Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

86 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.94%—Khanacademy Simple-markdown12/2/202317/6/2026
A vulnerability has been found in simple-markdown 0.5.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file simple-markdown.js. The manipulation leads to inefficient regular expression complexity. The attack can be launched remotely. Upgrading to version 0.5.2 is able…
ModificadaAlta (7.5)1.1%—Khanacademy Simple-markdown12/2/202317/6/2026
A vulnerability, which was classified as problematic, was found in simple-markdown 0.6.0. Affected is an unknown function of the file simple-markdown.js. The manipulation with the input <<<<<<<<<<:/:/:/:/:/:/:/:/:/:/ leads to inefficient regular expression complexity. It is possible to launch the attack remotely. The…
ModificadaAlta (7.5)0.95%—Markdown-it Project Markdown-it27/12/202217/6/2026
A vulnerability was found in markdown-it up to 2.x. It has been classified as problematic. Affected is an unknown function of the file lib/common/html_re.js. The manipulation leads to inefficient regular expression complexity. Upgrading to version 3.0.0 is able to address this issue. The name of the patch is…
ModificadaCrítica (9.8)0.97%—Markdown Preview Enhanced Project Markdown Preview Enhanced7/12/202217/6/2026
An issue in Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom allows attackers to execute arbitrary commands during the GFM export process.
ModificadaCrítica (9.8)35%—Markdown Preview Enhanced Project Markdown Preview Enhanced7/12/202217/6/2026
Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerability via the PDF file import function.
ModificadaMedia (5.5)0.38%—Markdownify Project Markdownify3/11/202217/6/2026
Markdownify version 1.4.1 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious markdown file through Markdownify. This is possible because the application does not have a CSP policy (or at least not strict enough) and/or does not properly validate the…
ModificadaAlta (7.8)0.45%—Markdownify Project Markdownify19/10/202217/6/2026
Markdownify version 1.4.1 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Markdownify. This is possible because the application has the "nodeIntegration" option enabled.
ModificadaMedia (5.4)0.50%—Inkdrop Markdown Nice9/9/202217/6/2026
A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Community Posting field.
ModificadaMedia (4.7)0.86%—Ckeditor5-html-embedCkeditor5-html-supportCkeditor5-markdown-gfm3/8/202217/6/2026
CKEditor 5 is a JavaScript rich text editor. A cross-site scripting vulnerability has been discovered affecting three optional CKEditor 5's packages in versions prior to 35.0.1. The vulnerability allowed to trigger a JavaScript code after fulfilling special conditions. The affected packages are…
ModificadaMedia (6.1)0.60%—Markdown-it-decorate Project Markdown-it-decorate25/7/202217/6/2026
This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link.
ModificadaMedia (6.1)0.60%—Markdown-it-toc Project Markdown-it-toc25/7/202217/6/2026
This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.
ModificadaAlta (7.5)1.1%—Markdown-link-extractor Project Markdown-link-extractor2/6/202217/6/2026
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package, when an attacker is able to supply arbitrary input to the module's exported function
ModificadaMedia (5.3)2.3%—Markdown-it Project Markdown-it10/1/202217/6/2026
markdown-it is a Markdown parser. Prior to version 1.3.2, special patterns with length greater than 50 thousand characterss could slow down the parser significantly. Users should upgrade to version 12.3.2 to receive a patch. There are no known workarounds aside from upgrading.
ModificadaCrítica (9.8)5.4%—Markdown TO PDF Project Markdown TO PDF10/12/202117/6/2026
The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine.
ModificadaMedia (6.1)1.7%—Paste-markdown Project Paste-markdown12/8/202117/6/2026
@github/paste-markdown is an npm package for pasting markdown objects. A self Cross-Site Scripting vulnerability exists in the @github/paste-markdown before version 0.3.4. If the clipboard data contains the string `<table>`, a **div** is dynamically created, and the clipboard content is copied into its **innerHTML**…
ModificadaMedia (5.4)1.1%—Jenkins Markdown Formatter25/5/202117/6/2026
Jenkins Markdown Formatter Plugin 0.1.0 and earlier does not sanitize crafted link target URLs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to edit any description rendered using the configured markup formatter.
ModificadaMedia (6.5)1.7%—Ckeditor5-engineCkeditor5-fontCkeditor5-imageCkeditor5-list+429/4/202117/6/2026
CKEditor 5 provides a WYSIWYG editing solution. This CVE affects the following npm packages: ckeditor5-engine, ckeditor5-font, ckeditor5-image, ckeditor5-list, ckeditor5-markdown-gfm, ckeditor5-media-embed, ckeditor5-paste-from-office, and ckeditor5-widget. Following an internal audit, a regular expression denial of…
ModificadaAlta (7.5)2.2%—Markdown2 Project Markdown2Fedoraproject Fedora3/3/202117/6/2026
markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicious string, it can make markdown2 processing difficult or delayed for an extended period of time.
ModificadaMedia (6.1)1.4%—Markdown-it-highlightjs Project Markdown-it-highlightjs16/11/202017/6/2026
—
ModificadaAlta (7.5)1.4%—Peg-markdown Project Peg-markdown23/9/202017/6/2026
peg-markdown 0.4.14 has a NULL pointer dereference in process_raw_blocks in markdown_lib.c. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
ModificadaMedia (6.5)1.6%—Github Flavored Markdown Project Github Flavored MarkdownFedoraproject Fedora1/7/202017/6/2026
The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a markdown table which would take an unreasonably long time to process, causing a denial of service. This issue does not affect the upstream cmark project. The issue has been…
ModificadaMedia (6.1)1.9%—Python-markdown2 Project Python-markdown220/4/202017/6/2026
python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute.
ModificadaMedia (6.1)0.77%—Python-markdown2 Project Python-markdown215/1/202016/6/2026
python-markdown2 before 1.0.1.14 has multiple cross-site scripting (XSS) issues.
ModificadaCrítica (9.8)14%—Oracle Application Testing SuiteOracle Banking Enterprise CollectionsOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+1816/10/201917/6/2026
Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and…
ModificadaMedia (6.1)1.3%—Khanacademy Simple-markdownFedoraproject Fedora9/4/201917/6/2026
simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI.