Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2748▲ 38 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
148 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.6) | 0.37% | — | CheerioAIMicrosoft PlaywrightAIPuppeteerAIFlowiseai FlowiseAI | 15/9/2026 | 17/9/2026 | Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services, and private network resources with response content returned as… | |
| Aplazada | Media (6.3) | 0.37% | — | Huly PlatformAIPuppeteerAI | 14/9/2026 | 24/9/2026 | Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer renders and returns as downloadable PDFs or images, enabling access to… | |
| Pendiente de análisis | Alta (8.6) | 1.3% | — | Puppet EnterpriseAI | 11/9/2026 | 18/9/2026 | Affected versions of Puppet Enterprise contain a command injection vulnerability. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this parameter, which is passed to a shell execution context without sufficient sanitization.… | |
| Pendiente de análisis | Media (6.7) | 0.11% | — | Puppet Resource APIAIPuppet CoreAIPuppet EnterpriseAI | 3/7/2026 | 6/7/2026 | Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing values such as passwords to be stored in cleartext in the agent's local transaction state cache. Affected versions of the resource_api… | |
| Aplazada | Media (6.9) | 0.19% | — | Puppet EnterpriseAI | 24/9/2025 | 25/9/2026 | In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant database was not excluded from the files gathered by Puppet backup. The key is only present on the system if the user has a Puppet Enterprise Advanced license and has enabled the Infra Assistant… | |
| Modificada | Alta (8.6) | 1.1% | — | Puppet Enterprise | 26/6/2025 | 4/9/2026 | A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary host. It affects Puppet Enterprise versions 2018.1.8 through 2023.8.3 and 2025.3 and has been resolved in versions 2023.8.4 and 2025.4.0. | |
| Aplazada | Media (6.6) | 0.55% | — | Puppet AgentAI | 7/2/2025 | 17/6/2026 | Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release. | |
| Aplazada | Media (5.4) | 0.17% | — | Puppet PeadmAI | 27/9/2024 | 17/6/2026 | In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered. | |
| Aplazada | Media (6.5) | 2.6% | — | Puppeteer-rendererAI | 17/6/2024 | 17/6/2026 | puppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal. Attackers can exploit the URL parameter using the file protocol to read sensitive information from the server. | |
| Modificada | Crítica (9.8) | 0.50% | — | Puppet Enterprise | 7/11/2023 | 17/6/2026 | Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations. | |
| Modificada | Crítica (9.8) | 0.37% | — | Puppet Bolt | 6/10/2023 | 17/6/2026 | In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified. | |
| Modificada | Alta (7.5) | 0.41% | — | Puppet EnterprisePuppet Server | 3/10/2023 | 17/6/2026 | For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked. | |
| Modificada | Crítica (9.8) | 1.1% | — | Puppet Enterprise | 7/6/2023 | 17/6/2026 | A privilege escalation allowing remote code execution was discovered in the orchestration service. | |
| Modificada | Media (5.3) | 0.44% | — | Puppet EnterprisePuppet Server | 4/5/2023 | 17/6/2026 | A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations. | |
| Modificada | Alta (7.8) | 1.2% | — | Helecloud Puppet-facter | 26/1/2023 | 17/6/2026 | All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization. | |
| Modificada | Alta (8.8) | 1.7% | — | Puppetlabs-mysql | 7/10/2022 | 17/6/2026 | Command injection is possible in the puppetlabs-mysql module prior to version 13.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of Puppet and Puppet Enterprise. | |
| Modificada | Crítica (9.8) | 2.2% | — | Puppetlabs-mysqlFedoraproject Fedora | 7/10/2022 | 17/6/2026 | Command injection is possible in the puppetlabs-apt module prior to version 9.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of Puppet and Puppet Enterprise. | |
| Modificada | Baja (3.5) | 0.52% | — | Perforce Puppet Bolt | 19/7/2022 | 17/6/2026 | Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being logged when run programmatically, such as via Puppet Enterprise. | |
| Modificada | Crítica (9.8) | 0.92% | — | Puppet Firewall | 2/3/2022 | 17/6/2026 | In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unmanaged rules to exist on the target system and leave the system in an unsafe state. | |
| Modificada | Media (4.4) | 0.25% | — | PuppetPuppet ConnectPuppet Enterprise | 18/11/2021 | 17/6/2026 | A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged | |
| Modificada | Media (6.5) | 1.1% | — | PuppetPuppet AgentPuppet EnterpriseFedoraproject Fedora | 18/11/2021 | 17/6/2026 | A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'. | |
| Modificada | Alta (8.1) | 0.82% | — | Puppet Continuous Delivery | 18/11/2021 | 17/6/2026 | A flaw was discovered in Continuous Delivery for Puppet Enterprise (CD4PE) that results in a user with lower privileges being able to access a Puppet Enterprise API token. This issue is resolved in CD4PE 4.10.0 | |
| Modificada | Crítica (9.8) | 1.4% | — | Puppet AgentPuppet EnterprisePuppet ServerFedoraproject Fedora | 18/11/2021 | 17/6/2026 | A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007 | |
| Modificada | Media (4.9) | 0.92% | — | PuppetPuppet Enterprise | 7/9/2021 | 17/6/2026 | A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory service nodes). | |
| Modificada | Alta (8.8) | 1.1% | — | Puppet Enterprise | 30/8/2021 | 17/6/2026 | Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export. |