Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2724▼ 13 respecto a la semana anterior
Críticas / altas1452▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.34% | — | Unjs Unhead | 9/4/2026 | 17/6/2026 | Unhead is a document head and template manager. Prior to 2.1.13, useHeadSafe() is the composable that Nuxt's own documentation explicitly recommends for rendering user-supplied content in <head> safely. Internally, the hasDangerousProtocol() function in packages/unhead/src/plugins/safe.ts decodes HTML entities before… | |
| Analizada | Alta (7.5) | 0.52% | — | Unjs Defu | 6/4/2026 | 21/7/2026 | defu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pass unsanitized user input (e.g. parsed JSON request bodies, database records, or config files from untrusted sources) as the first argument to `defu()` are vulnerable to prototype pollution. A… | |
| Analizada | Media (6.1) | 0.26% | — | Unjs Unhead | 12/3/2026 | 17/6/2026 | Unhead is a document head and template manager. Prior to 2.1.11, The link.href check in makeTagSafe (safe.ts) uses String.includes(), which is case-sensitive. Browsers treat URI schemes case-insensitively. DATA:text/css,... is the same as data:text/css,... to the browser, but 'DATA:...'.includes('data:') returns… | |
| Analizada | Media (5.3) | 0.27% | — | Unjs Unhead | 12/3/2026 | 17/6/2026 | Unhead is a document head and template manager. Prior to 2.1.11, useHeadSafe() can be bypassed to inject arbitrary HTML attributes, including event handlers, into SSR-rendered <head> tags. This is the composable that Nuxt docs recommend for safely handling user-generated content. The acceptDataAttrs function (safe.ts,… | |
| Analizada | Crítica (9.8) | 0.88% | — | Unjs Nanotar | 11/2/2026 | 17/6/2026 | nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory via a crafted tar archive containing path traversal sequence. | |
| Analizada | Media (6.9) | 0.67% | — | Unjs IPX | 5/8/2025 | 17/6/2026 | IPX is an image optimizer powered by sharp and svgo. In versions 1.3.1 and below, 2.0.0-0 through 2.1.0, and 3.0.0 through 3.1.0, the approach used to check whether a path is within allowed directories is vulnerable to path prefix bypass when the allowed directories do not end with a path separator. This occurs… | |
| Modificada | Alta (8.8) | 0.26% | — | Nikunjsoni Easy WP Cleaner | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nikunj Soni Easy WP Cleaner plugin <= 1.9 versions. | |
| Modificada | Alta (8.1) | 1.8% | — | Spunjs Selenium-binaries | 29/5/2018 | 17/6/2026 | selenium-binaries downloads Selenium related binaries for your OS. selenium-binaries downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on… |