Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3040▲ 560 respecto a la semana anterior
Críticas / altas1452▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
151 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.19% | — | ReactpressAI | 30/9/2026 | 30/9/2026 | The ReactPress – Create React App for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permalink' parameter in all versions up to, and including, 3.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.25% | — | Software Mansion React Native WorkletsAI | 25/9/2026 | 30/9/2026 | A prototype pollution vulnerability in Software Mansion React Native Worklets before 0.12.2 allows an attacker-controlled object containing a __proto__ property to modify the prototype of an object created during serialization in clonePlainJSObject in packages/react-native-worklets/src/memory/serializable.native.ts.… | |
| Aplazada | Baja (2.1) | 1.2% | — | Jhen0409 React-native-debuggerAI | 24/9/2026 | 25/9/2026 | A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function openDevTools of the file electron/window.js of the component Open in Editor Handler. The manipulation of the argument host results in os command injection. It is possible to launch the attack… | |
| Pendiente de análisis | Alta (7.5) | 0.53% | — | ReactpressAI | 22/9/2026 | 23/9/2026 | ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list endpoints build TypeORM `QueryBuilder` conditions using unsanitized HTTP query parameter names as SQL column identifiers (e.g. `` `article.${key}` ``). TypeORM parameterizes values but not column names, allowing… | |
| Aplazada | Media (5.1) | 0.35% | — | Novu JSAINovu ReactAI | 22/9/2026 | 24/9/2026 | Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu's @novu/js In-App Inbox and the @novu/react Inbox component accept a notification call-to-action redirect.url from the v1 cta.data object and pass it through apps/api/src/app/inbox/utils/notification-mapper.ts and… | |
| Pendiente de análisis | Alta (7.5) | 0.66% | — | Reactphp HttpAI | 16/9/2026 | 30/9/2026 | react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, React\Http\Io\ChunkedDecoder could enter an infinite loop while processing a malformed Transfer-Encoding: chunked body because handleData required its buffer to shrink on every iteration. An incomplete… | |
| Aplazada | Media (6.5) | 0.28% | — | React Native Auth0AI | 8/9/2026 | 10/9/2026 | The react-native-auth0 SDK's web platform implementation does not scope its in-memory token cache to individual user sessions when operating in a server-side rendering (SSR) environment where module state persists across HTTP requests. Under the listed preconditions, tokens cached in module memory can be retrieved… | |
| Analizada | Media (5.3) | 0.40% | — | Pivotal Reactor Netty | 27/8/2026 | 2/9/2026 | The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server to consume an excessive amount of memory. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier | |
| Analizada | Alta (7.5) | 0.40% | — | Broadcom Reactor Core | 27/8/2026 | 1/9/2026 | In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.7.19 and earlier | |
| Analizada | Media (5.9) | 0.37% | — | Broadcom Reactor Core | 27/8/2026 | 4/9/2026 | In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.5.0 - 3.7.19 Reactor Core 3.4.41 and earlier | |
| Analizada | Media (5.3) | 0.29% | — | Broadcom Reactor Netty | 27/8/2026 | 4/9/2026 | In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. In order for this to happen, the application must be configured to use HAProxy Protocol. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier | |
| Analizada | Media (6.1) | 0.26% | — | Broadcom Reactor Netty | 26/8/2026 | 4/9/2026 | In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty… | |
| Analizada | Baja (3.7) | 0.24% | — | Broadcom Reactor Netty | 26/8/2026 | 4/9/2026 | In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for this to happen, the server must be configured with Brave Tracing. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier | |
| Analizada | Baja (3.7) | 0.26% | — | Broadcom Reactor Netty | 26/8/2026 | 4/9/2026 | In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrectly reuse a previously configured DNS resolver. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier | |
| Aplazada | Media (5.3) | 0.55% | — | Element WEBAIMatrix React SDKAI | 21/8/2026 | 30/9/2026 | Element Web is a Matrix web client built using the Matrix React SDK. Prior to 1.12.22, EmbeddedPage in apps/web/src/components/structures/EmbeddedPage.tsx renders homeserver-supplied homepage content through dangerouslySetInnerHTML without passing it through sanitizedHtmlNode. A malicious homeserver can provide… | |
| Aplazada | Media (6) | 0.21% | — | ReactpressAI | 13/8/2026 | 14/8/2026 | Subscriber Broken Access Control in ReactPress <= 3.4.0 versions. | |
| Aplazada | Crítica (9.3) | 0.67% | — | React-trackedAI | 10/8/2026 | 9/9/2026 | react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the default branch contained malicious commits 6978272a7d6ca02225cb747ea69f427512e33699 through 949f1a3d6bb1ff7d1a0dec892afd773e742627e8 that executed remote attacker-controlled code on developer machines… | |
| Aplazada | Crítica (9.3) | 0.67% | — | React18-useAI | 10/8/2026 | 18/9/2026 | react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contained malicious commits 7b79148d1495a2505f9277da295a98cf176f4496 through 7b79148d1495a2505f9277da295a98cf176f4496 that executed remote attacker-controlled code on developer machines during `npm… | |
| Aplazada | Baja (1.9) | 0.17% | — | Azer React Analyzer MCPAI | 9/8/2026 | 12/8/2026 | A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected by this vulnerability is the function generateProjectDocs of the file src/index.ts of the component analyze-projec. The manipulation of the argument projectName results in path traversal. The attack… | |
| Aplazada | Baja (1.9) | 0.21% | — | Blix Email Blue Mail Calendar APPAIReact Native Receive Sharing IntentAI | 3/8/2026 | 12/8/2026 | A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the argument _display_name results in path traversal. The attack is only possible with… | |
| Analizada | Alta (8.7) | 0.71% | — | Shopify React-router | 27/7/2026 | 3/8/2026 | React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times. This issue is a follow up to CVE-2026-42342, and does not does not impact React Router applications… | |
| Analizada | Media (5.1) | 0.32% | — | Shopify React-router | 27/7/2026 | 3/8/2026 | React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in <Link> and useNavigate. This issue is a follow up to CVE-2025-68470 and has been fixed in version 7.18.0. | |
| Analizada | Media (6.9) | 0.34% | — | Shopify React-router | 27/7/2026 | 3/8/2026 | React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker could craft a malicious link that redirects users to an unexpected external site or that exploits an XSS vector.This issue has been fixed in version… | |
| Analizada | Media (6.1) | 0.36% | — | Shopify React-router | 27/7/2026 | 3/8/2026 | React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. This issue is a follow up to CVE-2026-53667, and only affects consuming applications if they are using the unstable RSC APIs. This issue has been… | |
| Analizada | Media (6.1) | 0.42% | — | Shopify React-router | 27/7/2026 | 3/8/2026 | React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for an attacker to trigger unexpected constructor execution on the client, which… |