Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.2) | 0.77% | — | Kubernetes Cri-oRedhat Openshift Container Platform | 9/2/2022 | 17/6/2026 | An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace. | |
| Modificada | Alta (7.5) | 81% | 💥 PoC | Apache Log4jFedoraproject FedoraRedhat Codeready StudioRedhat Integration Camel K+42 | 14/12/2021 | 17/6/2026 | JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in… | |
| Modificada | Crítica (9.1) | 2.8% | — | Lapack Project LapackOpenblas Project OpenblasJulialang JuliaRedhat Ceph Storage+4 | 8/12/2021 | 17/6/2026 | An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory. | |
| Modificada | Media (5.3) | 0.85% | — | Redhat Wildfly ElytronRedhat Build OF QuarkusRedhat Codeready StudioRedhat Data Grid+9 | 5/8/2021 | 17/6/2026 | A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality. | |
| Modificada | Media (4.6) | 0.28% | — | Redhat Openshift | 30/7/2021 | 17/6/2026 | It was found in OpenShift, before version 4.8, that the generated certificate for the in-cluster Service CA, incorrectly included additional certificates. The Service CA is automatically mounted into all pods, allowing them to safely connect to trusted in-cluster services that present certificates signed by the… | |
| Modificada | Alta (7) | 0.26% | — | Kubernetes-nmstateRedhat Openshift Virtualization | 7/6/2021 | 17/6/2026 | An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before kubernetes-nmstate-handler-container-v2.3.0-30 are affected. | |
| Modificada | Alta (7.1) | 0.70% | — | Redhat Noobaa-operatorRedhat Openshift Container Platform | 2/6/2021 | 17/6/2026 | A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in the application response, resulting in arbitrary JavaScript being… | |
| Modificada | Alta (7) | 0.22% | — | Redhat Openshift | 2/6/2021 | 17/6/2026 | An insecure modification flaw in the /etc/kubernetes/kubeconfig file was found in OpenShift. This flaw allows an attacker with access to a running container which mounts /etc/kubernetes or has local access to the node, to copy this kubeconfig file and attempt to add their own node to the OpenShift cluster. The highest… | |
| Modificada | Media (6.5) | 0.93% | — | Redhat Openshift Container Platform | 2/6/2021 | 17/6/2026 | A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an attacker to cause a denial of service attack on an OpenShift Container Platform cluster if they can deploy pods. The highest threat from this vulnerability is to system… | |
| Modificada | Media (4.3) | 0.71% | — | Elastic KibanaRedhat Openshift Container Platform | 2/6/2021 | 17/6/2026 | It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary actions in OCP's distribution of Kibana, such as clickjacking. | |
| Modificada | Alta (8.8) | 0.97% | — | Netlify Kiali-operatorRedhat Openshift Service Mesh | 1/6/2021 | 17/6/2026 | An incorrect access control flaw was found in the kiali-operator in versions before 1.33.0 and before 1.24.7. This flaw allows an attacker with a basic level of access to the cluster (to deploy a kiali operand) to use this vulnerability and deploy a given image to anywhere in the cluster, potentially gaining access to… | |
| Modificada | Media (6.1) | 0.63% | — | Redhat Openshift | 27/5/2021 | 17/6/2026 | A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaw to get the access token via physical access, or an XSS attack on the victim's browser. This flaw affects openshift/console versions before openshift/console-4. | |
| Modificada | Media (6.1) | 1.4% | — | Redhat FuseRedhat Jboss Enterprise Application PlatformRedhat Openshift Application RuntimesRedhat Resteasy | 27/5/2021 | 17/6/2026 | A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack. | |
| Modificada | Media (5.5) | 0.26% | — | Gnome NetworkmanagerRedhat Openshift Container PlatformRedhat Enterprise LinuxFedoraproject Fedora | 26/5/2021 | 17/6/2026 | A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability. | |
| Modificada | Alta (7.1) | 1.7% | — | Redhat Openshift Container Platform | 14/5/2021 | 17/6/2026 | A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by using a specially crafted raw container image (.tar file) which contains symbolic links. The vulnerability is limited to the command `oc image extract`. If a symbolic link is first created pointing… | |
| Modificada | Media (6.5) | 1.6% | — | Storage Project StorageRedhat Openshift Container PlatformRedhat Enterprise LinuxFedoraproject Fedora | 1/4/2021 | 17/6/2026 | A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the… | |
| Modificada | Alta (7.8) | 0.28% | — | Redhat Openshift Container Platform | 24/3/2021 | 17/6/2026 | An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hadoop as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. | |
| Modificada | Alta (7) | 0.33% | — | Redhat Openshift Container Platform | 24/3/2021 | 17/6/2026 | An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hive as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. | |
| Modificada | Alta (7) | 0.26% | — | Redhat Openshift Container Platform | 24/3/2021 | 17/6/2026 | An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/presto as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. | |
| Modificada | Alta (7.8) | 0.34% | — | Redhat Openshift | 24/3/2021 | 17/6/2026 | An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as shipped in Red Hat Openshift 4 and 3.11. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. | |
| Modificada | Alta (7.8) | 0.34% | — | Redhat Openshift | 24/3/2021 | 17/6/2026 | An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-metering as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. | |
| Modificada | Alta (7.5) | 2.8% | — | PygmentsRedhat Openshift Container PlatformRedhat Openstack PlatformRedhat Software Collections+3 | 23/3/2021 | 17/6/2026 | An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword. | |
| Modificada | Media (6.3) | 0.59% | — | Redhat OpenshiftRedhat Openshift Container Platform | 19/3/2021 | 17/6/2026 | A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the GlusterFS StorageClass against leaking of the restuserkey. An attacker with basic-user permissions is able to obtain the value of restuserkey, and use it to authenticate… | |
| Modificada | Alta (7.2) | 1.3% | — | Redhat Openshift Container Platform | 19/3/2021 | 17/6/2026 | A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloads on master nodes. Pods with permission to access the host network, running on master nodes, can retrieve security credentials for the master AWS IAM role, allowing… | |
| Modificada | Alta (7.5) | 3.2% | — | Lldpd Project LldpdOpenvswitchRedhat Openshift Container PlatformRedhat Openstack+13 | 18/3/2021 | 17/6/2026 | A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability. |