Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.5%—Rollupjs Rollup25/2/202610/9/2026
Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure file name sanitization in the core engine allows an attacker to control output…
AplazadaAlta (8.8)0.41%—Error-exAIBabelAINext.jsAIRollupjs RollupAI+115/9/202517/6/2026
error-ex allows error subclassing and stack customization. On 8 September 2025, an npm publishing account for error-ex was taken over after a phishing attack. Version 1.3.3 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency…
AplazadaAlta (8.8)0.41%—Simple-swizzleAIBabelAIVercel Next.jsAIRollupjs RollupAI+115/9/202517/6/2026
simple-swizzle swizzles function arguments. On 8 September 2025, the npm publishing account for simple-swizzle was taken over after a phishing attack. Version 0.2.3 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions…
AplazadaAlta (8.8)0.41%—BacklashAINPMAIBabelAIVercel Next.jsAI+215/9/202517/6/2026
backlash parses collected strings with escapes. On 8 September 2025, the npm publishing account for backslash was taken over after a phishing attack. Version 0.2.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to…
AplazadaAlta (8.8)0.55%—Color-nameAIBabelAIVercel Next.jsAIRollupjs RollupAI+115/9/202530/9/2026
color-name is a JSON with CSS color names. On 8 September 2025, an npm publishing account for color-name was taken over after a phishing attack. Version 2.0.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the…
AplazadaMedia (6)0.42%—Vite-plugin-static-copyAIRollup-plugin-copyAI21/8/202517/6/2026
vite-plugin-static-copy is rollup-plugin-copy for Vite with dev server support. Files not included in src are accessible with a crafted request. The vulnerability is fixed in 2.3.2 and 3.1.2.
AplazadaMedia (6.5)0.32%—ScrollupAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in midori scrollup scrollup allows DOM-Based XSS.This issue affects scrollup: from n/a through <= 1.1.
ModificadaMedia (6.1)0.74%—Rollupjs Rollup23/9/202417/6/2026
Rollup is a module bundler for JavaScript. Versions prior to 2.79.2, 3.29.5, and 4.22.4 are susceptible to a DOM Clobbering vulnerability when bundling scripts with properties from `import.meta` (e.g., `import.meta.url`) in `cjs`/`umd`/`iife` format. The DOM Clobbering gadget can lead to cross-site scripting (XSS) in…
ModificadaAlta (7.5)1.8%—Rollup-plugin-dev-server Project Rollup-plugin-dev-server25/7/202017/6/2026
This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation inside the readFileFromContentBase function.
ModificadaAlta (7.5)1.8%—Rollup-plugin-server Project Rollup-plugin-server25/7/202017/6/2026
This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed inside the readFileFromContentBase function.
ModificadaCrítica (9.8)1.5%—Rollup-plugin-serve Project Rollup-plugin-serve17/7/202017/6/2026
This affects all versions of package rollup-plugin-serve. There is no path sanitization in readFile operation.
ModificadaMedia (5.4)1.5%—Microsoft Windows Azure Pack Rollup12/12/201817/6/2026
A Cross-site Scripting (XSS) vulnerability exists when Windows Azure Pack does not properly sanitize user-provided input, aka "Windows Azure Pack Cross Site Scripting Vulnerability." This affects Windows Azure Pack Rollup 13.1.