Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2734▲ 30 respecto a la semana anterior
Críticas / altas1469▲ 361 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.59% | — | S3-url-parserAI | 1/5/2024 | 17/6/2026 | s3-url-parser 1.0.3 is vulnerable to Denial of service via the regexes component. | |
| Modificada | Alta (7.5) | 0.76% | — | Git-url-parse Project Git-url-parse | 12/6/2023 | 17/6/2026 | The git-url-parse crate through 0.4.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to normalize_url in lib.rs, a similar issue to CVE-2023-32758 (Python). | |
| Modificada | Alta (7.5) | 1.0% | — | Coala Git-url-parse | 15/5/2023 | 17/6/2026 | giturlparse (aka git-url-parse) through 1.2.2, as used in Semgrep 1.5.2 through 1.24.1, is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing untrusted URLs. This might be relevant if Semgrep is analyzing an untrusted package (for example, to check whether it accesses any Git repository at an… | |
| Modificada | Crítica (9.8) | 2.2% | — | Url-parse Project Url-parse | 21/2/2022 | 17/6/2026 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9. | |
| Modificada | Crítica (9.1) | 1.8% | — | Url-parse Project Url-parse | 20/2/2022 | 17/6/2026 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8. | |
| Modificada | Media (5.3) | 1.5% | — | Url-parse Project Url-parse | 17/2/2022 | 17/6/2026 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7. | |
| Modificada | Media (5.3) | 1.8% | — | Url-parse Project Url-parse | 14/2/2022 | 17/6/2026 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6. | |
| Modificada | Media (5.3) | 1.8% | — | Url-parse Project Url-parse | 26/7/2021 | 17/6/2026 | url-parse is vulnerable to URL Redirection to Untrusted Site | |
| Modificada | Media (5.3) | 2.0% | — | Url-parse Project Url-parse | 22/2/2021 | 17/6/2026 | url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path. | |
| Modificada | Media (5.3) | 1.7% | — | Url-parse Project Url-parse | 4/2/2020 | 17/6/2026 | Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks. | |
| Modificada | Crítica (10) | 3.8% | — | Url-parse Project Url-parse | 12/8/2018 | 17/6/2026 | Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol. |