Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.4% | — | Elastic Cloud ON Kubernetes | 3/6/2020 | 17/6/2026 | Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determine when the current Elastic Stack cluster was deployed they may be able to more easily brute force the Elasticsearch credentials generated by ECK. | |
| Modificada | Media (6.5) | 0.67% | — | Mongodb Enterprise Kubernetes Operator | 9/4/2020 | 17/6/2026 | X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an attacker with access to the Kubernetes cluster improper access to MongoDB instances. Customers who do not use X.509 authentication, and those who do not use the Operator to generate their X.509 certificates are unaffected. This… | |
| Modificada | Media (6.5) | 3.2% | — | Kubernetes | 1/4/2020 | 17/6/2026 | The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML. | |
| Modificada | Media (4.3) | 2.4% | — | KubernetesFedoraproject Fedora | 27/3/2020 | 17/6/2026 | The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests. | |
| Modificada | Media (6.5) | 1.2% | — | KubernetesFedoraproject Fedora | 27/3/2020 | 17/6/2026 | The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typically served on port 10255, and the authenticated HTTPS API typically served on port 10250. | |
| Modificada | Alta (8.8) | 2.7% | — | Jenkins Google Kubernetes Engine | 12/2/2020 | 17/6/2026 | Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability. | |
| Modificada | Media (5.7) | 2.6% | — | Kubernetes | 3/2/2020 | 17/6/2026 | The Kubernetes kubectl cp command in versions 1.1-1.12, and versions prior to 1.13.11, 1.14.7, and 1.15.4 allows a combination of two symlinks provided by tar output of a malicious container to place a file outside of the destination directory specified in the kubectl cp invocation. This could be used to allow an… | |
| Modificada | Media (5.3) | 1.1% | — | Kubernetes Nginx Ingress Controller | 14/1/2020 | 17/6/2026 | Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly. | |
| Modificada | Media (6.5) | 0.85% | — | Jenkins Alauda Kubernetes Support | 17/12/2019 | 17/6/2026 | A missing permission check in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing the Kubernetes service account token or credentials stored in… | |
| Modificada | Alta (8.8) | 0.86% | — | Jenkins Alauda Kubernetes Support | 17/12/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing the Kubernetes service account token or credentials stored in Jenkins. | |
| Modificada | Media (6.5) | 2.0% | — | Kubernetes External-provisionerKubernetes External-resizerKubernetes External-snapshotterRedhat Openshift Container Platform | 5/12/2019 | 17/6/2026 | Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot,… | |
| Modificada | Baja (2.6) | 0.62% | — | KubernetesFedoraproject Fedora | 5/12/2019 | 17/6/2026 | Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will follow the redirect as a GET request with client-certificate credentials for… | |
| Modificada | Media (5) | 0.80% | — | Kubernetes Cri-oFedoraproject FedoraRedhat Openshift Container Platform | 25/11/2019 | 17/6/2026 | A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for the cgroup. An attacker could abuse this flaw to get host network… | |
| Modificada | Media (6.5) | 1.8% | — | Kubernetes Kube-state-metricsRedhat Openshift Container Platform | 5/11/2019 | 17/6/2026 | A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that enabled annotations to be exposed as metrics. By default, the kube-state-metrics metrics only expose metadata about Secrets. However, a combination of the default `kubectl`… | |
| Modificada | Media (6.5) | 0.84% | — | Jenkins Kubernetes CI | 23/10/2019 | 17/6/2026 | A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins. | |
| Modificada | Media (6.5) | 0.84% | — | Jenkins Kubernetes CI | 23/10/2019 | 17/6/2026 | A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Alta (8.8) | 0.64% | — | Jenkins Kubernetes CI | 23/10/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Analizada | Alta (7.5) | 26% | 💥 Exploit | KubernetesRedhat Openshift Container Platform | 17/10/2019 | 17/6/2026 | Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to… | |
| Modificada | Media (4.3) | 0.69% | — | Jenkins Google Kubernetes Engine | 16/10/2019 | 17/6/2026 | A missing permission check in Jenkins Google Kubernetes Engine Plugin 0.7.0 and earlier allowed attackers with Overall/Read permission to obtain limited information about the scope of a credential with an attacker-specified credentials ID. | |
| Modificada | Crítica (9.9) | 1.2% | — | Jenkins Kubernetes Pipeline | 25/9/2019 | 17/6/2026 | Jenkins Kubernetes :: Pipeline :: Arquillian Steps Plugin provides a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection. | |
| Modificada | Crítica (9.9) | 1.2% | — | Jenkins Kubernetes Pipeline | 25/9/2019 | 17/6/2026 | Jenkins Kubernetes :: Pipeline :: Kubernetes Steps Plugin provides a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection. | |
| Modificada | Media (6.5) | 1.8% | — | KubernetesRedhat Openshift Container Platform | 29/8/2019 | 17/6/2026 | The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity… | |
| Modificada | Media (6.5) | 3.7% | — | KubernetesRedhat Openshift Container Platform | 29/8/2019 | 17/6/2026 | The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar binary in the container is malicious, it could run… | |
| Modificada | Alta (8.2) | 75% | 💥 Exploit | Kubernetes | 29/8/2019 | 17/6/2026 | The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpoint can potentially leak sensitive information such as internal Kubelet memory addresses and configuration, or for limited denial of… | |
| Modificada | Alta (8.1) | 2.1% | — | KubernetesRedhat Openshift Container Platform | 29/8/2019 | 17/6/2026 | The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if the resource were namespaced. Authorizations for the resource accessed in this manner are enforced using roles and role bindings within the namespace, meaning that a user with access only to a… |