Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

5 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.2)1.1%—Dchester JsonpathAI9/2/202625/8/2026
Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JSON Path input, which is not designed to handle untrusted data safely. An attacker can exploit this…
AnalizadaCrítica (9.8)0.51%—Dchester Jsonpath28/1/20267/9/2026
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
AplazadaAlta (8.9)10%—Jsonpath-plusAI15/2/202517/6/2026
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode. **Note:** This is caused by an incomplete fix for…
AplazadaCrítica (9.8)9.0%—Jsonpath-plusAI11/10/202417/6/2026
All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** There were several attempts to fix it in versions…
AnalizadaMedia (5.3)0.68%—Json-path Jayway Jsonpath27/12/202317/6/2026
json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.