Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3045▲ 455 respecto a la semana anterior
Críticas / altas1424▲ 188 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)389▲ 174 respecto a la semana anterior
215 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.67% | — | Plesk RubyAIPlesk Node.js ToolkitAI | 14/9/2026 | 18/9/2026 | Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables. | |
| Pendiente de análisis | Alta (7.5) | 0.61% | — | CompressionAINodejs Node.jsAIExpressjs ExpressAI | 11/9/2026 | 16/9/2026 | compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never destroyed, so each aborted compressed response leaks its native zlib memory. A remote… | |
| Pendiente de análisis | Media (6.5) | 0.12% | — | Snowflake Python DriverAISnowflake GO DriverAISnowflake Jdbc DriverAISnowflake Node.js DriverAI+2 | 8/9/2026 | 10/9/2026 | Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be written to diagnostic logs in circumstances where the available log redaction did… | |
| Pendiente de análisis | Alta (7.4) | 0.16% | — | Snowflake Python DriverAISnowflake GO DriverAISnowflake Jdbc DriverAISnowflake Node.js DriverAI | 4/9/2026 | 10/9/2026 | Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and definitive verification failures were treated as transient. A man-in-the-middle… | |
| Pendiente de análisis | Media (6.5) | 0.47% | — | Mariadb Connector/node.jsAIMysqlAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js permits SQL injection when attacker-controlled Buffer parameters are escaped client-side under the big5, gbk, sjis, cp932, or gb18030 client… | |
| Pendiente de análisis | Media (5.9) | 0.42% | — | Mariadb Connector/node.jsAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js can disclose an account password when PAM dialog authentication is negotiated over an insecure transport. In… | |
| Pendiente de análisis | Alta (7.5) | 0.57% | — | Mariadb Connector Node.jsAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to versions 3.3.3, 3.4.6, and 3.5.3, when ssl is enabled without a pinned CA or server certificate, MariaDB Connector/Node.js sends credentials before completing certificate fingerprint validation. In… | |
| Aplazada | Alta (8.8) | 0.49% | — | Mercadopago Node.js SDKAI | 24/8/2026 | 24/9/2026 | The Mercado Pago Node.js SDK interpolates caller-supplied identifiers into API request paths without percent-encoding them, so characters that are structural in a URL survive into the outgoing request. The payment (get, capture, cancel), paymentRefund (create, total, list, get), advancedPayment (get, capture, cancel,… | |
| Pendiente de análisis | Media (6.2) | 0.17% | — | Nodejs Node.jsAI | 4/8/2026 | 3/9/2026 | A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected. Repeated exploitation of this condition can result in a denial of service. This vulnerability affects… | |
| Pendiente de análisis | Baja (3.7) | 0.27% | — | Nodejs Node.jsAI | 4/8/2026 | 3/9/2026 | A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while piping the original body to a reused backend connection. Node.js can omit headers beyond `maxHeadersCount` / `maxHeaderPairs` from… | |
| Pendiente de análisis | Media (5.3) | 0.29% | — | Nodejs Node.jsAI | 4/8/2026 | 3/9/2026 | A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared statement after it has been reset and rebound with new parameters. SQLTagStore resets cached statements using sqlite3_reset() directly, bypassing the iterator… | |
| Pendiente de análisis | Baja (3.3) | 0.15% | — | Nodejs Node.jsAI | 31/7/2026 | 3/9/2026 | A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**. | |
| Pendiente de análisis | Media (5.7) | 0.16% | — | Google RE2AINodejs Node.jsAI | 30/7/2026 | 10/9/2026 | re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and split, allowing an attacker-influenced lastIndex on a non-ASCII subject to trigger an… | |
| Analizada | Alta (8.4) | 0.15% | — | Nodejs Node.js | 30/7/2026 | 25/8/2026 | A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects… | |
| Pendiente de análisis | Media (6.3) | 0.30% | — | Nodejs Node.jsAI | 30/7/2026 | 3/9/2026 | An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**. | |
| Analizada | Media (4.4) | 0.08% | — | Nodejs Node.js | 30/7/2026 | 25/8/2026 | A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**. | |
| Analizada | Media (6.1) | 0.16% | — | Nodejs Node.js | 30/7/2026 | 25/8/2026 | A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and… | |
| Analizada | Baja (3.3) | 0.14% | — | Nodejs Node.js | 26/6/2026 | 26/6/2026 | A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects one supported release line: **Node.js 26**. | |
| Analizada | Baja (3.3) | 0.18% | — | Nodejs Node.js | 26/6/2026 | 26/6/2026 | A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | |
| Modificada | Media (4.3) | 0.26% | — | Nodejs Node.js | 26/6/2026 | 29/6/2026 | A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | |
| Modificada | Alta (7.5) | 3.7% | — | Nodejs Node.js | 26/6/2026 | 10/8/2026 | A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | |
| Analizada | Crítica (9.8) | 0.32% | — | Nodejs Node.js | 26/6/2026 | 26/6/2026 | A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | |
| Analizada | Media (5.4) | 0.22% | — | Nodejs Node.js | 26/6/2026 | 26/6/2026 | A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | |
| Analizada | Alta (7.5) | 0.64% | — | Nodejs Node.js | 26/6/2026 | 26/6/2026 | A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on the client. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | |
| Modificada | Media (6.5) | 3.2% | — | Nodejs Node.js | 26/6/2026 | 10/8/2026 | A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.… |