Total alertas: 196
Por severidad: {'medium': 112, 'high': 65, 'low': 14, 'critical': 5}

--- CVEs únicos críticos/altos ---
Total CVEs únicos críticos+altos: 47
  [    high] CVE-2026-42033     axios                          Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and 
  [    high] CVE-2026-42035     axios                          Axios: Header Injection via Prototype Pollution
  [    high] CVE-2026-42043     axios                          Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 
  [    high] CVE-2026-42264     axios                          Axios has prototype pollution read-side gadgets in HTTP adapter that allow crede
  [    high] CVE-2026-33671     picomatch                      Picomatch has a ReDoS vulnerability via extglob quantifiers
  [    high] CVE-2026-27903     minimatch                      minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adja
  [    high] CVE-2026-27904     minimatch                      minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regu
  [    high] CVE-2026-27606     rollup                         Rollup 4 has Arbitrary File Write via Path Traversal
  [    high] CVE-2026-26996     minimatch                      minimatch has a ReDoS via repeated wildcards with non-matching literal in patter
  [    high] CVE-2026-25639     axios                          Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
  [    high] CVE-2026-44705     tmp                            tmp has Path Traversal via unsanitized prefix/postfix that enables directory esc
  [    high] CVE-2026-6322      fast-uri                       fast-uri vulnerable to host confusion via percent-encoded authority delimiters
  [    high] CVE-2026-6321      fast-uri                       fast-uri vulnerable to path traversal via percent-encoded dot segments
  [    high] CVE-2026-40879     @nestjs/microservices          Nest Affected by DoS via Recursive handleData in JsonSocket (TCP Transport)
  [    high] CVE-2026-4800      lodash                         lodash vulnerable to Code Injection via `_.template` imports key names
