Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2543▼ 416 respecto a la semana anterior
Críticas / altas1316▲ 27 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.40% | — | Hickory-resolverAI | 18/9/2026 | 22/9/2026 | hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records… | |
| Aplazada | Alta (8.7) | 0.85% | — | Resolver PerspectiveAI | 4/8/2026 | 9/9/2026 | Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files from the server filesystem by including literal ../ segments in HTTP request URL paths. Attackers can bypass the insufficient query-string-stripping sanitization to traverse outside the… | |
| Aplazada | Alta (7.1) | 0.52% | — | Resolver PerspectiveAI | 4/8/2026 | 9/9/2026 | Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a crafted expression containing unbounded for or while loop constructs in a TableMakeViewReq message. Attackers can embed an arbitrarily large iteration count in an… | |
| Aplazada | Alta (8.7) | 0.29% | — | Resolver PerspectiveAI | 4/8/2026 | 9/9/2026 | Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthenticated remote attackers to crash the server process by sending malformed or incomplete protobuf messages. Attackers can send well-formed requests such as ViewToArrowReq with no viewport set or… | |
| Aplazada | Media (5.1) | 0.26% | — | Resolver PerspectiveAI | 4/8/2026 | 9/9/2026 | Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to inject arbitrary HTML and JavaScript by writing table cell values containing unescaped HTML markup, which are interpolated directly into innerHTML during CSV serialization rendering. Attackers can… | |
| Aplazada | Alta (8.7) | 1.2% | — | Resolver PerspectiveAI | 4/8/2026 | 9/9/2026 | Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the PolarsVirtualServer backend, which passes client-supplied input directly to Python's eval() with only __builtins__={}… | |
| Aplazada | Alta (8.1) | 0.62% | — | Knot ResolverAI | 25/7/2026 | 30/7/2026 | Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path. | |
| Aplazada | Alta (7.5) | 0.49% | — | FlaresolverrAI | 20/7/2026 | 21/7/2026 | FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. This allows a remote attacker to obtain sensitive information | |
| Aplazada | Alta (8.9) | 0.63% | — | Intlify Message ResolverAIIntlify VUE I18n CoreAIVuejs VUE I18nAI | 7/3/2025 | 17/6/2026 | Vue I18n is the internationalization plugin for Vue.js. @intlify/message-resolver and @intlify/vue-i18n-core are vulnerable to Prototype Pollution through the entry function: handleFlatJson. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype… | |
| Aplazada | Alta (8.3) | 0.42% | — | Apphp Js-object-resolverAI | 17/6/2024 | 17/6/2026 | apphp js-object-resolver < 3.1.1 is vulnerable to Prototype Pollution via Module.setNestedProperty. | |
| Modificada | Alta (7.5) | 100% | — | Redhat Enterprise LinuxMicrosoft Windows Server 2008Microsoft Windows Server 2012Microsoft Windows Server 2016+9 | 14/2/2024 | 17/6/2026 | Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the… | |
| Modificada | Alta (7.5) | 1.3% | — | Apache Sling Servlets Resolver | 6/2/2024 | 17/6/2026 | Malicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affects all version of Apache Sling Servlets Resolver before 2.11.0. However, whether a system is vulnerable to this attack depends on the exact configuration of the system. If the system is vulnerable,… | |
| Modificada | Alta (7.5) | 0.64% | — | NIC Knot Resolver | 22/10/2023 | 17/6/2026 | Knot Resolver before 5.7.0 performs many TCP reconnections upon receiving certain nonsensical responses from servers. | |
| Modificada | Alta (7.5) | 0.71% | — | NIC Knot Resolver | 21/2/2023 | 17/6/2026 | Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of service. Specifically, a single client query may lead to a hundred TCP connection attempts if a DNS server closes connections without providing a response. | |
| Modificada | Alta (7.5) | 0.24% | — | Go-resolver Project Go-resolver | 28/12/2022 | 17/6/2026 | DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. Root DNSSEC public keys are not validated, permitting an attacker to present a self-signed root key and delegation chain. | |
| Modificada | Media (6.5) | 0.23% | — | Go-resolver Project Go-resolver | 28/12/2022 | 17/6/2026 | DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. The owner name of RRSIG RRs is not validated, permitting an attacker to present the RRSIG for an attacker-controlled domain in a response for any other domain. | |
| Modificada | Alta (7.5) | 1.9% | — | NIC Knot ResolverFedoraproject FedoraDebian Linux | 23/9/2022 | 17/6/2026 | Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must return large NS sets or address sets. | |
| Modificada | Media (5.3) | 0.74% | — | NIC Knot Resolver | 20/6/2022 | 17/6/2026 | Knot Resolver through 5.5.1 may allow DNS cache poisoning when there is an attempt to limit forwarding actions by filters. | |
| Modificada | Alta (7.5) | 1.4% | — | NIC Knot Resolver | 25/8/2021 | 17/6/2026 | Knot Resolver before 5.3.2 is prone to an assertion failure, triggerable by a remote attacker in an edge case (NSEC3 with too many iterations used for a positive wildcard proof). | |
| Modificada | Crítica (9.8) | 2.9% | — | Pac-resolver Project Pac-resolver | 24/8/2021 | 17/6/2026 | This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC file handling. **NOTE:** The fix for this vulnerability is applied in the node-degenerator library, a dependency written by the same maintainer. | |
| Modificada | Alta (7.5) | 1.2% | — | NIC Knot Resolver | 30/3/2021 | 17/6/2026 | A flaw was found in knot-resolver before version 2.3.0. Malformed DNS messages may cause denial of service. | |
| Modificada | Alta (7.5) | 2.6% | — | NIC Knot Resolver | 19/5/2020 | 17/6/2026 | Knot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records. | |
| Modificada | Media (5.9) | 0.78% | — | Postfix-mta-sts-resolver Project Postfix-mta-sts-resolver | 22/1/2020 | 17/6/2026 | In postfix-mta-sts-resolver before 0.5.1, All users can receive incorrect response from daemon under rare conditions, rendering downgrade of effective STS policy. | |
| Modificada | Alta (7.5) | 2.2% | — | NIC Knot ResolverDebian Linux | 16/12/2019 | 17/6/2026 | knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might be processed very inefficiently, in extreme cases taking even several CPU seconds for each such uncached message. For example, a few thousand A records can be squashed… | |
| Modificada | Media (5.9) | 3.5% | — | ISC BindNlnetlabs NSDNIC Knot ResolverRedhat Enterprise Linux | 5/11/2019 | 16/6/2026 | Cache Poisoning issue exists in DNS Response Rate Limiting. |