Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3047▲ 440 respecto a la semana anterior
Críticas / altas1452▲ 212 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 151 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.55% | — | Lemmy-uiAIMarkdown-it-html5-embedAI | 19/8/2026 | 9/9/2026 | Lemmy is a link aggregator and forum for the fediverse. Prior to lemmy-ui 0.19.19-beta.1, LemmyNet/lemmy-ui renders Markdown in src/shared/markdown.ts for post bodies, comment bodies, private messages, and community and site sidebars through mdToHtml, which returns a raw __html object that Inferno injects without a… | |
| Analizada | Alta (8.7) | 0.52% | — | Markdown-it Linkify-it | 14/7/2026 | 6/8/2026 | linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices input and re-runs unanchored regex… | |
| Analizada | Alta (7.5) | 0.64% | — | Markdown-it Linkify-it | 8/7/2026 | 26/8/2026 | linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used by .test() and .match() can be invoked at every mailto: occurrence and scan the remaining input through src_email_name in lib/re.mjs, causing O(n^2) CPU consumption on crafted user text. This issue is… | |
| Analizada | Media (5.3) | 0.43% | — | Markdown-it Project Markdown-it | 17/6/2026 | 24/6/2026 | markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true is enabled, due to quadratic (O(n^2)) processing in the smartquotes rule. The issue stems from repeatedly modifying strings with replaceAt(), which performs O(n) slicing and concatenation per… | |
| Analizada | Media (5.5) | 0.68% | — | Markdown-it Project Markdown-it | 12/2/2026 | 17/6/2026 | Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*+$/ in the linkify function. An attacker can supply a long sequence of * characters followed by a non-matching character, which triggers excessive backtracking… | |
| Aplazada | Media (5.9) | 0.38% | — | Sapui5AIMarkdown-itAISAP Openui5AI | 9/12/2025 | 17/6/2026 | SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known security vulnerabilities. When markdown-it encounters special malformed input, it fails to terminate properly, resulting in an infinite loop. This Denial of Service via infinite loop causes high CPU usage and system unresponsiveness due to a… | |
| Analizada | Media (6.9) | 0.24% | — | Markdown-it Project Markdown-it | 21/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in markdown-it allows Cross-Site Scripting (XSS). This vulnerability is associated with program files lib/renderer.mjs. This issue affects markdown-it: 14.1.0. NOTE: the Supplier does not consider this issue to be… | |
| Modificada | Media (5.5) | 0.23% | — | Executablebooks Markdown-it-py | 23/2/2023 | 17/6/2026 | Denial of service could be caused to markdown-it-py, before v2.2.0, if an attacker was allowed to force null assertions with specially crafted input. | |
| Modificada | Media (5.5) | 0.23% | — | Executablebooks Markdown-it-py | 22/2/2023 | 17/6/2026 | Denial of service could be caused to the command line interface of markdown-it-py, before v2.2.0, if an attacker was allowed to use invalid UTF-8 characters as input. | |
| Modificada | Alta (7.5) | 0.95% | — | Markdown-it Project Markdown-it | 27/12/2022 | 17/6/2026 | A vulnerability was found in markdown-it up to 2.x. It has been classified as problematic. Affected is an unknown function of the file lib/common/html_re.js. The manipulation leads to inefficient regular expression complexity. Upgrading to version 3.0.0 is able to address this issue. The name of the patch is… | |
| Modificada | Media (6.1) | 0.60% | — | Markdown-it-decorate Project Markdown-it-decorate | 25/7/2022 | 17/6/2026 | This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link. | |
| Modificada | Media (6.1) | 0.60% | — | Markdown-it-toc Project Markdown-it-toc | 25/7/2022 | 17/6/2026 | This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped. | |
| Modificada | Media (5.3) | 2.2% | — | Markdown-it Project Markdown-it | 10/1/2022 | 17/6/2026 | markdown-it is a Markdown parser. Prior to version 1.3.2, special patterns with length greater than 50 thousand characterss could slow down the parser significantly. Users should upgrade to version 12.3.2 to receive a patch. There are no known workarounds aside from upgrading. | |
| Modificada | Media (6.1) | 1.4% | — | Markdown-it-highlightjs Project Markdown-it-highlightjs | 16/11/2020 | 17/6/2026 | — | |
| Modificada | Media (5.3) | 1.3% | — | Markdown-it Project Markdown-it | 7/6/2017 | 17/6/2026 | markdown-it before 4.1.0 does not block data: URLs. |