Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
601 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.46% | — | OAI EPC FederationAILinuxfoundation MagmaAI | 15/11/2024 | 17/6/2026 | Magma v1.8.0 and OAI EPC Federation v1.20 were discovered to contain an out-of-bounds read in the amf_as_establish_req function at /tasks/amf/amf_as.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet. | |
| Analizada | Alta (7.4) | 0.53% | — | Linuxfoundation Harbor | 14/11/2024 | 17/6/2026 | Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts to read/update P2P preheat execution logs and specifying different job IDs, malicious authenticated users could read all the job logs stored in the Harbor… | |
| Analizada | Alta (7.7) | 0.55% | — | Linuxfoundation Harbor | 14/11/2024 | 17/6/2026 | Harbor fails to validate the user permissions when updating tag retention policies. By sending a request to update a tag retention policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag retention policies configured in other projects. | |
| Analizada | Alta (7.7) | 0.41% | — | Linuxfoundation Harbor | 14/11/2024 | 17/6/2026 | Harbor fails to validate the user permissions when updating tag immutability policies. By sending a request to update a tag immutability policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag immutability policies configured in other… | |
| Analizada | Alta (7.7) | 0.30% | — | Linuxfoundation Harbor | 14/11/2024 | 17/6/2026 | Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that belongs to a project that the currently authenticated user doesn't have access to, the attacker could modify p2p preheat policies configured in other projects. | |
| Analizada | Media (6.4) | 0.53% | — | Linuxfoundation Harbor | 14/11/2024 | 17/6/2026 | Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access to. By sending a request that attempts to update a robot account, and specifying a robot account id and robot account name that belongs to a different project that the… | |
| Analizada | Media (5.4) | 0.50% | — | Linuxfoundation Harbor | 14/11/2024 | 17/6/2026 | Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users. The attacker could modify Webhook policies configured in other projects. | |
| Analizada | Media (6.2) | 0.10% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 4/11/2024 | 17/6/2026 | In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09124360; Issue ID: MSV-1823. | |
| Analizada | Alta (8.4) | 0.09% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 4/11/2024 | 17/6/2026 | In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09073261; Issue ID: MSV-1772. | |
| Analizada | Crítica (9.8) | 1.6% | — | Linuxfoundation Pytorch | 29/10/2024 | 17/6/2026 | In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing. | |
| Analizada | Media (5.3) | 0.21% | — | Linuxfoundation Zowe API Mediation Layer | 10/10/2024 | 17/6/2026 | The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endpoints, and swagger. It could advise about the running version of a service to an attacker. The attacker could also… | |
| Analizada | Media (5.3) | 0.23% | — | Linuxfoundation Zowe API Mediation Layer | 10/10/2024 | 17/6/2026 | The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers. | |
| Analizada | Media (6.7) | 0.08% | — | Linuxfoundation YoctoGoogle Android | 7/10/2024 | 17/6/2026 | In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08997492; Issue ID: MSV-1625. | |
| Analizada | Media (6.7) | 0.08% | — | Linuxfoundation YoctoGoogle Android | 7/10/2024 | 17/6/2026 | In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996886; Issue ID: MSV-1626. | |
| Analizada | Crítica (9.8) | 34% | 💥 Exploit | Linuxfoundation Dragonfly | 19/9/2024 | 17/6/2026 | Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. Dragonfly uses JWT to verify user. However, the secret key for JWT, "Secret Key", is hard coded, which leads to authentication bypass. An… | |
| Analizada | Media (5.4) | 0.29% | — | Linuxfoundation Backstage | 17/9/2024 | 17/6/2026 | Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs storage buckets is able to inject executable scripts in the TechDocs content that will be executed in the victim's browser when browsing documentation or navigating to an attacker provided link. This… | |
| Analizada | Media (6.5) | 0.73% | — | Linuxfoundation Backstage | 17/9/2024 | 17/6/2026 | Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDocs it is possible to access content in the entire storage bucket. This can leak contents of the bucket that are not intended to be accessible, as well as bypass permission checks in Backstage. This… | |
| Analizada | Media (6.5) | 0.51% | — | Linuxfoundation Backstage | 17/9/2024 | 17/6/2026 | Backstage is an open framework for building developer portals. A malicious actor with authenticated access to a Backstage instance with the catalog backend plugin installed is able to interrupt the service using a specially crafted query to the catalog API. This has been fixed in the `1.26.0` release of the… | |
| Analizada | Baja (3.6) | 0.32% | — | Linuxfoundation Runc | 3/9/2024 | 17/6/2026 | runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as well as 1.2.0-rc2 and earlier, can be tricked into creating empty files or directories in arbitrary locations in the host filesystem by sharing a volume between two containers and exploiting a race… | |
| Analizada | Alta (7.5) | 0.31% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle Android | 2/9/2024 | 17/6/2026 | In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08861558; Issue ID: MSV-1526. | |
| Modificada | Media (4.4) | 0.10% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 2/9/2024 | 17/6/2026 | In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08944204; Issue ID: MSV-1560. | |
| Modificada | Media (4.4) | 0.10% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 2/9/2024 | 17/6/2026 | In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08944210; Issue ID: MSV-1561. | |
| Modificada | Media (4.3) | 0.36% | — | Linuxfoundation Harbor | 2/8/2024 | 17/6/2026 | Incorrect user permission validation in Harbor <v2.9.5 and Harbor <v2.10.3 allows authenticated users to modify configurations. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Linuxfoundation VolcanoAI | 24/7/2024 | 17/6/2026 | Insecure permissions in volcano v1.8.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. | |
| Modificada | Media (6.7) | 0.22% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 1/7/2024 | 17/6/2026 | In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08719602; Issue ID: MSV-1412. |