Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.5% | — | Rollupjs Rollup | 25/2/2026 | 10/9/2026 | Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure file name sanitization in the core engine allows an attacker to control output… | |
| Aplazada | Alta (8.8) | 0.41% | — | Error-exAIBabelAINext.jsAIRollupjs RollupAI+1 | 15/9/2025 | 17/6/2026 | error-ex allows error subclassing and stack customization. On 8 September 2025, an npm publishing account for error-ex was taken over after a phishing attack. Version 1.3.3 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency… | |
| Aplazada | Alta (8.8) | 0.41% | — | Simple-swizzleAIBabelAIVercel Next.jsAIRollupjs RollupAI+1 | 15/9/2025 | 17/6/2026 | simple-swizzle swizzles function arguments. On 8 September 2025, the npm publishing account for simple-swizzle was taken over after a phishing attack. Version 0.2.3 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions… | |
| Aplazada | Alta (8.8) | 0.41% | — | BacklashAINPMAIBabelAIVercel Next.jsAI+2 | 15/9/2025 | 17/6/2026 | backlash parses collected strings with escapes. On 8 September 2025, the npm publishing account for backslash was taken over after a phishing attack. Version 0.2.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to… | |
| Aplazada | Alta (8.8) | 0.55% | — | Color-nameAIBabelAIVercel Next.jsAIRollupjs RollupAI+1 | 15/9/2025 | 30/9/2026 | color-name is a JSON with CSS color names. On 8 September 2025, an npm publishing account for color-name was taken over after a phishing attack. Version 2.0.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the… | |
| Aplazada | Media (6) | 0.42% | — | Vite-plugin-static-copyAIRollup-plugin-copyAI | 21/8/2025 | 17/6/2026 | vite-plugin-static-copy is rollup-plugin-copy for Vite with dev server support. Files not included in src are accessible with a crafted request. The vulnerability is fixed in 2.3.2 and 3.1.2. | |
| Aplazada | Media (6.5) | 0.32% | — | ScrollupAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in midori scrollup scrollup allows DOM-Based XSS.This issue affects scrollup: from n/a through <= 1.1. | |
| Modificada | Media (6.1) | 0.74% | — | Rollupjs Rollup | 23/9/2024 | 17/6/2026 | Rollup is a module bundler for JavaScript. Versions prior to 2.79.2, 3.29.5, and 4.22.4 are susceptible to a DOM Clobbering vulnerability when bundling scripts with properties from `import.meta` (e.g., `import.meta.url`) in `cjs`/`umd`/`iife` format. The DOM Clobbering gadget can lead to cross-site scripting (XSS) in… | |
| Modificada | Alta (7.5) | 1.8% | — | Rollup-plugin-dev-server Project Rollup-plugin-dev-server | 25/7/2020 | 17/6/2026 | This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation inside the readFileFromContentBase function. | |
| Modificada | Alta (7.5) | 1.8% | — | Rollup-plugin-server Project Rollup-plugin-server | 25/7/2020 | 17/6/2026 | This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed inside the readFileFromContentBase function. | |
| Modificada | Crítica (9.8) | 1.5% | — | Rollup-plugin-serve Project Rollup-plugin-serve | 17/7/2020 | 17/6/2026 | This affects all versions of package rollup-plugin-serve. There is no path sanitization in readFile operation. | |
| Modificada | Media (5.4) | 1.5% | — | Microsoft Windows Azure Pack Rollup | 12/12/2018 | 17/6/2026 | A Cross-site Scripting (XSS) vulnerability exists when Windows Azure Pack does not properly sanitize user-provided input, aka "Windows Azure Pack Cross Site Scripting Vulnerability." This affects Windows Azure Pack Rollup 13.1. |