Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▲ 460 respecto a la semana anterior
Críticas / altas1445▲ 228 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 156 respecto a la semana anterior
261 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.33% | — | SimdjsonAI | 24/9/2026 | 29/9/2026 | simdjson 4.6.1 contains a one-byte out-of-bounds read vulnerability in dom::parser::parse_unpadded(). A specially crafted truncated JSON document whose final structural token closes a nested array or object can cause json_iterator::walk_document() to access buf[len] after the input buffer has been exhausted. This… | |
| Aplazada | Media (5.5) | 0.53% | — | Davegamble CjsonAI | 10/9/2026 | 10/9/2026 | A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue… | |
| Aplazada | Alta (8.7) | 0.35% | — | Pocketmine-mpAIJsonmapperAI | 9/9/2026 | 30/9/2026 | PocketMine-MP versions before 4.20.5 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper validation in the JsonMapper dependency. Attackers can send malformed JSON structures in LoginPacket to crash the server. | |
| Aplazada | Media (5.5) | 0.70% | — | Java-json-tools Jackson-coreutilsAI | 8/9/2026 | 28/9/2026 | A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePointer.tokensFromInput of the file src/main/java/com/github/fge/jackson/jsonpointer/TreePointer.java of the component JSON Pointer parser. The manipulation results in allocation of resources. The… | |
| Aplazada | Baja (2.1) | 0.37% | — | Starcounter-jack Json-patchAI | 8/9/2026 | 28/9/2026 | A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component Copy Move Operations. The manipulation leads to improper access controls. Remote exploitation… | |
| Aplazada | Media (5.5) | 0.70% | — | Java-json-tools Jackson-coreutilsAI | 8/9/2026 | 28/9/2026 | A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDecimal.toPlainString of the file src/main/java/com/github/fge/jackson/JacksonUtils.java. Performing a manipulation results in resource consumption. The attack may be initiated remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.66% | — | Java-json-tools Jackson-coreutilsAI | 7/9/2026 | 8/9/2026 | A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java of the component URL Validation. The manipulation results in server-side request forgery. It is possible to launch the attack… | |
| Aplazada | Media (5.5) | 0.70% | — | Java-json-tools Json PatchAI | 7/9/2026 | 9/9/2026 | A vulnerability has been found in java-json-tools json-patch up to 1.13. Affected by this vulnerability is the function JsonPatch.apply of the file src/main/java/com/github/fge/jsonpatch/JsonPatch.java of the component Patch Operation Handler. The manipulation leads to resource consumption. It is possible to initiate… | |
| Aplazada | Media (5.5) | 0.76% | — | Starcounter-jack Json-patchAI | 7/9/2026 | 8/9/2026 | A flaw has been found in java-json-tools json-patch up to 1.13. Affected is the function JsonMergePatch.fromJson of the file JsonMergePatchDeserializer.java. Executing a manipulation can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. The… | |
| Aplazada | Alta (8.7) | 0.34% | — | Pocketmine-mpAIAdhocore Json-commentAI | 6/9/2026 | 10/9/2026 | PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with invalid geometry JSON to trigger an unhandled RuntimeException, causing server crash. | |
| Aplazada | Media (6.2) | 0.16% | — | Stream-jsonAI | 3/9/2026 | 9/9/2026 | stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.5.0, the path filters pick, ignore, filter, and replace in src/core/filters/filter-base.js recompute the full path string from the nesting stack for every checkable token. Because the stack… | |
| Aplazada | Media (5.5) | 0.70% | — | Armink Struct2jsonAI | 31/8/2026 | 2/9/2026 | A vulnerability has been found in armink struct2json 1.0. This affects the function S2J_STRUCT_GET_string_ELEMENT in the library struct2json/inc/s2jdef.h of the component JSON Deserialization. The manipulation of the argument valuestring leads to null pointer dereference. The attack may be initiated remotely. The… | |
| Aplazada | Crítica (9.3) | 0.39% | — | Auth0 JsonwebtokenAIOmnivoreAI | 29/8/2026 | 24/9/2026 | The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed it as the sole allowed algorithm to jwt.verify(). Using jsonwebtoken v8 (which… | |
| Aplazada | Alta (7.5) | 0.49% | — | Owasp Json-sanitizerAI | 28/8/2026 | 9/9/2026 | An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2.3 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Crítica (9.3) | 0.89% | — | JsonataAI | 21/8/2026 | 9/9/2026 | JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weaknesses to execute arbitrary code. The chain could overwrite $clone to mutate objects through evaluateTransformExpression, expose and deconstruct JSONata functions or… | |
| Aplazada | Crítica (9.3) | 0.57% | — | JsonataAI | 21/8/2026 | 9/9/2026 | JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOwnProperty check. Crafted expressions could use $hasOwnProperty, $spread, $string, prototype access, and $constructor to reach the object prototype and invoke… | |
| Aplazada | Crítica (9.3) | 0.72% | — | JsonataAI | 21/8/2026 | 9/9/2026 | JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions to access inherited prototype members. An attacker able to supply an expression could use inherited prototype setters and… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Json OptionsAI | 20/8/2026 | 26/8/2026 | The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing them to update arbitrary WordPress options. This can be leveraged to enable user registration and set the… | |
| Pendiente de análisis | Alta (8.7) | 0.44% | — | CjsonAI | 11/8/2026 | 24/9/2026 | cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations to target wrong object keys by supplying crafted JSON Pointer escape sequences (~0 or… | |
| Aplazada | Crítica (9.3) | 0.46% | — | FirecrawlAIJson-schema-ref-parserAI | 10/8/2026 | 18/9/2026 | Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in Firecrawl's extraction functionality due to unsafe schema dereferencing of user-supplied JSON schemas in apps/api/src/lib/extract/helpers/dereference-schema.ts. The… | |
| Aplazada | Crítica (9.8) | 0.68% | — | Tencent ApijsonAI | 10/8/2026 | 28/8/2026 | A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-table access control and read arbitrary database tables via the Map-form @having operator. | |
| Pendiente de análisis | Alta (8.7) | 0.43% | — | Ruby JsonAI | 7/8/2026 | 18/9/2026 | Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input buffer but leaves state.start, state.cursor, and state.end pointing into released storage. When partial_value reconstructs an incomplete object containing duplicate… | |
| Analizada | Alta (8.7) | 0.43% | — | Amazon Aws-smithy-json | 30/7/2026 | 10/8/2026 | Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial of service (process abort via stack exhaustion) via a single small HTTP… | |
| Analizada | Media (6.9) | 0.43% | — | Davegamble Cjson | 29/7/2026 | 4/8/2026 | cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved, the existing target member is detached and deleted before the operation is fully… | |
| Analizada | Alta (8.2) | 0.65% | — | Davegamble Cjson | 29/7/2026 | 4/8/2026 | cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the running time exponential in nesting depth. A small, deeply nested document of a few hundred… |