Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▲ 32 respecto a la semana anterior
Críticas / altas1474▲ 364 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.9)0.54%—TerragruntAIOpentofuAIHashicorp TerraformAI21/8/202625/9/2026
Terragrunt is a flexible orchestration tool that allows Infrastructure as Code written in OpenTofu or Terraform to scale. Prior to 1.0.4, Terragrunt trusts paths decoded from a downloaded module's .terragrunt-module-manifest during fileManifest.Clean() in internal/util/file.go. A malicious or compromised external…
ModificadaCrítica (9.8)1.8%—Grunt-karma Project Grunt-karma14/10/202217/6/2026
Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js.
ModificadaAlta (7.8)0.38%—Grunt-util-property Project Grunt-util-property17/7/202217/6/2026
This affects all versions of package grunt-util-property. The function call could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
ModificadaAlta (7)0.30%—Gruntjs Grunt10/5/202217/6/2026
file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which can lead to local privilege escalation to the GruntJS user if a lower-privileged user has write…
ModificadaMedia (5.5)0.57%—Gruntjs Grunt12/4/202217/6/2026
Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.
ModificadaAlta (7.1)2.3%—Gruntjs GruntDebian LinuxCanonical Ubuntu Linux3/9/202017/6/2026
The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.
ModificadaAlta (7.5)1.1%—Gruntcli Project Gruntcli7/6/201817/6/2026
gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
ModificadaAlta (8.1)1.7%—Grunt-images Project Grunt-images4/6/201817/6/2026
grunt-images is a grunt plugin for processing images. grunt-images downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or…
ModificadaAlta (8.1)1.8%—Grunt-ccompiler Project Grunt-ccompiler4/6/201817/6/2026
grunt-ccompiler is a Closure Compiler Grunt Plugin. grunt-ccompiler downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or…
ModificadaAlta (8.1)1.7%—Grunt-webdriver-qunit Project Grunt-webdriver-qunit1/6/201817/6/2026
grunt-webdriver-qunit is a grunt plugin to run qunit with webdriver in grunt grunt-webdriver-qunit downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the…
ModificadaAlta (8.6)1.6%—Grunt-gh-pages Project Grunt-gh-pages31/5/201817/6/2026
A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth part of the url. In module versions < 0.9.1 the auth portion of the url is outputted as part of the grunt tasks logging function. If this output is publicly available then the…