Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

332 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.4)0.51%—Systemd Project SystemdFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux+104/9/201917/6/2026
In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivileged user can exploit this by executing D-Bus methods that should be…
ModificadaAlta (7.8)2.0%—Artifex GhostscriptRedhat Openshift Container PlatformOpensuse LeapFedoraproject Fedora+13/9/201917/6/2026
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or…
ModificadaAlta (7.8)3.7%💥 PoCArtifex GhostscriptRedhat Openshift Container PlatformFedoraproject FedoraOpensuse Leap+13/9/201917/6/2026
A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or…
ModificadaMedia (6.5)1.8%—KubernetesRedhat Openshift Container Platform29/8/201917/6/2026
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity…
ModificadaMedia (6.5)3.7%—KubernetesRedhat Openshift Container Platform29/8/201917/6/2026
The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar binary in the container is malicious, it could run…
ModificadaAlta (8.1)2.1%—KubernetesRedhat Openshift Container Platform29/8/201917/6/2026
The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if the resource were namespaced. Authorizations for the resource accessed in this manner are enforced using roles and role bindings within the namespace, meaning that a user with access only to a…
ModificadaAlta (8.8)1.6%—JenkinsOracle Communications Cloud Native Core Automated Test SuiteRedhat Openshift Container Platform28/8/201917/6/2026
Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens that did not expire and could be used to bypass CSRF protection for the anonymous user.
ModificadaMedia (4.8)1.4%—JenkinsOracle Communications Cloud Native Core Automated Test SuiteRedhat Openshift Container Platform28/8/201917/6/2026
A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with Overall/Administer permission to configure the update site URL to inject arbitrary HTML and JavaScript in update center web pages.
ModificadaAlta (7.5)87%—Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+1813/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a…
ModificadaAlta (7.5)83%—Apple SwiftnioApache Traffic ServerDebian LinuxCanonical Ubuntu Linux+2413/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can…
ModificadaMedia (5.4)0.55%—Redhat Openshift Container Platform2/8/201917/6/2026
A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user's session. An attacker with the ability to observe the value of this token would be able to re-use the token to perform a CSRF attack.
ModificadaMedia (4.3)1.2%—Jenkins Pipeline\Redhat Openshift Container Platform31/7/201917/6/2026
A missing permission check in Jenkins Pipeline: Shared Groovy Libraries Plugin 2.14 and earlier allowed users with Overall/Read access to obtain limited information about the content of SCM repositories referenced by global libraries.
ModificadaAlta (8.8)2.5%—Jenkins Script SecurityRedhat Openshift Container Platform31/7/201917/6/2026
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of method pointer expressions allowed attackers to execute arbitrary code in sandboxed scripts.
ModificadaAlta (8.8)2.5%—Jenkins Script SecurityRedhat Openshift Container Platform31/7/201917/6/2026
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of type casts allowed attackers to execute arbitrary code in sandboxed scripts.
ModificadaBaja (2.3)0.38%—Redhat Openshift Container Platform30/7/201917/6/2026
OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources.
ModificadaCrítica (9.8)8.1%—Fasterxml Jackson-databindDebian LinuxNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation+2029/7/201917/6/2026
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
ModificadaCrítica (9.8)6.3%—Gnome PangoOracle Sd-wan EdgeFedoraproject FedoraDebian Linux+919/7/201917/6/2026
Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. The attack vector is: Bug can be used when application pass…
ModificadaMedia (4.3)1.6%—JenkinsRedhat Openshift Container Platform17/7/201917/6/2026
A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.
ModificadaMedia (5.4)0.87%—Redhat Openshift Container Platform11/7/201917/6/2026
A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7 and openshift-enterprise-3.9 through 3.11. An attacker could use this flaw to steal authorization data by getting them to click on a malicious link.
ModificadaCrítica (9.8)5.7%—Fasterxml Jackson-databindRedhat Openshift Container PlatformOracle ClusterwareOracle Communications Instant Messaging Server+39/7/201917/6/2026
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.
ModificadaMedia (5.9)1.4%—Redhat Openshift Container Platform12/6/201917/6/2026
It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output.
ModificadaAlta (8.1)12%💥 ExploitOracle JDKOracle JRERedhat Openshift Container PlatformDebian Linux+1123/4/201917/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability…
ModificadaMedia (5.9)38%—Oracle JDKOracle JRERedhat Openshift Container PlatformRedhat Satellite+1323/4/201917/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaAlta (7.5)4.4%—Oracle JDKOracle JRERedhat Openshift Container PlatformRedhat Satellite+1223/4/201917/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaCrítica (9.8)1.4%—Redhat Openshift Container PlatformHeketi Project Heketi22/4/201917/6/2026
It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.
Orbitaley — Vulnerabilidades