Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 2.8% | — | Npmjs Semver | 21/6/2023 | 17/6/2026 | Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range. | |
| Modificada | Alta (7.5) | 3.9% | — | Npmjs NPMNetapp Ontap Select Deploy Administration Utility | 13/6/2022 | 17/6/2026 | npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files… | |
| Modificada | Crítica (9.8) | 2.7% | — | Npmjs NPMNetapp Next Generation Application Programming InterfaceFedoraproject Fedora | 13/11/2021 | 17/6/2026 | The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact… | |
| Modificada | Alta (7.8) | 0.55% | — | Npmjs ArboristOracle GraalvmSiemens Sinec Infrastructure Network Services | 31/8/2021 | 17/6/2026 | `@npmcli/arborist`, the library that calculates dependency trees and manages the node_modules folder hierarchy for the npm command line interface, aims to guarantee that package dependency contracts will be met, and the extraction of package contents will always be performed into the expected folder. This is… | |
| Modificada | Alta (7.8) | 0.58% | — | Npmjs ArboristOracle GraalvmSiemens Sinec Infrastructure Network Services | 31/8/2021 | 17/6/2026 | `@npmcli/arborist`, the library that calculates dependency trees and manages the `node_modules` folder hierarchy for the npm command line interface, aims to guarantee that package dependency contracts will be met, and the extraction of package contents will always be performed into the expected folder. This is, in… | |
| Modificada | Alta (8.6) | 1.3% | — | Npmjs TAROracle GraalvmSiemens Sinec Infrastructure Network Services | 31/8/2021 | 17/6/2026 | The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be outside of the extraction target directory is not extracted. This is, in part,… | |
| Modificada | Alta (8.6) | 1.8% | — | Npmjs TARDebian LinuxOracle GraalvmSiemens Sinec Infrastructure Network Services | 31/8/2021 | 17/6/2026 | The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that… | |
| Modificada | Alta (8.6) | 3.3% | — | Npmjs TARDebian LinuxOracle GraalvmSiemens Sinec Infrastructure Network Services | 31/8/2021 | 17/6/2026 | The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that… | |
| Modificada | Media (5.3) | 3.6% | — | Npmjs Hosted-git-infoSiemens Sinec Infrastructure Network Services | 23/3/2021 | 17/6/2026 | The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity. | |
| Modificada | Alta (7.5) | 3.5% | — | Npmjs Npm-user-validate | 27/10/2020 | 17/6/2026 | This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters. | |
| Modificada | Media (4.4) | 0.40% | — | Npmjs NPMOpensuse LeapFedoraproject Fedora | 7/7/2020 | 17/6/2026 | Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>". The password value is not redacted and is printed to stdout and also to any generated log files. | |
| Modificada | Media (6.5) | 2.1% | — | Npmjs NPMOpensuse LeapOracle GraalvmFedoraproject Fedora+2 | 13/12/2019 | 17/6/2026 | Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of packages that also… | |
| Modificada | Alta (8.1) | 3.4% | — | Npmjs NPMOpensuse LeapOracle GraalvmFedoraproject Fedora+2 | 13/12/2019 | 17/6/2026 | Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field would allow a package publisher to modify and/or gain access to… | |
| Modificada | Media (6.5) | 3.3% | — | Redhat Enterprise LinuxRedhat Enterprise Linux EUSNpmjs NPMOpensuse Leap+2 | 13/12/2019 | 17/6/2026 | Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a… | |
| Modificada | Alta (8.1) | 1.1% | — | Cnpmjs Operadriver | 31/5/2018 | 17/6/2026 | operadriver is a Opera Driver for Selenium. operadriver versions below 0.2.3 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network… | |
| Modificada | Alta (7.8) | 0.32% | — | Npmjs NPM | 22/2/2018 | 17/6/2026 | An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by an "npm upgrade -g npm" command, and also announced in the vendor's blog without mention of pre-release status). It might allow local users to bypass intended filesystem access restrictions… | |
| Modificada | Alta (7.5) | 6.7% | — | IBM SDKNodejs Node.jsNpmjs NPM | 2/7/2016 | 17/6/2026 | The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers. |