Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 213 respecto a la semana anterior
Críticas / altas1376▲ 145 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 2.0% | — | Mihula ProdotnetzipDotnetzip.semverd Project Dotnetzip.semverd | 13/11/2024 | 17/6/2026 | Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code via the src/Zip.Shared/ZipEntry.Extract.cs component NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |
| Analizada | Alta (7.5) | 2.8% | — | Npmjs Semver | 21/6/2023 | 17/6/2026 | Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range. | |
| Modificada | Alta (7.8) | 1.1% | — | Semver-tags Project Semver-tags | 6/2/2023 | 17/6/2026 | All versions of the package semver-tags are vulnerable to Command Injection via the getGitTagsRemote function due to improper input sanitization. | |
| Modificada | Alta (7.5) | 1.5% | — | Semver-regex Project Semver-regex | 2/6/2022 | 17/6/2026 | An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method | |
| Modificada | Alta (7.5) | 1.5% | — | Semver-regex Project Semver-regex | 15/9/2021 | 17/6/2026 | semver-regex is vulnerable to Inefficient Regular Expression Complexity | |
| Modificada | Media (5.5) | 10% | — | Dotnetzip.semverd Project Dotnetzip.semverd | 25/7/2018 | 17/6/2026 | DotNetZip.Semvered before 1.11.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'. |