Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

380 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.4)1.4%—Hashicorp Vault3/6/202117/6/2026
HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.
ModificadaAlta (7.5)1.9%—Hashicorp Vault-action7/5/202117/6/2026
HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line secret was not correctly registered with GitHub Actions for log masking.
ModificadaAlta (7.5)0.55%—Hashicorp Vault22/4/202117/6/2026
HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstances, may exclude revoked but unexpired certificates from the CRL. Fixed in 1.5.8, 1.6.4, and 1.7.1.
ModificadaAlta (7.5)0.57%—Hashicorp Vault22/4/202117/6/2026
HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates when connecting to Cassandra clusters. Fixed in 1.6.4 and 1.7.1
ModificadaAlta (7.5)1.3%—Hashicorp Vault1/2/202117/6/2026
HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secondaries without authentication. Fixed in 1.6.2.
ModificadaMedia (5.3)1.4%—Hashicorp Vault1/2/202117/6/2026
HashiCorp Vault and Vault Enterprise disclosed the internal IP address of the Vault node when responding to some invalid, unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.
ModificadaMedia (5.3)1.4%—Hashicorp Vault1/2/202117/6/2026
HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.
ModificadaMedia (6.5)1.4%—Google Secret Manager Provider FOR Secret Store CSI DriverHashicorp Vault Provider FOR Secrets Store CSI DriverMicrosoft Azure KEY Vault Provider FOR Secrets Store CSI Driver21/1/202117/6/2026
Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including /var/lib/kubelet/pods.
ModificadaAlta (8.8)0.45%—Veritas Enterprise Vault6/1/202117/6/2026
An issue was discovered in Veritas Enterprise Vault through 14.0. On start-up, it loads the OpenSSL library. The OpenSSL library then attempts to load the openssl.cnf configuration file (which does not exist) at the following locations in both the System drive (typically C:\) and the product's installation drive…
ModificadaMedia (5.3)0.82%—Hashicorp Vault17/12/202017/6/2026
HashiCorp Vault Enterprise’s Sentinel EGP policy feature incorrectly allowed requests to be processed in parent and sibling namespaces. Fixed in 1.5.6 and 1.6.1.
ModificadaMedia (5.3)1.3%—Hashicorp Vault17/12/202017/6/2026
HashiCorp Vault and Vault Enterprise 1.4.1 and newer allowed the enumeration of users via the LDAP auth method. Fixed in 1.5.6 and 1.6.1.
ModificadaCrítica (9.8)2.9%—Hashicorp Vault17/12/202017/6/2026
The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)1.5%—Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+10814/12/202017/6/2026
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
ModificadaCrítica (9.8)1.1%—Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+10814/12/202017/6/2026
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
ModificadaMedia (4.3)0.79%—Jenkins Azure KEY Vault4/11/202017/6/2026
A missing permission check in Jenkins Azure Key Vault Plugin 2.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
ModificadaAlta (7.5)9.9%💥 ExploitCommvault Commcell29/10/202017/6/2026
In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, Directory Traversal can occur such that an attempt to view a log file can instead view a file outside of the log-files folder.
ModificadaBaja (3.8)0.81%—Oracle Database Vault21/10/202017/6/2026
Vulnerability in the Database Vault component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Create Public Synonym privilege with network access via Oracle Net to compromise Database Vault.…
ModificadaAlta (8.8)67%💥 ExploitOpenmediavault2/10/202017/6/2026
openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.php, because json_encode_safe is not used in config/databasebackend.inc. Successful exploitation allows arbitrary command execution on the underlying operating system as root.
ModificadaMedia (6.8)1.0%—Hashicorp Vault30/9/202017/6/2026
HashiCorp Vault and Vault Enterprise versions 1.0 and newer allowed leases created with a batch token to outlive their TTL because expiration time was not scheduled correctly. Fixed in 1.4.7 and 1.5.4.
ModificadaAlta (7.8)0.30%—IBM Security Verify Privilege Vault Remote On-premises29/9/202017/6/2026
IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security restrictions due to improper input validation. IBM X-Force ID: 184884.
ModificadaAlta (8.2)2.8%—Hashicorp Vault26/8/202017/6/2026
HashiCorp Vault and Vault Enterprise versions 0.8.3 and newer, when configured with the GCP GCE auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1.
ModificadaAlta (8.2)1.5%—Hashicorp Vault26/8/202017/6/2026
HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1..
ModificadaAlta (7.5)1.0%—Hashicorp Vault-ssh-helper20/8/202017/6/2026
HashiCorp vault-ssh-helper up to and including version 0.1.6 incorrectly accepted Vault-issued SSH OTPs for the subnet in which a host's network interface was located, rather than the specific IP address assigned to that interface. Fixed in 0.2.0.
ModificadaMedia (5.9)0.97%—Vipre Password Vault22/6/202017/6/2026
The ThreatTrack VIPRE Password Vault app through 1.100.1090 for iOS has Missing SSL Certificate Validation.
ModificadaAlta (7.5)1.2%—Hashicorp Vault10/6/202017/6/2026
HashiCorp Vault and Vault Enterprise logged proxy environment variables that potentially included sensitive credentials. Fixed in 1.3.6 and 1.4.2.
Orbitaley — Vulnerabilidades