Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
79 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.58% | — | Fastify StaticAI | 17/9/2026 | 18/9/2026 | @fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions before 10.1.4, on a case-insensitive filesystem such as Windows or the default macOS volume, a route guard or allowedPath restriction can be bypassed by altering the letter case of a path segment. The route… | |
| Aplazada | Media (4.3) | 0.39% | — | Static-web-server Static WEB ServerAI | 26/8/2026 | 9/9/2026 | Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instances with both basic-auth and metrics features enabled process the /metrics endpoint before the basic-auth check in src/handler.rs, allowing an unauthenticated remote attacker to retrieve Prometheus… | |
| Aplazada | Media (5.7) | 0.32% | — | Catalyst Plugin Static SimpleAI | 20/8/2026 | 28/8/2026 | Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable. The _serve_static method always sets the Cache-Control header to "public", with no means of overriding it. This advises proxies that the content may be stored in a shared cache, and may be reused in responses to… | |
| Aplazada | Media (6.1) | 0.32% | — | Corebunch InstaticAI | 10/8/2026 | 28/8/2026 | A cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14 allows an unauthenticated remote attacker to poison the shared process-wide render cache by manipulating the u query parameter of the GET /_instatic/hole/<nodeId> server island endpoint. | |
| Analizada | Alta (7.5) | 0.66% | — | Fastify-static | 6/8/2026 | 4/9/2026 | @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or backslashes before route matching and before delegating to the send layer.… | |
| Aplazada | Crítica (9.1) | 0.53% | — | Outstatic CMSAI | 30/7/2026 | 31/7/2026 | Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticated remote attacker can exploit this by forging JWT session tokens with… | |
| Analizada | Media (5.3) | 0.37% | — | Fastify-static | 23/7/2026 | 28/7/2026 | @fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to and including 10.1.1 are affected. An unauthenticated attacker can bypass allowedPath restrictions by requesting equivalent non-canonical pathnames,… | |
| Analizada | Alta (7.5) | 0.67% | — | Fastify-static | 23/7/2026 | 28/7/2026 | @fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This is a bypass of the earlier fix for CVE-2026-6414, which only covered encoded forward slashes. Because the underlying send library normalizes dot segments before applying… | |
| Aplazada | Media (4.3) | 0.21% | — | Static BlockAI | 16/6/2026 | 17/6/2026 | The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2. This is due to the static_block_content() shortcode handler retrieving a post via get_post() using an attacker-supplied 'id' attribute and outputting its post_content without verifying the… | |
| Aplazada | Media (6.5) | 0.14% | — | Recorp Export WP Page TO Static Html CSSAI | 25/5/2026 | 24/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows Cross Site Request Forgery. This issue affects Export WP Page to Static HTML/CSS: from n/a through 6.0.0. | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Pendiente de análisis | Alta (8.6) | 0.74% | — | Qnabot-on-awsAINPM Static-evalAI | 27/4/2026 | 17/6/2026 | Improper use of the static-eval npm package in the open source solution qnabot-on-aws versions 7.2.4 and earlier may allow an authenticated administrator to execute arbitrary code within the fulfillment Lambda execution context by injecting a crafted conditional chaining expression via the Content Designer interface,… | |
| Analizada | Media (5.3) | 0.53% | — | Fastify-static | 16/4/2026 | 17/6/2026 | @fastify/static versions 8.0.0 through 9.1.0 allow path traversal when directory listing is enabled via the list option. The dirList.path() function resolves directories outside the configured static root using path.join() without a containment check. A remote unauthenticated attacker can obtain directory listings for… | |
| Analizada | Media (5.9) | 0.45% | — | Fastify-static | 16/4/2026 | 17/6/2026 | @fastify/static versions 8.0.0 through 9.1.0 decode percent-encoded path separators (%2F) before filesystem resolution, while Fastify's router treats them as literal characters. This mismatch allows attackers to bypass route-based middleware or guards that protect files served by @fastify/static. For example, a route… | |
| Analizada | Media (5.3) | 0.43% | — | Static-web-server Static WEB Server | 21/2/2026 | 17/6/2026 | Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. In versions 2.1.0 through 2.40.1, a timing-based username enumeration vulnerability in Basic Authentication allows attackers to identify valid users by exploiting early responses for invalid usernames, enabling targeted… | |
| Aplazada | Crítica (9.8) | 2.1% | — | Export WP Page TO Static Html PDFAI | 13/12/2025 | 17/6/2026 | The Export WP Page to Static HTML & PDF plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.4 through publicly exposed cookies.txt files containing authentication cookies. This makes it possible for unauthenticated attackers to cookies that may have been… | |
| Analizada | Media (5.5) | 0.42% | — | Static-web-server Static WEB Server | 9/12/2025 | 17/6/2026 | Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Versions 2.40.0 and below contain symbolic links (symlinks) which can be used to access files or directories outside the intended web root folder. SWS generally does not prevent symlinks from escaping the web server’s… | |
| Aplazada | Alta (7.5) | 0.52% | — | Node-staticAINubosoftware Node-staticAI | 30/9/2025 | 17/6/2026 | This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception when user input includes null bytes. This allows attackers to access http://host/%00 and crash the server. | |
| Aplazada | Media (5.3) | 0.23% | — | Recorp Export WP Page TO Static HtmlAI | 9/9/2025 | 17/6/2026 | Missing Authorization vulnerability in recorp Export WP Page to Static HTML/CSS export-wp-page-to-static-html allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Export WP Page to Static HTML/CSS: from n/a through <= 4.1.0. | |
| Aplazada | Media (6) | 0.42% | — | Vite-plugin-static-copyAIRollup-plugin-copyAI | 21/8/2025 | 17/6/2026 | vite-plugin-static-copy is rollup-plugin-copy for Vite with dev server support. Files not included in src are accessible with a crafted request. The vulnerability is fixed in 2.3.2 and 3.1.2. | |
| Aplazada | Media (6.5) | 0.25% | — | Simple Google Static MAPAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ángel C. Simple Google Static Map simple-google-static-map allows DOM-Based XSS.This issue affects Simple Google Static Map: from n/a through <= 1.0.1. | |
| Aplazada | Media (4.3) | 0.28% | — | Wokamoto StaticpressAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in wokamoto StaticPress staticpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects StaticPress: from n/a through <= 0.4.5. | |
| Aplazada | Media (4.3) | 0.20% | — | Hitoy Super Static CacheAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in hitoy Super Static Cache super-static-cache allows Cross Site Request Forgery.This issue affects Super Static Cache: from n/a through <= 3.3.5. | |
| Analizada | Alta (8.6) | 2.4% | ⚠ Explotación activa | Reviewdog Action-ast-grepReviewdog Action-composite-templateReviewdog Action-setupReviewdog Action-shellcheck+2 | 19/3/2025 | 17/6/2026 | reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be… | |
| Aplazada | Media (6.5) | 0.36% | — | Steven Nolles Bonway Static Block EditorAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Steven Nolles Bonway Static Block Editor bonway-static-block-editor allows DOM-Based XSS.This issue affects Bonway Static Block Editor: from n/a through <= 1.1.0. |