Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3047▲ 441 respecto a la semana anterior
Críticas / altas1452▲ 212 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 151 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.51%—Naturalintelligence Fast-xml-parserAI13/8/202618/9/2026
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From 5.9.3 until 5.10.1, src/xmlparser/OrderedObjParser.js processes multiple DOCTYPE declarations within a single XML document and passes each declaration's entities through addInputEntities(). addInputEntities()…
AnalizadaMedia (6.1)0.27%—Naturalintelligence Fast-xml-parser7/5/202617/6/2026
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version 5.7.0, XMLBuilder does not escape the "-->" sequence in comment content or the "]]>" sequence in CDATA sections when building XML from JavaScript objects. This allows XML injection when…
AnalizadaMedia (5.9)0.48%—Naturalintelligence Fast-xml-parser24/3/202617/6/2026
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.0-beta.3 to before version 5.5.7, the DocTypeReader in fast-xml-parser uses JavaScript truthy checks to evaluate maxEntityCount and maxEntitySize configuration limits. When a developer explicitly…
AnalizadaAlta (7.5)0.73%—Naturalintelligence Fast-xml-parser20/3/202617/6/2026
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-beta.3 through 5.5.5 contain a bypass vulnerability where numeric character references (&#NNN;, &#xHH;) and standard XML entities completely evade the entity expansion limits (e.g., maxTotalExpansions,…
AnalizadaBaja (2.7)0.66%—Naturalintelligence Fast-xml-parser26/2/202617/6/2026
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with stack overflow when user use XML builder with `preserveOrder:true`. Version 5.3.8 fixes the issue. As a workaround, use…
ModificadaCrítica (9.3)0.50%—Naturalintelligence Fast-xml-parser20/2/202610/9/2026
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities…
ModificadaAlta (7.5)0.97%—Naturalintelligence Fast-xml-parser19/2/202610/9/2026
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML input, it’s possible to make the parser…
AnalizadaAlta (7.5)0.62%—Naturalintelligence Fast-xml-parser30/1/202617/6/2026
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 5.0.9 through 5.3.3, a RangeError vulnerability exists in the numeric entity processing of fast-xml-parser when parsing XML with out-of-range entity code points…
ModificadaAlta (7.5)0.83%—Naturalintelligence Fast-xml-parser29/7/202417/6/2026
fast-xml-parser is an open source, pure javascript xml parser. a ReDOS exists on currency.js. This vulnerability is fixed in 4.4.1.
ModificadaMedia (6.5)1.2%—Naturalintelligence Fast XML Parser12/12/202317/6/2026
fast-xml-parser before 4.1.2 allows __proto__ for Prototype Pollution.
ModificadaAlta (7.5)1.1%—Naturalintelligence Fast-xml-parser6/6/202317/6/2026
fast-xml-parser is an open source, pure javascript xml parser. fast-xml-parser allows special characters in entity names, which are not escaped or sanitized. Since the entity name is used for creating a regex for searching and replacing entities in the XML body, an attacker can abuse it for denial of service (DoS)…
ModificadaAlta (7.5)1.4%—Axml Parser Project Axml Parser19/7/201817/6/2026
CopyData in AxmlParser.c in AXML Parser through 2018-01-04 has an out-of-bounds read.
ModificadaBaja (2.6)21%—Microsoft XML Core ServicesMicrosoft XML Parser10/10/200616/6/2026
The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.
ModificadaAlta (7.5)30%—Microsoft XML Core ServicesMicrosoft XML Parser10/10/200616/6/2026
Buffer overflow in the Extensible Stylesheet Language Transformations (XSLT) processing in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted Web page.