Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2719▼ 93 respecto a la semana anterior
Críticas / altas1415▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (2.3) | 0.30% | — | Serialize JavascriptAI | 29/9/2026 | 30/9/2026 | Serialize JavaScript serializes JavaScript values to a superset of JSON that includes regular expressions and functions. From 7.1.1 until 7.1.2, function values serialized by serialize-javascript are not fully protected against script-closing tags in attacker-influenced function source because SCRIPT_CLOSE_REGEXP can… | |
| Analizada | Alta (7.5) | 0.49% | — | Fastify/accepts-serializer | 4/5/2026 | 17/6/2026 | @fastify/accepts-serializer cached serializer-selection results keyed by the request Accept header without a size limit or eviction policy. A remote unauthenticated client could send many distinct but matching Accept header variants to make the cache grow unbounded, eventually exhausting the Node.js heap and crashing… | |
| Analizada | Alta (7.5) | 0.58% | — | Yahoo Serialize | 31/3/2026 | 17/6/2026 | Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial of Service (DoS) vulnerability caused by CPU exhaustion. When serializing a specially crafted "array-like" object (an object that inherits from Array.prototype but has a very large… | |
| Aplazada | Alta (8.1) | 1.0% | — | Zumba Json SerializerAI | 21/2/2026 | 17/6/2026 | Zumba Json Serializer is a library to serialize PHP variables in JSON format. In versions 3.2.2 and below, the library allows deserialization of PHP objects from JSON using a special @type field. The deserializer instantiates any class specified in the @type field without restriction. When processing untrusted JSON… | |
| Aplazada | Media (5.4) | 1.1% | — | Verizon Serialize-javascriptAI | 10/2/2025 | 1/10/2026 | A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser,… | |
| Aplazada | Media (6.3) | 0.42% | — | Harvey-woo Key-serializerAI | 1/7/2024 | 17/6/2026 | harvey-woo cat5th/key-serializer v0.2.5 was discovered to contain a prototype pollution via the function "query". This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. | |
| Modificada | Alta (8.1) | 3.0% | — | Verizon Serialize-javascript | 1/6/2020 | 17/6/2026 | serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js". | |
| Modificada | Media (6.1) | 0.65% | — | Serialize-to-js Project Serialize-to-js | 7/12/2019 | 17/6/2026 | The serialize-to-js NPM package before version 3.0.1 is vulnerable to Cross-site Scripting (XSS). It does not properly mitigate against unsafe characters in serialized regular expressions. This vulnerability is not affected on Node.js environment since Node.js's implementation of RegExp.prototype.toString()… | |
| Modificada | Media (5.4) | 0.80% | — | Verizon Serialize-javascript | 5/12/2019 | 17/6/2026 | The serialize-javascript npm package before version 2.1.1 is vulnerable to Cross-site Scripting (XSS). It does not properly mitigate against unsafe characters in serialized regular expressions. This vulnerability is not affected on Node.js environment since Node.js's implementation of RegExp.prototype.toString()… | |
| Modificada | Alta (8.1) | 5.4% | — | Exadel Flamingo Amf-serializer | 11/6/2018 | 17/6/2026 | The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0 derives class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExternalizable. A remote attacker with the ability to spoof or control an RMI server connection… | |
| Modificada | Alta (7.5) | 1.1% | — | Serialize-to-js Project Serialize-to-js | 24/10/2017 | 17/6/2026 | The deserialize function in serialize-to-js through 1.1.1 allows attackers to cause a denial of service via vectors involving an Immediately Invoked Function Expression "function()" substring, as demonstrated by a "function(){console.log(" call or a simple infinite loop. NOTE: the vendor agrees that denial of service… | |
| Modificada | Crítica (9.8) | 4.5% | — | Serialize-to-js Project Serialize-to-js | 10/2/2017 | 17/6/2026 | An issue was discovered in the serialize-to-js package 0.5.0 for Node.js. Untrusted data passed into the deserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE). | |
| Modificada | Crítica (9.8) | 61% | — | Node-serialize Project Node-serialize | 9/2/2017 | 17/6/2026 | An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE). |