Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
–

48 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.52%—Webpack.js Webpack-dev-server3/7/20267/7/2026
webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends either a normal HTTP request with a malformed Host header or a WebSocket upgrade to the default /ws endpoint with a malformed Origin header. The malformed value causes an uncaught exception in the…
AnalizadaMedia (4.7)0.52%—Webpack.js Webpack-dev-server3/7/20267/7/2026
webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the request originated from the dev server's own page. Any website a developer visits…
AnalizadaMedia (4.3)0.23%—Webpack.js Webpack-dev-server15/6/202617/6/2026
Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the proxy target. This leaks the browser's cookies and Origin header to the backend, bypasses the dev server's Host/Origin validation, and…
AnalizadaMedia (6.5)0.35%—Webpack.js Webpack-dev-server12/5/202617/6/2026
webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving over a non-potentially trustworthy origin such as plain HTTP. The previous fix relied on the Sec-Fetch-Mode and Sec-Fetch-Site request headers, which browsers omit for non-trustworthy origins,…
AnalizadaMedia (6.5)0.34%—Webpack.js Webpack-dev-server3/6/202517/6/2026
webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version 5.2.1, webpack-dev-server users' source code may be stolen when you access a malicious web site with non-Chromium based browser. The `Origin` header is checked to prevent Cross-site WebSocket…
AnalizadaMedia (5.9)0.57%—Webpack.js Webpack-dev-server3/6/202517/6/2026
webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version 5.2.1, webpack-dev-server users' source code may be stolen when they access a malicious web site. Because the request for classic script by a script tag is not subject to same origin policy, an…
AplazadaAlta (7.8)0.19%—Vserver V-serverAIVserver V-server LiteAI28/11/202417/6/2026
There is an Out-of-bounds read vulnerability in V-Server (v4.0.19.0 and earlier) and V-Server Lite (v4.0.19.0 and earlier). If a user opens a specially crafted file, information may be disclosed and/or arbitrary code may be executed.
ModificadaAlta (7.8)0.29%—Fujielectric V-server15/11/202317/6/2026
Multiple heap-based buffer overflow vulnerabilities exist in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a user opens a specially crafted VPR file, information may be disclosed and/or arbitrary code may be executed.
ModificadaAlta (7.8)0.27%—Fujielectric V-server15/11/202317/6/2026
Out-of-bounds read vulnerability exists in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a user opens a specially crafted VPR file, information may be disclosed and/or arbitrary code may be executed.
ModificadaAlta (7.8)0.27%—Fujielectric V-server15/11/202317/6/2026
Out-of-bounds write vulnerability exists in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a user opens a specially crafted VPR file, information may be disclosed and/or arbitrary code may be executed.
ModificadaAlta (7.8)0.27%—Fujielectric V-server19/6/202317/6/2026
Stack-based buffer overflow vulnerability in V-Server v4.0.15.0 and V-Server Lite v4.0.15.0 and earlier allows an attacker to execute arbitrary code by having user open a specially crafted VPR file.
ModificadaAlta (7.8)0.25%—Fujielectric V-server3/1/202317/6/2026
Stack-based buffer overflow vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrary code by having a user to open a specially crafted project file.
ModificadaAlta (7.8)0.23%—Fujielectric V-server3/1/202317/6/2026
Out-of-bounds write vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrary code by having a user to open a specially crafted project file.
ModificadaAlta (7.8)0.23%—Fujielectric V-server3/1/202317/6/2026
Out-of-bounds read vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrary code by having a user to open a specially crafted project file.
ModificadaAlta (7.5)1.4%—Lite-dev-server Project Lite-dev-server21/12/202217/6/2026
All versions of package lite-dev-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url user input that is passed to the server code.
ModificadaAlta (7.5)1.0%—Static-dev-server Project Static-dev-server29/11/202217/6/2026
This affects all versions of package static-dev-server. This is because when paths from users to the root directory are joined, the assets for the path accessed are relative to that of the root directory.
ModificadaAlta (7.8)0.92%—Fujielectric V-server16/6/202217/6/2026
Out-of-bounds read vulnerability exists in V-Server v4.0.11.0 and earlier and V-Server Lite v4.0.13.0 and earlier, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.
ModificadaAlta (7.8)0.92%—Fujielectric V-server14/6/202217/6/2026
Out-of-bounds write vulnerability exists in V-Server v4.0.11.0 and earlier and V-Server Lite v4.0.13.0 and earlier, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.
ModificadaAlta (7.8)0.78%—Fujielectric V-serverFujielectric V-sft14/6/202217/6/2026
Use after free vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.
ModificadaAlta (7.8)0.92%—Fujielectric V-serverFujielectric V-sft14/6/202217/6/2026
Out-of-bounds read vulnerability exist in the simulator module contained in the graphic editor 'V-SFT' v6.1.3.0 and earlier, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.
ModificadaAlta (7.1)0.75%—Fujielectric V-serverFujielectric V-simulator20/12/202117/6/2026
Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to an out-of-bounds read, which may allow an attacker to read sensitive information from other memory locations or cause a crash.
ModificadaAlta (7.8)0.91%—Fujielectric V-serverFujielectric V-simulator20/12/202117/6/2026
Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to an out-of-bounds write, which can result in data corruption, a system crash, or code execution.
ModificadaAlta (7.8)0.97%—Fujielectric V-serverFujielectric V-simulator20/12/202117/6/2026
Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable a heap-based buffer overflow when parsing a specially crafted project file, which may allow an attacker to execute arbitrary code.
ModificadaAlta (7.8)0.98%—Fujielectric V-serverFujielectric V-simulator20/12/202117/6/2026
Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to a stack-based buffer overflow, which may allow an attacker to achieve code execution.
ModificadaAlta (7.8)0.69%—Fujielectric V-serverFujielectric V-simulator20/12/202117/6/2026
Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to an access of uninitialized pointer, which may allow an attacker read from or write to unexpected memory locations, leading to a denial-of-service.