Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2748▲ 38 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

148 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.6)0.37%—CheerioAIMicrosoft PlaywrightAIPuppeteerAIFlowiseai FlowiseAI15/9/202617/9/2026
Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services, and private network resources with response content returned as…
AplazadaMedia (6.3)0.37%—Huly PlatformAIPuppeteerAI14/9/202624/9/2026
Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer renders and returns as downloadable PDFs or images, enabling access to…
Pendiente de análisisAlta (8.6)1.3%—Puppet EnterpriseAI11/9/202618/9/2026
Affected versions of Puppet Enterprise contain a command injection vulnerability. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this parameter, which is passed to a shell execution context without sufficient sanitization.…
Pendiente de análisisMedia (6.7)0.11%—Puppet Resource APIAIPuppet CoreAIPuppet EnterpriseAI3/7/20266/7/2026
Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing values such as passwords to be stored in cleartext in the agent's local transaction state cache. Affected versions of the resource_api…
AplazadaMedia (6.9)0.19%—Puppet EnterpriseAI24/9/202525/9/2026
In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant database was not excluded from the files gathered by Puppet backup. The key is only present on the system if the user has a Puppet Enterprise Advanced license and has enabled the Infra Assistant…
ModificadaAlta (8.6)1.1%—Puppet Enterprise26/6/20254/9/2026
A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary host. It affects Puppet Enterprise versions 2018.1.8 through 2023.8.3 and 2025.3 and has been resolved in versions 2023.8.4 and 2025.4.0.
AplazadaMedia (6.6)0.55%—Puppet AgentAI7/2/202517/6/2026
Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release.
AplazadaMedia (5.4)0.17%—Puppet PeadmAI27/9/202417/6/2026
In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered.
AplazadaMedia (6.5)2.6%—Puppeteer-rendererAI17/6/202417/6/2026
puppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal. Attackers can exploit the URL parameter using the file protocol to read sensitive information from the server.
ModificadaCrítica (9.8)0.50%—Puppet Enterprise7/11/202317/6/2026
Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.
ModificadaCrítica (9.8)0.37%—Puppet Bolt6/10/202317/6/2026
In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.
ModificadaAlta (7.5)0.41%—Puppet EnterprisePuppet Server3/10/202317/6/2026
For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.
ModificadaCrítica (9.8)1.1%—Puppet Enterprise7/6/202317/6/2026
A privilege escalation allowing remote code execution was discovered in the orchestration service.
ModificadaMedia (5.3)0.44%—Puppet EnterprisePuppet Server4/5/202317/6/2026
A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations.
ModificadaAlta (7.8)1.2%—Helecloud Puppet-facter26/1/202317/6/2026
All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization.
ModificadaAlta (8.8)1.7%—Puppetlabs-mysql7/10/202217/6/2026
Command injection is possible in the puppetlabs-mysql module prior to version 13.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of Puppet and Puppet Enterprise.
ModificadaCrítica (9.8)2.2%—Puppetlabs-mysqlFedoraproject Fedora7/10/202217/6/2026
Command injection is possible in the puppetlabs-apt module prior to version 9.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of Puppet and Puppet Enterprise.
ModificadaBaja (3.5)0.52%—Perforce Puppet Bolt19/7/202217/6/2026
Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being logged when run programmatically, such as via Puppet Enterprise.
ModificadaCrítica (9.8)0.92%—Puppet Firewall2/3/202217/6/2026
In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unmanaged rules to exist on the target system and leave the system in an unsafe state.
ModificadaMedia (4.4)0.25%—PuppetPuppet ConnectPuppet Enterprise18/11/202117/6/2026
A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged
ModificadaMedia (6.5)1.1%—PuppetPuppet AgentPuppet EnterpriseFedoraproject Fedora18/11/202117/6/2026
A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.
ModificadaAlta (8.1)0.82%—Puppet Continuous Delivery18/11/202117/6/2026
A flaw was discovered in Continuous Delivery for Puppet Enterprise (CD4PE) that results in a user with lower privileges being able to access a Puppet Enterprise API token. This issue is resolved in CD4PE 4.10.0
ModificadaCrítica (9.8)1.4%—Puppet AgentPuppet EnterprisePuppet ServerFedoraproject Fedora18/11/202117/6/2026
A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007
ModificadaMedia (4.9)0.92%—PuppetPuppet Enterprise7/9/202117/6/2026
A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory service nodes).
ModificadaAlta (8.8)1.1%—Puppet Enterprise30/8/202117/6/2026
Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.