Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.2% | — | Redhat Openshift Container Platform | 22/8/2022 | 17/6/2026 | A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker to access resources that would otherwise be restricted to specified IP ranges. The highest threat from this vulnerability is to data confidentiality and integrity as… | |
| Modificada | Media (6.5) | 0.78% | — | Jenkins Openshift Deployer | 27/7/2022 | 17/6/2026 | A missing permission check in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system and to upload a SSH key file from the Jenkins controller file system to an… | |
| Modificada | Media (6.5) | 0.53% | — | Jenkins Openshift Deployer | 27/7/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to check for the existence of an attacker-specified file path on the Jenkins controller file system and to upload a SSH key file from the Jenkins controller file system to an attacker-specified URL. | |
| Modificada | Media (6.5) | 0.76% | — | Jenkins Openshift Deployer | 27/7/2022 | 17/6/2026 | A missing permission check in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password. | |
| Modificada | Media (6.5) | 0.53% | — | Jenkins Openshift Deployer | 27/7/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified username and password. | |
| Modificada | Media (5.3) | 0.74% | — | Openshift Origin | 7/7/2022 | 17/6/2026 | In Openshift Origin 3 the cookies being set in console have no 'secure', 'HttpOnly' attributes. | |
| Modificada | Alta (7) | 0.46% | — | GNU Grub2Redhat Developer ToolsRedhat OpenshiftRedhat Enterprise Linux+8 | 6/7/2022 | 17/6/2026 | A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data… | |
| Modificada | Media (4.5) | 0.47% | — | GNU Grub2Redhat Developer ToolsRedhat OpenshiftRedhat Enterprise Linux+9 | 6/7/2022 | 17/6/2026 | A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman… | |
| Modificada | Media (4.5) | 0.46% | — | GNU Grub2Fedoraproject FedoraRedhat Developer ToolsRedhat Openshift+10 | 6/7/2022 | 17/6/2026 | A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform… | |
| Modificada | Media (5.5) | 0.22% | — | Redhat Openshift-origin-node-util | 30/6/2022 | 17/6/2026 | It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission. | |
| Modificada | Crítica (9.1) | 1.4% | — | Redhat Openshift | 30/6/2022 | 16/6/2026 | In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and integrity. | |
| Modificada | Alta (7.5) | 3.2% | — | Kubernetes Cri-oFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux | 7/6/2022 | 17/6/2026 | A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. This output is then read by CRI-O after command execution, and it is read in a manner where the entire… | |
| Modificada | Media (5.9) | 1.1% | — | Redhat FuseRedhat Jboss Enterprise Application PlatformRedhat Openshift Application RuntimesRedhat Single Sign-on+4 | 24/5/2022 | 17/6/2026 | A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to… | |
| Modificada | Media (6.5) | 1.3% | — | Redhat IgnitionRedhat Openshift Container PlatformRedhat Enterprise LinuxFedoraproject Fedora | 17/5/2022 | 17/6/2026 | A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible… | |
| Modificada | Alta (8.8) | 4.2% | 💥 PoC | Podman Project PodmanPsgo Project PsgoRedhat Developer ToolsRedhat Enterprise Linux Server Update Services FOR SAP Solutions+12 | 29/4/2022 | 17/6/2026 | A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem,… | |
| Modificada | Media (5.3) | 0.24% | — | Kubernetes Cri-oFedoraproject FedoraMobyproject MobyRedhat Openshift Container Platform | 18/4/2022 | 17/6/2026 | A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable… | |
| Modificada | Alta (7.5) | 0.93% | — | Redhat Openshift | 11/4/2022 | 17/6/2026 | The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only affects Red Hat OpenShift 4.9. | |
| Modificada | Alta (7.5) | 1.3% | — | Crun Project CrunFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux | 4/4/2022 | 17/6/2026 | A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable… | |
| Modificada | Alta (7.5) | 1.4% | — | Podman Project PodmanRedhat Developer ToolsRedhat Openshift Container PlatformRedhat Enterprise Linux+10 | 4/4/2022 | 17/6/2026 | A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with… | |
| Modificada | Baja (3.7) | 0.77% | — | Redhat Openshift Container PlatformRedhat Openshift Machine-config-operator | 1/4/2022 | 17/6/2026 | It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accessed externally from clusters without authentication. The MCS endpoint (port 22623) provides ignition configuration used for bootstrapping Nodes and can include some sensitive data, e.g. registry pull… | |
| Modificada | Alta (7) | 0.43% | — | Linux KernelRedhat 3scale API ManagementRedhat Build OF QuarkusRedhat Codeready Linux Builder EUS+28 | 3/3/2022 | 17/6/2026 | .A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root. | |
| Modificada | Media (6.3) | 0.49% | — | Redhat LibvirtRedhat Openshift Container PlatformRedhat Enterprise LinuxNetapp Ontap Select Deploy Administration Utility | 2/3/2022 | 17/6/2026 | A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity. | |
| Modificada | Alta (7.5) | 17% | — | HaproxyRedhat Openshift Container PlatformRedhat Software CollectionsRedhat Enterprise Linux+1 | 2/3/2022 | 17/6/2026 | A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability. | |
| Analizada | Alta (7.8) | 24% | ⚠ Explotación activa💥 Exploit | Polkit Project PolkitDebian LinuxCanonical Ubuntu LinuxRedhat Virtualization+2 | 16/2/2022 | 17/6/2026 | It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to… | |
| Modificada | Media (6.5) | 0.76% | — | Argoproj Argo CDRedhat Openshift Gitops | 16/2/2022 | 17/6/2026 | A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-server, the unprivileged user is able to read all resources of the cluster including all secrets which might enable privilege escalations. The highest threat from this… |