Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

17 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)2.8%—Npmjs Semver21/6/202317/6/2026
Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
ModificadaAlta (7.5)3.9%—Npmjs NPMNetapp Ontap Select Deploy Administration Utility13/6/202217/6/2026
npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files…
ModificadaCrítica (9.8)2.7%—Npmjs NPMNetapp Next Generation Application Programming InterfaceFedoraproject Fedora13/11/202117/6/2026
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact…
ModificadaAlta (7.8)0.55%—Npmjs ArboristOracle GraalvmSiemens Sinec Infrastructure Network Services31/8/202117/6/2026
`@npmcli/arborist`, the library that calculates dependency trees and manages the node_modules folder hierarchy for the npm command line interface, aims to guarantee that package dependency contracts will be met, and the extraction of package contents will always be performed into the expected folder. This is…
ModificadaAlta (7.8)0.58%—Npmjs ArboristOracle GraalvmSiemens Sinec Infrastructure Network Services31/8/202117/6/2026
`@npmcli/arborist`, the library that calculates dependency trees and manages the `node_modules` folder hierarchy for the npm command line interface, aims to guarantee that package dependency contracts will be met, and the extraction of package contents will always be performed into the expected folder. This is, in…
ModificadaAlta (8.6)1.3%—Npmjs TAROracle GraalvmSiemens Sinec Infrastructure Network Services31/8/202117/6/2026
The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be outside of the extraction target directory is not extracted. This is, in part,…
ModificadaAlta (8.6)1.8%—Npmjs TARDebian LinuxOracle GraalvmSiemens Sinec Infrastructure Network Services31/8/202117/6/2026
The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that…
ModificadaAlta (8.6)3.3%—Npmjs TARDebian LinuxOracle GraalvmSiemens Sinec Infrastructure Network Services31/8/202117/6/2026
The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that…
ModificadaMedia (5.3)3.6%—Npmjs Hosted-git-infoSiemens Sinec Infrastructure Network Services23/3/202117/6/2026
The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity.
ModificadaAlta (7.5)3.5%—Npmjs Npm-user-validate27/10/202017/6/2026
This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.
ModificadaMedia (4.4)0.40%—Npmjs NPMOpensuse LeapFedoraproject Fedora7/7/202017/6/2026
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>". The password value is not redacted and is printed to stdout and also to any generated log files.
ModificadaMedia (6.5)2.1%—Npmjs NPMOpensuse LeapOracle GraalvmFedoraproject Fedora+213/12/201917/6/2026
Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of packages that also…
ModificadaAlta (8.1)3.4%—Npmjs NPMOpensuse LeapOracle GraalvmFedoraproject Fedora+213/12/201917/6/2026
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field would allow a package publisher to modify and/or gain access to…
ModificadaMedia (6.5)3.3%—Redhat Enterprise LinuxRedhat Enterprise Linux EUSNpmjs NPMOpensuse Leap+213/12/201917/6/2026
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a…
ModificadaAlta (8.1)1.1%—Cnpmjs Operadriver31/5/201817/6/2026
operadriver is a Opera Driver for Selenium. operadriver versions below 0.2.3 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network…
ModificadaAlta (7.8)0.32%—Npmjs NPM22/2/201817/6/2026
An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by an "npm upgrade -g npm" command, and also announced in the vendor's blog without mention of pre-release status). It might allow local users to bypass intended filesystem access restrictions…
ModificadaAlta (7.5)6.7%—IBM SDKNodejs Node.jsNpmjs NPM2/7/201617/6/2026
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.