Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3043▲ 582 respecto a la semana anterior
Críticas / altas1452▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.37% | — | Socket.io Cluster-engineAI | 29/9/2026 | 30/9/2026 | Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 0.1.1, @socket.io/cluster-engine uses inherited object properties when looking up attacker-controlled session IDs in clustered deployments. Special property names such as __proto__ or constructor can resolve through the object… | |
| Pendiente de análisis | Crítica (9.3) | 0.41% | — | FreepbxAIAsteriskAISocket.ioAI | 13/8/2026 | 10/9/2026 | FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socket.IO version 4 applies that middleware only to the default namespace. An unauthenticated client can connect to custom namespaces that do not consistently invoke checkAuth… | |
| Aplazada | Alta (8.8) | 0.73% | — | Ground StationAISocket.ioAI | 6/8/2026 | 23/9/2026 | Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or replace the entire SQLite database by sending a single full_restore command with a… | |
| Pendiente de análisis | Alta (7.5) | 0.63% | — | Socket.ioAI | 3/8/2026 | 10/9/2026 | Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is… | |
| Analizada | Alta (8.7) | 0.63% | — | Socket.io-parser | 20/3/2026 | 17/6/2026 | Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory.… | |
| Aplazada | Alta (7.3) | 0.81% | — | Socket.ioAI | 19/6/2024 | 17/6/2026 | Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process. This issue is fixed by commit `15af22fc22` which has been included in `socket.io@4.6.2`… | |
| Modificada | Alta (7.5) | 1.1% | — | Socket.io-parser | 27/5/2023 | 17/6/2026 | socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol. A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process. A patch has been released in version 4.2.3. | |
| Analizada | Crítica (9.8) | 1.3% | — | Socket.io-parser | 26/10/2022 | 17/6/2026 | Due to improper type validation in attachment parsing the Socket.io js library, it is possible to overwrite the _placeholder object which allows an attacker to place references to functions at arbitrary places in the resulting query object. | |
| Modificada | Alta (7.5) | 1.6% | — | Socket.io-client Java | 2/8/2022 | 17/6/2026 | The package io.socket:socket.io-client before 2.0.1 are vulnerable to NULL Pointer Dereference when parsing a packet with with invalid payload format. | |
| Modificada | Media (4.3) | 0.73% | — | Socket.io | 19/1/2021 | 17/6/2026 | The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default. | |
| Modificada | Alta (7.5) | 2.6% | — | Socket.io-parser | 8/1/2021 | 17/6/2026 | socket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a concatenation approach is used. | |
| Modificada | Alta (7.8) | 2.1% | — | Socket.io-file Project Socket.io-file | 6/10/2020 | 17/6/2026 | The socket.io-file package through 2.0.31 for Node.js relies on client-side validation of file types, which allows remote attackers to execute arbitrary code by uploading an executable file via a modified JSON name field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Alta (7.5) | 1.6% | — | Socket.io-file Project Socket.io-file | 15/7/2020 | 17/6/2026 | A Path Traversal issue was discovered in the socket.io-file package through 2.0.31 for Node.js. The socket.io-file::createFile message uses path.join with ../ in the name option, and the uploadDir and rename options determine the path. | |
| Modificada | Alta (7.5) | 2.0% | — | Socket.io | 4/6/2018 | 17/6/2026 | Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on `Math.random()` to create socket IDs, the IDs are predictable. An attacker is able to guess the socket ID and gain access to socket.io servers, potentially obtaining sensitive… |