Vulnerabilities
Summary — last 7 days
New vulnerabilities2,726▼ 504 vs. last week
Critical / high1,294▼ 196 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)229▼ 273 vs. last week
1 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | High (7.3) | 1.1% | — | Aprendecondedos Dedos-web | 6/5/2018 | 6/17/2026 | In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code published on GitHub. An attacker can edit the contents of the session cookie and re-sign it using the hardcoded secret. Due to the use of Passport.js, this could lead to… |