP literals. Node.js's URL parser normalizes IPv4-mapped IPv6 addresses to compressed hex form (e.g.,… | |
| Analizada | Alta (7.5) | 0.46% | — | Nestjs Nest | 21/4/2026 | 17/6/2026 | Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.19, when an attacker sends many small, valid JSON messages in one TCP frame, handleData() recurses once per message; the buffer shrinks each call. maxBufferSize is never reached; call stack overflows instead. A ~47 KB payload is… | |
| Analizada | Media (6.3) | 0.29% | — | Nestjs Nest | 7/4/2026 | 17/6/2026 | Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.18, SseStream._transform() interpolates message.type and message.id directly into Server-Sent Events text protocol output without sanitizing newline characters (\r, \n). Since the SSE protocol treats both \r and \n as field… | |
| Analizada | Alta (8.7) | 0.47% | — | Nestjs Nest | 20/3/2026 | 17/6/2026 | Nest is a framework for building scalable Node.js server-side applications. In versions 11.1.15 and below, a NestJS application using @nestjs/platform-fastify GET middleware can be bypassed because Fastify automatically redirects HEAD requests to the corresponding GET handlers (if they exist). As a result: middleware… | |
| Modificada | Alta (8.2) | 0.68% | — | Nestjs Nest | 27/2/2026 | 15/7/2026 | A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled. This issue affects nest.Js: 11.1.13. | |
| Aplazada | Crítica (9.3) | 0.29% | — | Teconcetheme Nestbyte CoreAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Nestbyte Core nestbyte-core allows Blind SQL Injection.This issue affects Nestbyte Core: from n/a through <= 1.2. | |
| Aplazada | Crítica (9.8) | 0.39% | — | Boldthemes NestinAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in BoldThemes Nestin nestin allows Object Injection.This issue affects Nestin: from n/a through < 1.2.6. | |
| Analizada | Media (5.3) | 0.27% | — | Nestersoft Worktime | 19/2/2026 | 17/6/2026 | Any unauthenticated user can reset the WorkTime on-prem database configuration by sending a specific HTTP request to the WorkTime server. No authorization check is applied here. | |
| Analizada | Media (6.1) | 0.16% | — | Nestersoft Worktime | 19/2/2026 | 17/6/2026 | The server API endpoint /report/internet/urls reflects received data into the HTML response without applying proper encoding or filtering. This allows an attacker to execute arbitrary JavaScript in the victim's browser if the victim opens a URL prepared by the attacker. | |
| Analizada | Alta (7.8) | 0.11% | — | Nestersoft Worktime | 19/2/2026 | 17/6/2026 | An attacker can exploit the update behavior of the WorkTime monitoring daemon to elevate privileges on the local system to NT Authority\SYSTEM. A malicious executable must be named WTWatch.exe and dropped in the C:\ProgramData\wta\ClientExe directory, which is writable by "Everyone". The executable will then be run by… | |
| Analizada | Alta (8.8) | 0.26% | — | Nestersoft Worktime | 19/2/2026 | 17/6/2026 | An authenticated attacker with minimal permissions can exploit a SQL injection in the WorkTime server "widget" API endpoint to inject SQL queries. If the Firebird backend is used, attackers are able to retrieve all data from the database backend. If the MSSQL backend is used the attacker can execute arbitrary SQL… | |
| Analizada | Crítica (9.8) | 0.46% | — | Nestersoft Worktime | 19/2/2026 | 17/6/2026 | An unauthenticated attacker can inject OS commands when calling a server API endpoint in NesterSoft WorkTime. The server API call to generate and download the WorkTime client from the WorkTime server is vulnerable in the “guid” parameter. This allows an attacker to execute arbitrary commands on the WorkTime server as… | |
| Analizada | Media (6.9) | 0.38% | — | Nestjs Nest | 29/12/2025 | 17/6/2026 | Nest is a framework for building scalable Node.js server-side applications. Versions prior to 11.1.11 have a Fastify URL encoding middleware bypass. A NestJS application is vulnerable if it uses `@nestjs/platform-fastify`; relies on `NestMiddleware` (via `MiddlewareConsumer`) for security checks (authentication,… | |
| Aplazada | Crítica (9.3) | 0.29% | — | Steelthemes Nest AddonsAI | 28/8/2025 | 25/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SteelThemes Nest Addons nest-addons allows SQL Injection.This issue affects Nest Addons: from n/a through <= 1.6.3. |