Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2586▼ 297 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.3) | 1.3% | — | Iasset Project Iasset | 11/7/2022 | 17/6/2026 | The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Crítica (9.8) | 1.4% | — | Deep-get-set Project Deep-get-set | 24/6/2022 | 17/6/2026 | All versions of package deep-get-set are vulnerable to Prototype Pollution via the 'deep' function. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7715](https://security.snyk.io/vuln/SNYK-JS-DEEPGETSET-598666) | |
| Modificada | Alta (8.1) | 1.8% | — | Dset Project Dset | 1/5/2022 | 17/6/2026 | All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or protorype. By crafting a malicious object, it is possible to bypass this check and achieve prototype… | |
| Modificada | Crítica (9.8) | 3.7% | — | SET Project SET | 4/2/2022 | 17/6/2026 | This affects the package @strikeentco/set before 1.0.2. It allows an attacker to cause a denial of service and may lead to remote code execution. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-STRIKEENTCOSET-1038821 | |
| Modificada | Crítica (9.8) | 3.3% | — | Just-safe-set Project Just-safe-set | 7/7/2021 | 17/6/2026 | Prototype pollution vulnerability in ‘just-safe-set’ versions 1.0.0 through 2.2.1 allows an attacker to cause a denial of service and may lead to remote code execution. | |
| Modificada | Crítica (9.8) | 3.5% | — | Changeset Project Changeset | 9/3/2021 | 17/6/2026 | Prototype pollution vulnerability in 'changeset' versions 0.0.1 through 0.2.5 allows an attacker to cause a denial of service and may lead to remote code execution. | |
| Modificada | Crítica (9.8) | 3.1% | — | Dset Project Dset | 29/12/2020 | 17/6/2026 | Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service and may lead to remote code execution. | |
| Modificada | Crítica (9.8) | 3.1% | — | Deep-set Project Deep-set | 29/12/2020 | 17/6/2026 | Prototype pollution vulnerability in 'deep-set' versions 1.0.0 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution. | |
| Modificada | Alta (7.5) | 2.3% | — | SET Project SET | 10/11/2020 | 17/6/2026 | Prototype pollution vulnerability in '@strikeentco/set' version 1.0.0 allows attacker to cause a denial of service and may lead to remote code execution. | |
| Modificada | Crítica (9.8) | 2.0% | — | Deep-get-set Project Deep-get-set | 1/9/2020 | 17/6/2026 | All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function. | |
| Modificada | Alta (7.5) | 1.8% | — | Memoffset Project Memoffset | 26/8/2019 | 17/6/2026 | An issue was discovered in the memoffset crate before 0.5.0 for Rust. offset_of and span_of can cause exposure of uninitialized memory. | |
| Modificada | Alta (7.5) | 1.7% | — | Charset Project Charset | 7/6/2018 | 17/6/2026 | charset 1.0.0 and below are vulnerable to regular expression denial of service. Input of around 50k characters is required for a slow down of around 2 seconds. Unless node was compiled using the -DHTTP_MAX_HEADER_SIZE= option the default header max length is 80kb, so the impact of the ReDoS is relatively low. | |
| Modificada | Alta (8.1) | 2.2% | — | Node-wixtoolset Project Node-wixtoolset | 4/6/2018 | 17/6/2026 | wixtoolset is a Node module wrapper around the wixtoolset binaries wixtoolset downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the… | |
| Modificada | Alta (7.8) | 0.55% | — | Codders-dataset Project Codders-dataset | 10/1/2018 | 17/6/2026 | (1) lib/dataset/database/mysql.rb and (2) lib/dataset/database/postgresql.rb in the codders-dataset gem 1.3.2.1 for Ruby place credentials on the mysqldump command line, which allows local users to obtain sensitive information by listing the process. |