Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
6104 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.4) | 0.13% | — | Redhat Enterprise LinuxSpice-space Spice-vdagent | 29/6/2026 | 8/7/2026 | A path traversal vulnerability was found in spice-vdagent. This flaw allows a malicious or compromised SPICE host to write arbitrary files to any location on the guest operating system. This occurs because the filename provided by the SPICE host during file transfers is not properly sanitized before being used. An… | |
| Analizada | Media (5.1) | 0.11% | — | Redhat Enterprise LinuxSpice-space Spice-vdagent | 29/6/2026 | 8/7/2026 | A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a specially crafted message. This vulnerability can lead to a heap buffer overflow, causing the spice-vdagent daemon to crash and resulting in a Denial of Service (DoS) for the virtual machine. This… | |
| Analizada | Media (5.3) | 0.17% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise LinuxKernel Util-linux | 29/6/2026 | 31/8/2026 | A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer… | |
| Analizada | Media (4.9) | 0.24% | — | KubevirtRedhat Openshift Virtualization | 26/6/2026 | 6/7/2026 | A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance with a Multus network configuration, the supplied networkName value is written verbatim into the launcher pod's v1.multus-cni.io/default-network annotation without format validation or sanitization. The only… | |
| Analizada | Baja (3.8) | 0.13% | — | Redhat Openshift VirtualizationKubevirt | 26/6/2026 | 6/7/2026 | A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely until a newline character is received, with no length limit or read deadline. A user with access to a VM guest that has the downward metrics… | |
| Analizada | Media (6.4) | 0.24% | — | KubevirtRedhat Openshift Virtualization | 26/6/2026 | 6/7/2026 | A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-forward request to a VirtualMachineInstance (VMI), virt-api reads the target IP from vmi.Status.Interfaces[0].IP and passes it directly to net.Dial() without validation. For VMIs using non-masquerade… | |
| Analizada | Media (4.2) | 0.14% | — | KubevirtRedhat Openshift Virtualization | 26/6/2026 | 6/7/2026 | A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data to a launcher-rooted path using os.WriteFile and os.Chown without symlink protection. A user with access to the virt-launcher container can plant a symlink at the cache file path, causing virt-handler to… | |
| Analizada | Media (6.9) | 0.30% | — | Redhat PEN Drive | 26/6/2026 | 8/7/2026 | A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An attacker with cluster administrator privileges can inject a stored cross-site scripting (XSS) payload into cluster objects (such as ClusterVersion spec.channel) that… | |
| Modificada | Media (6.5) | 0.52% | — | Redhat Build OF Apicurio Registry | 26/6/2026 | 25/8/2026 | A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE declarations or enable FEATURE_SECURE_PROCESSING. An attacker with artifact-write permission can upload XML documents with internal entity-expansion payloads (billion-laughs… | |
| Modificada | Alta (7.4) | 0.34% | — | Redhat Build OF Apicurio Registry | 25/6/2026 | 26/8/2026 | A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature. When the VALIDITY rule is set to FULL, an attacker with Developer-role access can upload a WSDL document containing attacker-controlled import locations, causing the… | |
| Modificada | Alta (8.5) | 0.44% | — | Redhat Build OF Apicurio Registry | 25/6/2026 | 26/8/2026 | A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without enabling secure processing features or disabling external entity resolution. An attacker with artifact-write permission (or unauthenticated when the registry runs with default configuration) can upload… | |
| Analizada | Alta (8.1) | 0.30% | — | Redhat Build OF Keycloak | 25/6/2026 | 15/7/2026 | A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enables the attacker to impersonate any… | |
| Modificada | Alta (8.1) | 0.65% | — | Redhat Build OF Keycloak | 25/6/2026 | 14/9/2026 | A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query… | |
| Analizada | Media (4.6) | 0.29% | — | Redhat Build OF Keycloak | 25/6/2026 | 1/7/2026 | A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain unauthorized access to all resources of… | |
| Analizada | Media (6.5) | 0.46% | — | Redhat Build OF Keycloak | 25/6/2026 | 1/7/2026 | A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to re-enable a client that an administrator had explicitly disabled. This bypasses security controls, allowing the attacker to reset the… | |
| Analizada | Alta (7.7) | 0.49% | — | Redhat Build OF Keycloak | 25/6/2026 | 15/7/2026 | A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticated user with limited administrative privileges to reparent any existing group. When Fine-Grained Admin Permissions v2 (FGAPv2) is enabled, an attacker with management… | |
| Analizada | Alta (7.3) | 0.78% | 💥 PoC | Redhat Build OF Keycloak | 25/6/2026 | 15/7/2026 | A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to client registration endpoints, could bypass client Uniform Resource Identifier (URI) validation. This is achieved by registering a malicious client with a specially crafted… | |
| Analizada | Media (4.9) | 0.78% | — | Redhat Build OF Keycloak | 25/6/2026 | 1/7/2026 | A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and… | |
| Modificada | Alta (7.8) | 0.10% | — | Linux KernelRedhat Enterprise Linux | 25/6/2026 | 2/9/2026 | In the Linux kernel, the following vulnerability has been resolved: mm/list_lru: drain before clearing xarray entry on reparent memcg_reparent_list_lrus() clears the dying memcg's xarray entry with xas_store(&xas, NULL) before reparenting its per-node lists into the parent. This opens a window where a concurrent… | |
| Analizada | Alta (7.8) | 0.10% | — | Linux KernelRedhat Enterprise Linux | 25/6/2026 | 15/7/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/gem: Try to fix change_handle ioctl, attempt 4 [airlied: just added some comments on how to reenable] On-list because the cat is out of the bag and we're clearly not good enough to figure this out in private. The story thus far: 5e28b7b94408… | |
| Analizada | Media (6.5) | 0.13% | — | KubevirtRedhat Openshift Virtualization | 24/6/2026 | 6/7/2026 | A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity (namespace/name) solely from the request body without validating it against the connection's origin. Each virt-launcher pod connects through a per-VMI pipe socket, but no… | |
| Modificada | Alta (7.3) | 0.27% | — | KubevirtRedhat Openshift Virtualization | 24/6/2026 | 21/9/2026 | A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream operations resolve the path via /proc/self/fd/N using link-following syscalls. When the leaf is a symlink, the kernel dereferences it,… | |
| Modificada | Alta (7.8) | 0.19% | — | Linux KernelRedhat Enterprise Linux | 24/6/2026 | 9/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or ice_tx_csum() fail, the error path in ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points to it and is marked as valid (ICE_TX_BUF_SKB). 'next_to_use' remains unchanged, so the… | |
| Modificada | Crítica (9.8) | 0.53% | — | Linux KernelRedhat Enterprise Linux | 24/6/2026 | 16/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching saddr and daddr before pskb_pull() is problematic since skb->head can change. Remove these temporary variables: - Avoid potential future misuse after pskb_pull() call. | |
| Modificada | Crítica (9.8) | 0.37% | — | Linux KernelRedhat Enterprise Linux | 24/6/2026 | 10/9/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usage Replace it with scnprintf, the buffer sizes are expected to be large enough to hold the result, no need for snprintf+overflow check. Increase buffer size in mangle_content_len() while at it. |