Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

334 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)2.8%—JenkinsRedhat Openshift Container Platform10/12/201817/6/2026
A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.
ModificadaAlta (8.2)6.8%—JenkinsRedhat Openshift Container Platform10/12/201817/6/2026
A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.java that allows attackers to submit crafted user names that can cause an improper migration of user record storage formats, potentially preventing the victim from logging into Jenkins.
ModificadaMedia (4.3)1.4%—JenkinsRedhat Openshift Container Platform10/12/201817/6/2026
An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in DirectoryBrowserSupport.java that allows attackers with the ability to control build output to browse the file system on agents running builds beyond the duration of the build using the workspace browser.
AnalizadaCrítica (9.8)98%⚠ Explotación activa💥 ExploitJenkinsRedhat Openshift Container Platform10/12/201817/6/2026
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this…
ModificadaCrítica (9.8)12%—PerlCanonical Ubuntu LinuxDebian LinuxNetapp E-series Santricity OS Controller+147/12/201817/6/2026
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
ModificadaCrítica (9.8)87%💥 ExploitKubernetesRedhat Openshift Container PlatformNetapp Trident5/12/201817/6/2026
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same…
ModificadaAlta (7.8)3.0%—Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Openshift Container Platform+623/11/201817/6/2026
psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a JBIG2Decode type confusion.
ModificadaAlta (7.8)3.0%—Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Openshift Container Platform+623/11/201817/6/2026
psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a setcolorspace type confusion.
ModificadaAlta (7.8)9.5%—Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Openshift Container Platform+623/11/201817/6/2026
psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.
ModificadaAlta (8.1)2.6%—Linux KernelRedhat Openshift Container PlatformRedhat Virtualization HostRedhat Enterprise Linux Desktop+522/10/201817/6/2026
In the Linux kernel through 4.19, a use-after-free can occur due to a race condition between fanout_add from setsockopt and bind on an AF_PACKET socket. This issue exists because of the 15fe076edea787807a7cdc168df832544b58eba6 incomplete fix for a race condition. The code mishandles a certain multithreaded case…
ModificadaAlta (7.5)3.1%—HaproxyCanonical Ubuntu LinuxRedhat OpenshiftRedhat Openshift Container Platform+121/9/201817/6/2026
A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.
ModificadaMedia (6.1)1.6%—Elastic KibanaRedhat Openshift Container Platform19/9/201817/6/2026
Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
ModificadaMedia (5.4)1.1%—Redhat Openshift Container Platform11/9/201817/6/2026
A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods can use this flaw to perform actions on the K8s API as the victim.
ModificadaAlta (7.7)1.9%—Redhat Openshift Container PlatformStarcounter-jack Json-patch6/9/201817/6/2026
An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.
ModificadaAlta (7.8)1.6%—Artifex GhostscriptRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+75/9/201817/6/2026
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact.
ModificadaMedia (5.3)2.4%—Salesforce Tough-cookieIBM API ConnectRedhat Openshift Container Platform5/9/201817/6/2026
NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP header passed by client. This vulnerability appears to have been fixed in 2.3.0.
ModificadaAlta (7.5)8.1%—Nodejs Node.jsRedhat Openshift Container Platform21/8/201817/6/2026
In all versions of Node.js prior to 6.14.4, 8.11.4 and 10.9.0 when used with UCS-2 encoding (recognized by Node.js under the names `'ucs2'`, `'ucs-2'`, `'utf16le'` and `'utf-16le'`), `Buffer#write()` can be abused to write outside of the bounds of a single `Buffer`. Writes that start from the second-to-last position…
ModificadaMedia (5)0.90%—Redhat Openshift Container Platform13/8/201817/6/2026
The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook tokens.
ModificadaBaja (3.5)1.3%—Redhat OpenshiftRedhat Openshift Container Platform1/8/201817/6/2026
An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manifest associated with an image, can pull an image even if they do not have access to the image normally, resulting in the disclosure of any information contained within the image.
ModificadaMedia (4.8)1.4%—Redhat Openshift Container Platform27/7/201817/6/2026
A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given name used to authenticate and access Elasticsearch can later access it without the token, bypassing authentication. This attack also requires that the Elasticsearch be configured with…
ModificadaMedia (6.5)3.1%—Freedesktop PopplerCanonical Ubuntu LinuxDebian LinuxRedhat Ansible Tower+425/7/201817/6/2026
Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of service. This may be exploitable when a victim opens a specially crafted PDF file.
ModificadaCrítica (9.8)4.8%—Redhat Openshift Container PlatformRedhat OpenstackRedhat Storage ConsoleRedhat Virtualization+519/7/201817/6/2026
Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now…
ModificadaMedia (5.3)0.99%—Redhat OpenshiftRedhat Openshift Container Platform16/7/201817/6/2026
The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with access to OpenShift to run images from registries that should not be allowed.
ModificadaCrítica (9.8)4.2%—Gnome LibsoupCanonical Ubuntu LinuxDebian LinuxRedhat Ansible Tower+55/7/201817/6/2026
The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
ModificadaAlta (8.8)1.4%—Redhat Openshift Container Platform2/7/201817/6/2026
source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privilege escalation which allows the assemble script to run as the root user in a non-privileged container. An attacker can use this flaw to open network connections, and…