Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
86 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.94% | — | Khanacademy Simple-markdown | 12/2/2023 | 17/6/2026 | A vulnerability has been found in simple-markdown 0.5.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file simple-markdown.js. The manipulation leads to inefficient regular expression complexity. The attack can be launched remotely. Upgrading to version 0.5.2 is able… | |
| Modificada | Alta (7.5) | 1.1% | — | Khanacademy Simple-markdown | 12/2/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in simple-markdown 0.6.0. Affected is an unknown function of the file simple-markdown.js. The manipulation with the input <<<<<<<<<<:/:/:/:/:/:/:/:/:/:/ leads to inefficient regular expression complexity. It is possible to launch the attack remotely. The… | |
| Modificada | Alta (7.5) | 0.95% | — | Markdown-it Project Markdown-it | 27/12/2022 | 17/6/2026 | A vulnerability was found in markdown-it up to 2.x. It has been classified as problematic. Affected is an unknown function of the file lib/common/html_re.js. The manipulation leads to inefficient regular expression complexity. Upgrading to version 3.0.0 is able to address this issue. The name of the patch is… | |
| Modificada | Crítica (9.8) | 0.97% | — | Markdown Preview Enhanced Project Markdown Preview Enhanced | 7/12/2022 | 17/6/2026 | An issue in Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom allows attackers to execute arbitrary commands during the GFM export process. | |
| Modificada | Crítica (9.8) | 35% | — | Markdown Preview Enhanced Project Markdown Preview Enhanced | 7/12/2022 | 17/6/2026 | Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerability via the PDF file import function. | |
| Modificada | Media (5.5) | 0.38% | — | Markdownify Project Markdownify | 3/11/2022 | 17/6/2026 | Markdownify version 1.4.1 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious markdown file through Markdownify. This is possible because the application does not have a CSP policy (or at least not strict enough) and/or does not properly validate the… | |
| Modificada | Alta (7.8) | 0.45% | — | Markdownify Project Markdownify | 19/10/2022 | 17/6/2026 | Markdownify version 1.4.1 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Markdownify. This is possible because the application has the "nodeIntegration" option enabled. | |
| Modificada | Media (5.4) | 0.50% | — | Inkdrop Markdown Nice | 9/9/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Community Posting field. | |
| Modificada | Media (4.7) | 0.86% | — | Ckeditor5-html-embedCkeditor5-html-supportCkeditor5-markdown-gfm | 3/8/2022 | 17/6/2026 | CKEditor 5 is a JavaScript rich text editor. A cross-site scripting vulnerability has been discovered affecting three optional CKEditor 5's packages in versions prior to 35.0.1. The vulnerability allowed to trigger a JavaScript code after fulfilling special conditions. The affected packages are… | |
| Modificada | Media (6.1) | 0.60% | — | Markdown-it-decorate Project Markdown-it-decorate | 25/7/2022 | 17/6/2026 | This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link. | |
| Modificada | Media (6.1) | 0.60% | — | Markdown-it-toc Project Markdown-it-toc | 25/7/2022 | 17/6/2026 | This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped. | |
| Modificada | Alta (7.5) | 1.1% | — | Markdown-link-extractor Project Markdown-link-extractor | 2/6/2022 | 17/6/2026 | An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package, when an attacker is able to supply arbitrary input to the module's exported function | |
| Modificada | Media (5.3) | 2.3% | — | Markdown-it Project Markdown-it | 10/1/2022 | 17/6/2026 | markdown-it is a Markdown parser. Prior to version 1.3.2, special patterns with length greater than 50 thousand characterss could slow down the parser significantly. Users should upgrade to version 12.3.2 to receive a patch. There are no known workarounds aside from upgrading. | |
| Modificada | Crítica (9.8) | 5.4% | — | Markdown TO PDF Project Markdown TO PDF | 10/12/2021 | 17/6/2026 | The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine. | |
| Modificada | Media (6.1) | 1.7% | — | Paste-markdown Project Paste-markdown | 12/8/2021 | 17/6/2026 | @github/paste-markdown is an npm package for pasting markdown objects. A self Cross-Site Scripting vulnerability exists in the @github/paste-markdown before version 0.3.4. If the clipboard data contains the string `<table>`, a **div** is dynamically created, and the clipboard content is copied into its **innerHTML**… | |
| Modificada | Media (5.4) | 1.1% | — | Jenkins Markdown Formatter | 25/5/2021 | 17/6/2026 | Jenkins Markdown Formatter Plugin 0.1.0 and earlier does not sanitize crafted link target URLs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to edit any description rendered using the configured markup formatter. | |
| Modificada | Media (6.5) | 1.7% | — | Ckeditor5-engineCkeditor5-fontCkeditor5-imageCkeditor5-list+4 | 29/4/2021 | 17/6/2026 | CKEditor 5 provides a WYSIWYG editing solution. This CVE affects the following npm packages: ckeditor5-engine, ckeditor5-font, ckeditor5-image, ckeditor5-list, ckeditor5-markdown-gfm, ckeditor5-media-embed, ckeditor5-paste-from-office, and ckeditor5-widget. Following an internal audit, a regular expression denial of… | |
| Modificada | Alta (7.5) | 2.2% | — | Markdown2 Project Markdown2Fedoraproject Fedora | 3/3/2021 | 17/6/2026 | markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicious string, it can make markdown2 processing difficult or delayed for an extended period of time. | |
| Modificada | Media (6.1) | 1.4% | — | Markdown-it-highlightjs Project Markdown-it-highlightjs | 16/11/2020 | 17/6/2026 | — | |
| Modificada | Alta (7.5) | 1.4% | — | Peg-markdown Project Peg-markdown | 23/9/2020 | 17/6/2026 | peg-markdown 0.4.14 has a NULL pointer dereference in process_raw_blocks in markdown_lib.c. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (6.5) | 1.6% | — | Github Flavored Markdown Project Github Flavored MarkdownFedoraproject Fedora | 1/7/2020 | 17/6/2026 | The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a markdown table which would take an unreasonably long time to process, causing a denial of service. This issue does not affect the upstream cmark project. The issue has been… | |
| Modificada | Media (6.1) | 1.9% | — | Python-markdown2 Project Python-markdown2 | 20/4/2020 | 17/6/2026 | python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute. | |
| Modificada | Media (6.1) | 0.77% | — | Python-markdown2 Project Python-markdown2 | 15/1/2020 | 16/6/2026 | python-markdown2 before 1.0.1.14 has multiple cross-site scripting (XSS) issues. | |
| Modificada | Crítica (9.8) | 14% | — | Oracle Application Testing SuiteOracle Banking Enterprise CollectionsOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+18 | 16/10/2019 | 17/6/2026 | Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and… | |
| Modificada | Media (6.1) | 1.3% | — | Khanacademy Simple-markdownFedoraproject Fedora | 9/4/2019 | 17/6/2026 | simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI. |