Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3019▲ 545 respecto a la semana anterior
Críticas / altas1439▲ 265 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

29 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.8)0.45%—QuickjsAI24/9/202629/9/2026
QuickJS commit 04be24600 contains a heap out-of-bounds write condition in JS_ReadFunctionTag().
Pendiente de análisisCrítica (9.2)0.76%—Nginx NJSAINginxAIBellard QuickjsAI2/9/20263/9/2026
Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method.…
Pendiente de análisisAlta (8.8)0.38%—Nginx NJSAIQuickjs QJSAI2/9/20263/9/2026
Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous access-control evaluation before an explicit access denial is returned. An unauthenticated attacker can exploit this…
AnalizadaCrítica (9)0.57%—Delskayn RquickjsSurrealdb18/7/202613/8/2026
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.
AplazadaAlta (7.3)0.40%—Quickjs-ngAI11/5/202617/6/2026
An issue in QuickJS-NG v.0.12.1 allows an attacker to execute arbitrary code via the js_mapped_arguments_mark function
AplazadaBaja (1.9)0.16%—Quickjs-ng QuickjsAI12/3/202617/6/2026
A flaw has been found in quickjs-ng quickjs up to 0.12.1. This affects the function js_iterator_concat_return of the file quickjs.c. This manipulation causes use after free. The attack requires local access. The exploit has been published and may be used. Patch name: daab4ad4bae4ef071ed0294618d6244e92def4cd. Applying…
AnalizadaAlta (7.5)0.28%—Quickjs Project Quickjs6/3/202617/6/2026
A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a3877454f6b3 (2025-12-11),`qjs` interpreter using the `-m` option and a low memory limit can cause an out-of-memory condition followed by an assertion failure in JS_FreeRuntime…
AnalizadaMedia (6.5)0.21%—Quickjs Project Quickjs6/3/202617/6/2026
A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbba8a88eaa40d15a8a9b70bb1a0b8fb5b552e6 (2025-12-11), in file gc_decref_child in quickjs.c, when executed with the qjs interpreter using the -m option. This leads to an abort (SIGABRT) during garbage…
AplazadaMedia (5.5)0.15%—MquickjsAI10/2/202617/6/2026
An issue in mquickjs before commit 74b7e (2026-01-15) allows a local attacker to cause a denial of service via a crafted file to the get_mblock_size function at mquickjs.c.
ModificadaBaja (2.1)0.40%—Quickjs-ng Quickjs19/1/202617/6/2026
A flaw has been found in quickjs-ng quickjs up to 0.11.0. Affected by this vulnerability is the function js_typed_array_constructor_ta of the file quickjs.c. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch…
ModificadaBaja (2.1)0.41%—Quickjs-ng Quickjs19/1/202617/6/2026
A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the file quickjs.c of the component Atomics Ops Handler. The manipulation results in use after free. The attack can be executed remotely. The exploit is now public and may be used. The patch is identified as…
ModificadaBaja (2.1)0.46%—Quickjs-ng Quickjs10/1/202617/6/2026
A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function js_typed_array_sort of the file quickjs.c. The manipulation leads to heap-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the…
ModificadaMedia (5.5)0.50%—Quickjs-ng Quickjs10/1/202617/6/2026
A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_array_constructor of the file quickjs.c. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.…
AnalizadaBaja (1.9)0.20%—Bellard Quickjs5/11/202517/6/2026
A weakness has been identified in QuickJS up to eb2c89087def1829ed99630cb14b549d7a98408c. This affects the function js_array_buffer_slice of the file quickjs.c. This manipulation causes buffer over-read. The attack is restricted to local execution. The exploit has been made available to the public and could be…
AnalizadaAlta (7.1)0.48%—Quickjs Project Quickjs16/10/202517/6/2026
A vulnerability exists in the QuickJS engine's BigInt string parsing logic (js_bigint_from_string) when attempting to create a BigInt from a string with an excessively large number of digits. The function calculates the necessary number of bits (n_bits) required to store the BigInt using the formula: $$\text{n\_bits}…
AnalizadaAlta (7.1)0.46%—Quickjs Project Quickjs16/10/202517/6/2026
An integer overflow vulnerability exists in the QuickJS regular expression engine (libregexp) due to an inconsistent representation of the bytecode buffer size.
AnalizadaAlta (7.1)0.51%—Quickjs Project Quickjs16/10/202517/6/2026
A type confusion vulnerability exists in the handling of the string addition (+) operation within the QuickJS engine. This mismatch between the assumed type (string) and the actual type allows an attacker to control the data structure being processed by the concatenation logic, resulting in a type confusion condition.…
AnalizadaMedia (5.9)0.38%—Quickjs Project Quickjs16/10/202517/6/2026
A vulnerability exists in the QuickJS engine's BigInt string conversion logic (js_bigint_to_string1) due to an incorrect calculation of the required number of digits, which in turn leads to reading memory past the allocated BigInt structure. $$ \\ \text{n\_digits} = (\text{n\_bits} + \text{log2\_radix} - 1) /…
AnalizadaMedia (5.9)0.39%—Quickjs Project Quickjs16/10/202517/6/2026
A vulnerability stemming from floating-point arithmetic precision errors exists in the QuickJS engine's implementation of TypedArray.prototype.indexOf() when a negative fromIndex argument is supplied. $$d_{new} = d + \text{len}$$ This allows an attacker to cause an Out-of-Bounds Read of one element immediately…
AnalizadaAlta (8.8)0.41%—Quickjs Project Quickjs16/10/202517/6/2026
A Use-After-Free (UAF) vulnerability exists in the QuickJS engine's standard library when iterating over the global list of unhandled rejected promises (ts->rejected_promise_list).
AnalizadaAlta (8.8)0.41%—Quickjs Project Quickjs16/10/202517/6/2026
In quickjs, in js_print_object, when printing an array, the function first fetches the array length and then loops over it. The issue is, printing a value is not side-effect free. An attacker-defined callback could run during js_print_value, during which the array could get resized and len1 become out of bounds. This…
AnalizadaAlta (8.4)0.32%—Quickjs-ng QuickjsQuickjs Project Quickjs27/4/202517/6/2026
quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.
AnalizadaAlta (7.8)0.30%—Bellard QuickjsQuickjs-ng Quickjs27/4/202517/6/2026
quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.
AnalizadaMedia (5.3)0.70%—Quickjs-ng Quickjs21/3/202517/6/2026
A vulnerability was found in quickjs-ng QuickJS up to 0.8.0. It has been declared as problematic. Affected by this vulnerability is the function JS_GetRuntime of the file quickjs.c of the component qjs. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. Upgrading to version…
AnalizadaMedia (4)0.32%—Bellard Quickjs14/5/202417/6/2026
QuickJS commit 3b45d15 was discovered to contain an Assertion Failure via JS_FreeRuntime(JSRuntime *) at quickjs.c.