Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3047▲ 441 respecto a la semana anterior
Críticas / altas1452▲ 212 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 151 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.51% | — | Naturalintelligence Fast-xml-parserAI | 13/8/2026 | 18/9/2026 | fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From 5.9.3 until 5.10.1, src/xmlparser/OrderedObjParser.js processes multiple DOCTYPE declarations within a single XML document and passes each declaration's entities through addInputEntities(). addInputEntities()… | |
| Analizada | Media (6.1) | 0.27% | — | Naturalintelligence Fast-xml-parser | 7/5/2026 | 17/6/2026 | fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version 5.7.0, XMLBuilder does not escape the "-->" sequence in comment content or the "]]>" sequence in CDATA sections when building XML from JavaScript objects. This allows XML injection when… | |
| Analizada | Media (5.9) | 0.48% | — | Naturalintelligence Fast-xml-parser | 24/3/2026 | 17/6/2026 | fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.0-beta.3 to before version 5.5.7, the DocTypeReader in fast-xml-parser uses JavaScript truthy checks to evaluate maxEntityCount and maxEntitySize configuration limits. When a developer explicitly… | |
| Analizada | Alta (7.5) | 0.73% | — | Naturalintelligence Fast-xml-parser | 20/3/2026 | 17/6/2026 | fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-beta.3 through 5.5.5 contain a bypass vulnerability where numeric character references (&#NNN;, &#xHH;) and standard XML entities completely evade the entity expansion limits (e.g., maxTotalExpansions,… | |
| Analizada | Baja (2.7) | 0.66% | — | Naturalintelligence Fast-xml-parser | 26/2/2026 | 17/6/2026 | fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with stack overflow when user use XML builder with `preserveOrder:true`. Version 5.3.8 fixes the issue. As a workaround, use… | |
| Modificada | Crítica (9.3) | 0.50% | — | Naturalintelligence Fast-xml-parser | 20/2/2026 | 10/9/2026 | fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities… | |
| Modificada | Alta (7.5) | 0.97% | — | Naturalintelligence Fast-xml-parser | 19/2/2026 | 10/9/2026 | fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML input, it’s possible to make the parser… | |
| Analizada | Alta (7.5) | 0.62% | — | Naturalintelligence Fast-xml-parser | 30/1/2026 | 17/6/2026 | fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 5.0.9 through 5.3.3, a RangeError vulnerability exists in the numeric entity processing of fast-xml-parser when parsing XML with out-of-range entity code points… | |
| Modificada | Alta (7.5) | 0.83% | — | Naturalintelligence Fast-xml-parser | 29/7/2024 | 17/6/2026 | fast-xml-parser is an open source, pure javascript xml parser. a ReDOS exists on currency.js. This vulnerability is fixed in 4.4.1. | |
| Modificada | Media (6.5) | 1.2% | — | Naturalintelligence Fast XML Parser | 12/12/2023 | 17/6/2026 | fast-xml-parser before 4.1.2 allows __proto__ for Prototype Pollution. | |
| Modificada | Alta (7.5) | 1.1% | — | Naturalintelligence Fast-xml-parser | 6/6/2023 | 17/6/2026 | fast-xml-parser is an open source, pure javascript xml parser. fast-xml-parser allows special characters in entity names, which are not escaped or sanitized. Since the entity name is used for creating a regex for searching and replacing entities in the XML body, an attacker can abuse it for denial of service (DoS)… | |
| Modificada | Alta (7.5) | 1.4% | — | Axml Parser Project Axml Parser | 19/7/2018 | 17/6/2026 | CopyData in AxmlParser.c in AXML Parser through 2018-01-04 has an out-of-bounds read. | |
| Modificada | Baja (2.6) | 21% | — | Microsoft XML Core ServicesMicrosoft XML Parser | 10/10/2006 | 16/6/2026 | The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains. | |
| Modificada | Alta (7.5) | 30% | — | Microsoft XML Core ServicesMicrosoft XML Parser | 10/10/2006 | 16/6/2026 | Buffer overflow in the Extensible Stylesheet Language Transformations (XSLT) processing in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted Web page. |