Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▲ 32 respecto a la semana anterior
Críticas / altas1474▲ 364 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.54% | — | TerragruntAIOpentofuAIHashicorp TerraformAI | 21/8/2026 | 25/9/2026 | Terragrunt is a flexible orchestration tool that allows Infrastructure as Code written in OpenTofu or Terraform to scale. Prior to 1.0.4, Terragrunt trusts paths decoded from a downloaded module's .terragrunt-module-manifest during fileManifest.Clean() in internal/util/file.go. A malicious or compromised external… | |
| Modificada | Crítica (9.8) | 1.8% | — | Grunt-karma Project Grunt-karma | 14/10/2022 | 17/6/2026 | Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js. | |
| Modificada | Alta (7.8) | 0.38% | — | Grunt-util-property Project Grunt-util-property | 17/7/2022 | 17/6/2026 | This affects all versions of package grunt-util-property. The function call could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload. | |
| Modificada | Alta (7) | 0.30% | — | Gruntjs Grunt | 10/5/2022 | 17/6/2026 | file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which can lead to local privilege escalation to the GruntJS user if a lower-privileged user has write… | |
| Modificada | Media (5.5) | 0.57% | — | Gruntjs Grunt | 12/4/2022 | 17/6/2026 | Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2. | |
| Modificada | Alta (7.1) | 2.3% | — | Gruntjs GruntDebian LinuxCanonical Ubuntu Linux | 3/9/2020 | 17/6/2026 | The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML. | |
| Modificada | Alta (7.5) | 1.1% | — | Gruntcli Project Gruntcli | 7/6/2018 | 17/6/2026 | gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| Modificada | Alta (8.1) | 1.7% | — | Grunt-images Project Grunt-images | 4/6/2018 | 17/6/2026 | grunt-images is a grunt plugin for processing images. grunt-images downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or… | |
| Modificada | Alta (8.1) | 1.8% | — | Grunt-ccompiler Project Grunt-ccompiler | 4/6/2018 | 17/6/2026 | grunt-ccompiler is a Closure Compiler Grunt Plugin. grunt-ccompiler downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or… | |
| Modificada | Alta (8.1) | 1.7% | — | Grunt-webdriver-qunit Project Grunt-webdriver-qunit | 1/6/2018 | 17/6/2026 | grunt-webdriver-qunit is a grunt plugin to run qunit with webdriver in grunt grunt-webdriver-qunit downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the… | |
| Modificada | Alta (8.6) | 1.6% | — | Grunt-gh-pages Project Grunt-gh-pages | 31/5/2018 | 17/6/2026 | A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth part of the url. In module versions < 0.9.1 the auth portion of the url is outputted as part of the grunt tasks logging function. If this output is publicly available then the… |