Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
380 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.4) | 1.4% | — | Hashicorp Vault | 3/6/2021 | 17/6/2026 | HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2. | |
| Modificada | Alta (7.5) | 1.9% | — | Hashicorp Vault-action | 7/5/2021 | 17/6/2026 | HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line secret was not correctly registered with GitHub Actions for log masking. | |
| Modificada | Alta (7.5) | 0.55% | — | Hashicorp Vault | 22/4/2021 | 17/6/2026 | HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstances, may exclude revoked but unexpired certificates from the CRL. Fixed in 1.5.8, 1.6.4, and 1.7.1. | |
| Modificada | Alta (7.5) | 0.57% | — | Hashicorp Vault | 22/4/2021 | 17/6/2026 | HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates when connecting to Cassandra clusters. Fixed in 1.6.4 and 1.7.1 | |
| Modificada | Alta (7.5) | 1.3% | — | Hashicorp Vault | 1/2/2021 | 17/6/2026 | HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secondaries without authentication. Fixed in 1.6.2. | |
| Modificada | Media (5.3) | 1.4% | — | Hashicorp Vault | 1/2/2021 | 17/6/2026 | HashiCorp Vault and Vault Enterprise disclosed the internal IP address of the Vault node when responding to some invalid, unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7. | |
| Modificada | Media (5.3) | 1.4% | — | Hashicorp Vault | 1/2/2021 | 17/6/2026 | HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7. | |
| Modificada | Media (6.5) | 1.4% | — | Google Secret Manager Provider FOR Secret Store CSI DriverHashicorp Vault Provider FOR Secrets Store CSI DriverMicrosoft Azure KEY Vault Provider FOR Secrets Store CSI Driver | 21/1/2021 | 17/6/2026 | Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including /var/lib/kubelet/pods. | |
| Modificada | Alta (8.8) | 0.45% | — | Veritas Enterprise Vault | 6/1/2021 | 17/6/2026 | An issue was discovered in Veritas Enterprise Vault through 14.0. On start-up, it loads the OpenSSL library. The OpenSSL library then attempts to load the openssl.cnf configuration file (which does not exist) at the following locations in both the System drive (typically C:\) and the product's installation drive… | |
| Modificada | Media (5.3) | 0.82% | — | Hashicorp Vault | 17/12/2020 | 17/6/2026 | HashiCorp Vault Enterprise’s Sentinel EGP policy feature incorrectly allowed requests to be processed in parent and sibling namespaces. Fixed in 1.5.6 and 1.6.1. | |
| Modificada | Media (5.3) | 1.3% | — | Hashicorp Vault | 17/12/2020 | 17/6/2026 | HashiCorp Vault and Vault Enterprise 1.4.1 and newer allowed the enumeration of users via the LDAP auth method. Fixed in 1.5.6 and 1.6.1. | |
| Modificada | Crítica (9.8) | 2.9% | — | Hashicorp Vault | 17/12/2020 | 17/6/2026 | The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 1.5% | — | Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+108 | 14/12/2020 | 17/6/2026 | GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network. | |
| Modificada | Crítica (9.8) | 1.1% | — | Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+108 | 14/12/2020 | 17/6/2026 | GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network. | |
| Modificada | Media (4.3) | 0.79% | — | Jenkins Azure KEY Vault | 4/11/2020 | 17/6/2026 | A missing permission check in Jenkins Azure Key Vault Plugin 2.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Alta (7.5) | 9.9% | 💥 Exploit | Commvault Commcell | 29/10/2020 | 17/6/2026 | In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, Directory Traversal can occur such that an attempt to view a log file can instead view a file outside of the log-files folder. | |
| Modificada | Baja (3.8) | 0.81% | — | Oracle Database Vault | 21/10/2020 | 17/6/2026 | Vulnerability in the Database Vault component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Create Public Synonym privilege with network access via Oracle Net to compromise Database Vault.… | |
| Modificada | Alta (8.8) | 67% | 💥 Exploit | Openmediavault | 2/10/2020 | 17/6/2026 | openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.php, because json_encode_safe is not used in config/databasebackend.inc. Successful exploitation allows arbitrary command execution on the underlying operating system as root. | |
| Modificada | Media (6.8) | 1.0% | — | Hashicorp Vault | 30/9/2020 | 17/6/2026 | HashiCorp Vault and Vault Enterprise versions 1.0 and newer allowed leases created with a batch token to outlive their TTL because expiration time was not scheduled correctly. Fixed in 1.4.7 and 1.5.4. | |
| Modificada | Alta (7.8) | 0.30% | — | IBM Security Verify Privilege Vault Remote On-premises | 29/9/2020 | 17/6/2026 | IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security restrictions due to improper input validation. IBM X-Force ID: 184884. | |
| Modificada | Alta (8.2) | 2.8% | — | Hashicorp Vault | 26/8/2020 | 17/6/2026 | HashiCorp Vault and Vault Enterprise versions 0.8.3 and newer, when configured with the GCP GCE auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1. | |
| Modificada | Alta (8.2) | 1.5% | — | Hashicorp Vault | 26/8/2020 | 17/6/2026 | HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1.. | |
| Modificada | Alta (7.5) | 1.0% | — | Hashicorp Vault-ssh-helper | 20/8/2020 | 17/6/2026 | HashiCorp vault-ssh-helper up to and including version 0.1.6 incorrectly accepted Vault-issued SSH OTPs for the subnet in which a host's network interface was located, rather than the specific IP address assigned to that interface. Fixed in 0.2.0. | |
| Modificada | Media (5.9) | 0.97% | — | Vipre Password Vault | 22/6/2020 | 17/6/2026 | The ThreatTrack VIPRE Password Vault app through 1.100.1090 for iOS has Missing SSL Certificate Validation. | |
| Modificada | Alta (7.5) | 1.2% | — | Hashicorp Vault | 10/6/2020 | 17/6/2026 | HashiCorp Vault and Vault Enterprise logged proxy environment variables that potentially included sensitive credentials. Fixed in 1.3.6 and 1.4.2. |