Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2586▼ 297 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.3)1.3%—Iasset Project Iasset11/7/202217/6/2026
The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaCrítica (9.8)1.4%—Deep-get-set Project Deep-get-set24/6/202217/6/2026
All versions of package deep-get-set are vulnerable to Prototype Pollution via the 'deep' function. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7715](https://security.snyk.io/vuln/SNYK-JS-DEEPGETSET-598666)
ModificadaAlta (8.1)1.8%—Dset Project Dset1/5/202217/6/2026
All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or protorype. By crafting a malicious object, it is possible to bypass this check and achieve prototype…
ModificadaCrítica (9.8)3.7%—SET Project SET4/2/202217/6/2026
This affects the package @strikeentco/set before 1.0.2. It allows an attacker to cause a denial of service and may lead to remote code execution. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-STRIKEENTCOSET-1038821
ModificadaCrítica (9.8)3.3%—Just-safe-set Project Just-safe-set7/7/202117/6/2026
Prototype pollution vulnerability in ‘just-safe-set’ versions 1.0.0 through 2.2.1 allows an attacker to cause a denial of service and may lead to remote code execution.
ModificadaCrítica (9.8)3.5%—Changeset Project Changeset9/3/202117/6/2026
Prototype pollution vulnerability in 'changeset' versions 0.0.1 through 0.2.5 allows an attacker to cause a denial of service and may lead to remote code execution.
ModificadaCrítica (9.8)3.1%—Dset Project Dset29/12/202017/6/2026
Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
ModificadaCrítica (9.8)3.1%—Deep-set Project Deep-set29/12/202017/6/2026
Prototype pollution vulnerability in 'deep-set' versions 1.0.0 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
ModificadaAlta (7.5)2.3%—SET Project SET10/11/202017/6/2026
Prototype pollution vulnerability in '@strikeentco/set' version 1.0.0 allows attacker to cause a denial of service and may lead to remote code execution.
ModificadaCrítica (9.8)2.0%—Deep-get-set Project Deep-get-set1/9/202017/6/2026
All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function.
ModificadaAlta (7.5)1.8%—Memoffset Project Memoffset26/8/201917/6/2026
An issue was discovered in the memoffset crate before 0.5.0 for Rust. offset_of and span_of can cause exposure of uninitialized memory.
ModificadaAlta (7.5)1.7%—Charset Project Charset7/6/201817/6/2026
charset 1.0.0 and below are vulnerable to regular expression denial of service. Input of around 50k characters is required for a slow down of around 2 seconds. Unless node was compiled using the -DHTTP_MAX_HEADER_SIZE= option the default header max length is 80kb, so the impact of the ReDoS is relatively low.
ModificadaAlta (8.1)2.2%—Node-wixtoolset Project Node-wixtoolset4/6/201817/6/2026
wixtoolset is a Node module wrapper around the wixtoolset binaries wixtoolset downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the…
ModificadaAlta (7.8)0.55%—Codders-dataset Project Codders-dataset10/1/201817/6/2026
(1) lib/dataset/database/mysql.rb and (2) lib/dataset/database/postgresql.rb in the codders-dataset gem 1.3.2.1 for Ruby place credentials on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.