Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2734▲ 30 respecto a la semana anterior
Críticas / altas1469▲ 361 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.59%—S3-url-parserAI1/5/202417/6/2026
s3-url-parser 1.0.3 is vulnerable to Denial of service via the regexes component.
ModificadaAlta (7.5)0.76%—Git-url-parse Project Git-url-parse12/6/202317/6/2026
The git-url-parse crate through 0.4.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to normalize_url in lib.rs, a similar issue to CVE-2023-32758 (Python).
ModificadaAlta (7.5)1.0%—Coala Git-url-parse15/5/202317/6/2026
giturlparse (aka git-url-parse) through 1.2.2, as used in Semgrep 1.5.2 through 1.24.1, is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing untrusted URLs. This might be relevant if Semgrep is analyzing an untrusted package (for example, to check whether it accesses any Git repository at an…
ModificadaCrítica (9.8)2.2%—Url-parse Project Url-parse21/2/202217/6/2026
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.
ModificadaCrítica (9.1)1.8%—Url-parse Project Url-parse20/2/202217/6/2026
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.
ModificadaMedia (5.3)1.5%—Url-parse Project Url-parse17/2/202217/6/2026
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7.
ModificadaMedia (5.3)1.8%—Url-parse Project Url-parse14/2/202217/6/2026
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.
ModificadaMedia (5.3)1.8%—Url-parse Project Url-parse26/7/202117/6/2026
url-parse is vulnerable to URL Redirection to Untrusted Site
ModificadaMedia (5.3)2.0%—Url-parse Project Url-parse22/2/202117/6/2026
url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
ModificadaMedia (5.3)1.7%—Url-parse Project Url-parse4/2/202017/6/2026
Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks.
ModificadaCrítica (10)3.8%—Url-parse Project Url-parse12/8/201817/6/2026
Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.