Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1338▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 1.2% | — | Jhen0409 React-native-debuggerAI | 24/9/2026 | 25/9/2026 | A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function openDevTools of the file electron/window.js of the component Open in Editor Handler. The manipulation of the argument host results in os command injection. It is possible to launch the attack… | |
| Aplazada | Alta (7) | 0.19% | — | React-native-receive-sharing-intentAI | 2/7/2026 | 14/7/2026 | react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-resident malicious application to write files outside the intended cache directory by supplying a crafted _display_name value containing dot-dot path components through a malicious ContentProvider. Attackers can fire an… | |
| Analizada | Crítica (9.8) | 94% | ⚠ Explotación activa | React-native-community React Native Community CLI | 3/11/2025 | 17/6/2026 | The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On… | |
| Analizada | Alta (7.5) | 0.19% | — | Numan React-native-keys | 9/6/2025 | 17/6/2026 | react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as plaintext in the compiled native binary. Attackers can extract these secrets using basic static analysis tools. | |
| Analizada | Alta (7.8) | 0.53% | — | React-native-documents Document Picker | 16/2/2024 | 17/6/2026 | Directory Traversal vulnerability in React Native Document Picker before v.9.1.1 and fixed in v.9.1.1 allows a local attacker to execute arbitrary code via a crafted script to the Android library component. | |
| Modificada | Media (4.9) | 0.38% | — | Mrousavy React-native-mmkv | 9/1/2024 | 17/6/2026 | react-native-mmkv is a library that allows easy use of MMKV inside React Native applications. Before version 2.11.0, the react-native-mmkv logged the optional encryption key for the MMKV database into the Android system log. The key can be obtained by anyone with access to the Android Debugging Bridge (ADB) if it is… | |
| Modificada | Alta (8.1) | 0.91% | — | React-native-onesignal | 27/3/2023 | 17/6/2026 | OneSignal is an email, sms, push notification, and in-app message service for mobile apps.The Zapier.yml workflow is triggered on issues (types: [closed]) (i.e., when an Issue is closed). The workflow starts with full write-permissions GitHub repository token since the default workflow permissions on… | |
| Modificada | Alta (7.5) | 1.4% | — | Facebook React-native | 1/6/2021 | 17/6/2026 | A regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cause the application to use excessive resources, become unresponsive, or crash. This was introduced in react-native version 0.59.0 and fixed in version 0.64.1. | |
| Modificada | Media (5.3) | 1.6% | — | React-native-fast-image Project React-native-fast-image | 17/7/2020 | 17/6/2026 | This affects all versions of package react-native-fast-image. When an image with source={{uri: "...", headers: { host: "somehost.com", authorization: "..." }} is loaded, all other subsequent images will use the same headers, this can lead to signing credentials or other session tokens being leaked to other servers. | |
| Modificada | Alta (8.1) | 1.8% | — | React-native-baidu-voice-synthesizer Project React-native-baidu-voice-synthesizer | 4/6/2018 | 17/6/2026 | react-native-baidu-voice-synthesizer is a baidu voice speech synthesizer for react native. react-native-baidu-voice-synthesizer downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker… |