Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2567▼ 298 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.61%—Perl TIE Hash RegexAI22/8/202627/8/2026
Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys. The FETCH, EXISTS and DELETE methods throw an exception when on malformed regular expressions. Each method falls back to a regex match when the key is not already stored in the hash, compiling the caller's key with a…
AplazadaBaja (1.9)0.11%—Kokke Tiny-regex-cAI8/6/202623/7/2026
A flaw has been found in kokke tiny-regex-c up to f2632c6d9ed25272987471cdb8b70395c2460bdb. This vulnerability affects the function matchstar of the file re.c of the component Pattern Handler. This manipulation causes inefficient regular expression complexity. The attack is restricted to local execution. The exploit…
AplazadaAlta (7.5)0.28%—Youtube-regexAI7/5/202617/6/2026
Regex Denial of Service in youtube-regex npm package through version 1.0.5.
ModificadaAlta (7.5)0.89%—Pillarjs Path-to-regexp26/3/20269/9/2026
Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of service. Patches: Fixed in version 8.4.0. Workarounds: Limit the number of sequential…
AnalizadaMedia (5.9)0.37%—Pillarjs Path-to-regexp26/3/202617/6/2026
Impact: When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires the second wildcard to be somewhere other than the end of the path. Unsafe examples: /*foo-*bar-:baz /*a-:b-*c-:d /x/*a-:b/*c/y Safe…
AnalizadaAlta (7.5)0.62%—Pillarjs Path-to-regexp26/3/202617/6/2026
Impact: A bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:a-:b-:c or /:a-:b-:c-:d. The backtrack protection added in path-to-regexp@0.1.12 only prevents ambiguity for two parameters. With three or…
AnalizadaMedia (5.6)0.28%—Malvineous Masseditregex3/7/202517/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MassEditRegex Extension allows Stored XSS.This issue affects Mediawiki - MassEditRegex Extension: from 1.39.X before 1.39.12, from 1.42.X before 1.42.7, from 1.43.X before…
AplazadaAlta (7.7)0.79%—Pillarjs Path-to-regexpAI5/12/202417/6/2026
path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to backtracking can be generated in the 0.1.x release of path-to-regexp. Upgrade to 0.1.12. This…
AnalizadaAlta (8.7)0.48%—Talyssonoc Commonregexjs26/10/202417/6/2026
CommonRegexJS is a CommonRegex port for JavaScript. All available versions contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.
AplazadaAlta (7.5)0.93%—Pillarjs Path-to-regexpAI9/9/202417/6/2026
path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will block the event loop and lead to a…
AnalizadaMedia (5.3)0.80%—Nescalante Urlregex2/9/202417/6/2026
A vulnerability was found in nescalante urlregex up to 0.5.0 and classified as problematic. This issue affects some unknown processing of the file index.js of the component Backtracking. The manipulation leads to inefficient regular expression complexity. The attack may be initiated remotely. The exploit has been…
ModificadaAlta (7.5)1.1%—Regexfn Project Regexfn27/6/202217/6/2026
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in regexfn v1.0.5 when validating crafted invalid emails.
ModificadaAlta (7.5)1.1%—Todo-regex Project Todo-regex27/6/202217/6/2026
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in todo-regex v0.1.1 when matching crafted invalid TODO statements.
ModificadaAlta (7.5)1.5%—Semver-regex Project Semver-regex2/6/202217/6/2026
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method
ModificadaAlta (7.5)1.3%—Url-regex Project Url-regex20/5/202217/6/2026
All versions of package url-regex are vulnerable to Regular Expression Denial of Service (ReDoS) which can cause the CPU usage to crash.
ModificadaAlta (7.5)14%—Rust-lang RegexFedoraproject FedoraDebian Linux8/3/202217/6/2026
regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This…
ModificadaAlta (7.5)3.6%—Ansi-regex Project Ansi-regexOracle Communications Cloud Native Core Policy17/9/202117/6/2026
ansi-regex is vulnerable to Inefficient Regular Expression Complexity
ModificadaAlta (7.5)1.5%—Semver-regex Project Semver-regex15/9/202117/6/2026
semver-regex is vulnerable to Inefficient Regular Expression Complexity
ModificadaAlta (7.5)2.7%—Url-regex Project Url-regex4/6/202017/6/2026
all versions of url-regex are vulnerable to Regular Expression Denial of Service. An attacker providing a very long string in String.test can cause a Denial of Service.
ModificadaAlta (7.5)2.4%—Irregex Project Irregex21/4/201717/6/2026
The backtrack compilation code in the Irregex package (aka IrRegular Expressions) before 0.9.6 for Scheme allows remote attackers to cause a denial of service (memory consumption) via a crafted regular expression with a repeating pattern.
ModificadaMedia (5)2.7%—BoostBoost Regex Library17/1/200816/6/2026
regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed assertion and crash) via an invalid regular expression.