Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 213 respecto a la semana anterior
Críticas / altas1376▲ 145 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)2.0%—Mihula ProdotnetzipDotnetzip.semverd Project Dotnetzip.semverd13/11/202417/6/2026
Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code via the src/Zip.Shared/ZipEntry.Extract.cs component NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
AnalizadaAlta (7.5)2.8%—Npmjs Semver21/6/202317/6/2026
Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
ModificadaAlta (7.8)1.1%—Semver-tags Project Semver-tags6/2/202317/6/2026
All versions of the package semver-tags are vulnerable to Command Injection via the getGitTagsRemote function due to improper input sanitization.
ModificadaAlta (7.5)1.5%—Semver-regex Project Semver-regex2/6/202217/6/2026
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method
ModificadaAlta (7.5)1.5%—Semver-regex Project Semver-regex15/9/202117/6/2026
semver-regex is vulnerable to Inefficient Regular Expression Complexity
ModificadaMedia (5.5)10%—Dotnetzip.semverd Project Dotnetzip.semverd25/7/201817/6/2026
DotNetZip.Semvered before 1.11.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.