Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
48 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.52% | — | Webpack.js Webpack-dev-server | 3/7/2026 | 7/7/2026 | webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends either a normal HTTP request with a malformed Host header or a WebSocket upgrade to the default /ws endpoint with a malformed Origin header. The malformed value causes an uncaught exception in the… | |
| Analizada | Media (4.7) | 0.52% | — | Webpack.js Webpack-dev-server | 3/7/2026 | 7/7/2026 | webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the request originated from the dev server's own page. Any website a developer visits… | |
| Analizada | Media (4.3) | 0.23% | — | Webpack.js Webpack-dev-server | 15/6/2026 | 17/6/2026 | Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the proxy target. This leaks the browser's cookies and Origin header to the backend, bypasses the dev server's Host/Origin validation, and… | |
| Analizada | Media (6.5) | 0.35% | — | Webpack.js Webpack-dev-server | 12/5/2026 | 17/6/2026 | webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving over a non-potentially trustworthy origin such as plain HTTP. The previous fix relied on the Sec-Fetch-Mode and Sec-Fetch-Site request headers, which browsers omit for non-trustworthy origins,… | |
| Analizada | Media (6.5) | 0.34% | — | Webpack.js Webpack-dev-server | 3/6/2025 | 17/6/2026 | webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version 5.2.1, webpack-dev-server users' source code may be stolen when you access a malicious web site with non-Chromium based browser. The `Origin` header is checked to prevent Cross-site WebSocket… | |
| Analizada | Media (5.9) | 0.57% | — | Webpack.js Webpack-dev-server | 3/6/2025 | 17/6/2026 | webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version 5.2.1, webpack-dev-server users' source code may be stolen when they access a malicious web site. Because the request for classic script by a script tag is not subject to same origin policy, an… | |
| Aplazada | Alta (7.8) | 0.19% | — | Vserver V-serverAIVserver V-server LiteAI | 28/11/2024 | 17/6/2026 | There is an Out-of-bounds read vulnerability in V-Server (v4.0.19.0 and earlier) and V-Server Lite (v4.0.19.0 and earlier). If a user opens a specially crafted file, information may be disclosed and/or arbitrary code may be executed. | |
| Modificada | Alta (7.8) | 0.29% | — | Fujielectric V-server | 15/11/2023 | 17/6/2026 | Multiple heap-based buffer overflow vulnerabilities exist in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a user opens a specially crafted VPR file, information may be disclosed and/or arbitrary code may be executed. | |
| Modificada | Alta (7.8) | 0.27% | — | Fujielectric V-server | 15/11/2023 | 17/6/2026 | Out-of-bounds read vulnerability exists in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a user opens a specially crafted VPR file, information may be disclosed and/or arbitrary code may be executed. | |
| Modificada | Alta (7.8) | 0.27% | — | Fujielectric V-server | 15/11/2023 | 17/6/2026 | Out-of-bounds write vulnerability exists in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a user opens a specially crafted VPR file, information may be disclosed and/or arbitrary code may be executed. | |
| Modificada | Alta (7.8) | 0.27% | — | Fujielectric V-server | 19/6/2023 | 17/6/2026 | Stack-based buffer overflow vulnerability in V-Server v4.0.15.0 and V-Server Lite v4.0.15.0 and earlier allows an attacker to execute arbitrary code by having user open a specially crafted VPR file. | |
| Modificada | Alta (7.8) | 0.25% | — | Fujielectric V-server | 3/1/2023 | 17/6/2026 | Stack-based buffer overflow vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrary code by having a user to open a specially crafted project file. | |
| Modificada | Alta (7.8) | 0.23% | — | Fujielectric V-server | 3/1/2023 | 17/6/2026 | Out-of-bounds write vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrary code by having a user to open a specially crafted project file. | |
| Modificada | Alta (7.8) | 0.23% | — | Fujielectric V-server | 3/1/2023 | 17/6/2026 | Out-of-bounds read vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrary code by having a user to open a specially crafted project file. | |
| Modificada | Alta (7.5) | 1.4% | — | Lite-dev-server Project Lite-dev-server | 21/12/2022 | 17/6/2026 | All versions of package lite-dev-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url user input that is passed to the server code. | |
| Modificada | Alta (7.5) | 1.0% | — | Static-dev-server Project Static-dev-server | 29/11/2022 | 17/6/2026 | This affects all versions of package static-dev-server. This is because when paths from users to the root directory are joined, the assets for the path accessed are relative to that of the root directory. | |
| Modificada | Alta (7.8) | 0.92% | — | Fujielectric V-server | 16/6/2022 | 17/6/2026 | Out-of-bounds read vulnerability exists in V-Server v4.0.11.0 and earlier and V-Server Lite v4.0.13.0 and earlier, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file. | |
| Modificada | Alta (7.8) | 0.92% | — | Fujielectric V-server | 14/6/2022 | 17/6/2026 | Out-of-bounds write vulnerability exists in V-Server v4.0.11.0 and earlier and V-Server Lite v4.0.13.0 and earlier, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file. | |
| Modificada | Alta (7.8) | 0.78% | — | Fujielectric V-serverFujielectric V-sft | 14/6/2022 | 17/6/2026 | Use after free vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file. | |
| Modificada | Alta (7.8) | 0.92% | — | Fujielectric V-serverFujielectric V-sft | 14/6/2022 | 17/6/2026 | Out-of-bounds read vulnerability exist in the simulator module contained in the graphic editor 'V-SFT' v6.1.3.0 and earlier, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file. | |
| Modificada | Alta (7.1) | 0.75% | — | Fujielectric V-serverFujielectric V-simulator | 20/12/2021 | 17/6/2026 | Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to an out-of-bounds read, which may allow an attacker to read sensitive information from other memory locations or cause a crash. | |
| Modificada | Alta (7.8) | 0.91% | — | Fujielectric V-serverFujielectric V-simulator | 20/12/2021 | 17/6/2026 | Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to an out-of-bounds write, which can result in data corruption, a system crash, or code execution. | |
| Modificada | Alta (7.8) | 0.97% | — | Fujielectric V-serverFujielectric V-simulator | 20/12/2021 | 17/6/2026 | Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable a heap-based buffer overflow when parsing a specially crafted project file, which may allow an attacker to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.98% | — | Fujielectric V-serverFujielectric V-simulator | 20/12/2021 | 17/6/2026 | Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to a stack-based buffer overflow, which may allow an attacker to achieve code execution. | |
| Modificada | Alta (7.8) | 0.69% | — | Fujielectric V-serverFujielectric V-simulator | 20/12/2021 | 17/6/2026 | Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to an access of uninitialized pointer, which may allow an attacker read from or write to unexpected memory locations, leading to a denial-of-service. |