Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
6104 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.19% | — | Linux KernelRedhat Enterprise Linux | 24/6/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nat: use kfree_rcu to release ops Florian Westphal says: "Historically this is not an issue, even for normal base hooks: the data path doesn't use the original nf_hook_ops that are used to register the callbacks. However, in v5.14 I added… | |
| Modificada | Media (6.2) | 0.21% | — | Redhat SatelliteTheforeman Foreman | 23/6/2026 | 15/7/2026 | A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs session identifiers, which are treated as authentication credentials, at an informational level. The other, when debug logging is enabled,… | |
| Analizada | Media (4.4) | 0.16% | — | GstreamerRedhat Enterprise Linux | 23/6/2026 | 6/7/2026 | A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first… | |
| Analizada | Media (4.3) | 0.39% | — | GstreamerRedhat Enterprise Linux | 23/6/2026 | 1/7/2026 | A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a crafted aspect ratio indicator value, the H.266 parser performs an out-of-bounds read of up to 8 bytes from adjacent memory. This flaw allows an attacker to craft a malicious H.266 video file or stream… | |
| Modificada | Alta (7.8) | 0.22% | — | Redhat SatelliteTheforeman Foreman | 23/6/2026 | 16/7/2026 | A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an improper cache of authenticated client connections, by trusting a non-secret session ID without re-validating authentication tokens and by… | |
| Analizada | Media (6.5) | 0.39% | — | Redhat Enterprise Linux | 23/6/2026 | 1/7/2026 | A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the Vonage/Nexmo SMS API by encoding API credentials (api_key and api_secret) into URL query parameters and sending them via GET requests. This causes credentials to be exposed in web server access logs,… | |
| Analizada | Media (5.5) | 0.16% | — | Redhat Enterprise Linux | 23/6/2026 | 31/8/2026 | Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module retrieves a passphrase from the OS native keyring (GNOME Keyring, macOS Keychain, Windows Credential Manager) and places it directly into result["passphrase"] with no output suppression, no no_log… | |
| Analizada | Media (5.3) | 0.40% | — | Redhat Enterprise LinuxThekelleys Dnsmasq | 23/6/2026 | 31/8/2026 | An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker controlling a DNS zone can exploit this via… | |
| Analizada | Media (6.8) | 0.38% | — | Redhat Cluster Logging OperatorRedhat Logging Subsystem FOR RED HAT Openshift | 23/6/2026 | 8/7/2026 | A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output destinations without verifying that the ClusterLogForwarder creator has permission to use those credentials, allowing a delegated editor to exfiltrate SA tokens and… | |
| Analizada | Alta (8.7) | 0.77% | — | TraefikGolang GORedhat Openshift AI | 23/6/2026 | 26/9/2026 | Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote attacker can rapidly create and cancel HTTP/2 streams to exhaust… | |
| Modificada | Media (6.1) | 0.13% | — | Openbsd OpensshRedhat Enterprise Linux | 23/6/2026 | 7/10/2026 | A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the… | |
| Modificada | Baja (3.7) | 0.65% | — | Openbsd OpensshRedhat Hardened ImagesRedhat Enterprise Linux | 23/6/2026 | 24/9/2026 | A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving… | |
| Modificada | Media (6.5) | 0.60% | — | Openbsd OpensshRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 23/6/2026 | 7/10/2026 | A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters.… | |
| Analizada | Media (5.9) | 0.53% | — | Redhat Openshift Container PlatformRedhat Enterprise LinuxThekelleys Dnsmasq | 22/6/2026 | 31/8/2026 | A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may… | |
| Analizada | Media (4.8) | 0.36% | — | Redhat Enterprise LinuxGnome Libsoup | 22/6/2026 | 8/7/2026 | The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206… | |
| Modificada | Alta (8.3) | 0.30% | — | Redhat Openshift Container PlatformRedhat Windows Machine Config Operator | 22/6/2026 | 9/9/2026 | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH session can capture WICD and kubelet… | |
| Modificada | Alta (8.8) | 0.11% | — | Redhat Openshift Container PlatformRedhat Windows Machine Config Operator | 22/6/2026 | 9/9/2026 | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows… | |
| Pendiente de análisis | Media (6.3) | 0.33% | — | Redhat AWXAI | 19/6/2026 | 22/6/2026 | A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull_request webhooks, the controller stores the pull_request.statuses_url value from the webhook payload without validating that it points to a trusted GitHub API endpoint. If a job template is configured with a GitHub Personal Access… | |
| Modificada | Media (5) | 0.35% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 18/6/2026 | 30/6/2026 | A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsystem. If an administrator triggers schema reload while concurrent LDAP… | |
| Analizada | Alta (7.5) | 1.1% | — | Envoyproxy EnvoyRedhat Openshift Service Mesh | 17/6/2026 | 20/7/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability in Envoy's HTTP/2 downstream request processing allows an unauthenticated remote client to trigger excessive memory consumption, potentially resulting in OOM… | |
| Pendiente de análisis | Media (4.3) | 0.22% | — | Redhat SatelliteAIRedhat KatelloAI | 17/6/2026 | 4/8/2026 | A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization checks in the ContentUploadsController allowed users with the edit_products permission to query content information for repositories outside the products they were authorized to manage. An authenticated… | |
| Modificada | Crítica (9.2) | 6.5% | 💥 PoC | F5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+7 | 17/6/2026 | 14/9/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the… | |
| Analizada | Media (5.4) | 0.23% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 17/6/2026 | 28/6/2026 | A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after whitespace… | |
| Analizada | Alta (8.1) | 0.25% | — | Gnome LocalsearchRedhat Enterprise Linux | 16/6/2026 | 17/6/2026 | A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calculation during the… | |
| Analizada | Media (6.1) | 0.16% | — | Gnome LocalsearchRedhat Enterprise Linux | 16/6/2026 | 17/6/2026 | A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when processing specially crafted MP3 files containing malformed ID3v2.3 COMM (Comment) tags. An attacker could exploit this by… |