Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

790 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.47%—Sevenspark Shiftnav23/1/202317/6/2026
The ShiftNav WordPress plugin before 1.7.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
ModificadaMedia (5.3)0.32%—Redhat Openshift17/1/202317/6/2026
The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component. Even though the CVE-2016-2183 has been fixed in the etcd components, to enable periodic health checks from kubelet, it was necessary to open up a new port (9979) on etcd…
ModificadaMedia (5.4)0.39%—Wpsoul Greenshift16/1/202317/6/2026
The Greenshift WordPress plugin before 4.8.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
ModificadaMedia (5.9)0.68%—Redhat Openshift Container PlatformRedhat Openshift Osin28/12/202217/6/2026
A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch is 8612686d6dda34ae9ef6b5a974e4b7accb4fea29. It is recommended to…
ModificadaAlta (7.4)0.55%—Redhat Openshift9/12/202217/6/2026
Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks.
ModificadaAlta (8.1)0.74%—Redhat Openshift8/12/202217/6/2026
A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.
ModificadaMedia (4.8)0.44%—Redhat Openshift8/12/202217/6/2026
The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks.
ModificadaCrítica (9.8)1.1%—Shift-tech Bingo!cms7/12/202217/6/2026
Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a remote unauthenticated attacker to upload an arbitrary file. As a result, an arbitrary script may be executed and/or a file may be altered.
ModificadaMedia (5.5)0.21%—Redhat Openshift19/10/202216/6/2026
In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with local access to the broker to read this file.
ModificadaAlta (7.5)0.65%—Redhat Openshift19/10/202216/6/2026
The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file.
ModificadaBaja (3.5)0.50%—Redhat Openshift17/10/202217/6/2026
An input validation vulnerability exists in Openshift Enterprise due to a 1:1 mapping of tenants in Hawkular Metrics and projects/namespaces in OpenShift. If a user creates a project called "MyProject", and then later deletes it another user can then create a project called "MyProject" and access the metrics stored…
ModificadaAlta (8.1)1.9%💥 PoCAmazon WEB Services Redshift Java Database Connectivity Driver29/9/202217/6/2026
In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check the class type when instantiating an object from a class name.
ModificadaAlta (7.1)0.35%—Buildah Project BuildahRedhat Openshift Container PlatformRedhat Enterprise Linux13/9/202217/6/2026
An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary…
ModificadaAlta (7.1)0.32%—Podman Project PodmanRedhat Openshift Container PlatformRedhat Enterprise Linux13/9/202217/6/2026
An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code…
ModificadaMedia (6.5)0.56%—Redhat Openshift1/9/202217/6/2026
A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate was stored incorrectly in the oauth-serving-cert ConfigMaps, and accessible to any authenticated OpenShift user or service-account. A malicious user could exploit this flaw by reading the…
ModificadaMedia (6.3)0.58%—Redhat Openshift Container Platform1/9/202217/6/2026
In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of the cluster router's HAProxy configuration files. This malformed entry can match any arbitrary hostname, or all hostnames in the cluster, and direct traffic to an arbitrary…
ModificadaMedia (6.5)0.41%—Redhat Ansible Automation PlatformRedhat Openshift Container PlatformFedoraproject Fedora1/9/202217/6/2026
An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an invalid certificate, resulting in a loss of confidentiality.
ModificadaAlta (8.6)2.2%—Dpdk Data Plane Development KITFedoraproject FedoraDebian LinuxRedhat Enterprise Linux Fast Datapath+431/8/202217/6/2026
A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.
ModificadaAlta (7.5)1.6%—Redhat Openshift Application RuntimesRedhat Single Sign-onRedhat UndertowNetapp Active IQ Unified Manager+331/8/202217/6/2026
A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet…
ModificadaAlta (7.5)1.3%—Redhat Build OF QuarkusRedhat Integration Camel KRedhat Jboss Enterprise Application PlatformRedhat Openshift Application Runtimes+631/8/202217/6/2026
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.
ModificadaMedia (4.9)1.7%—Openstack Oslo.utilsRedhat Openshift Container PlatformRedhat Openstack PlatformDebian Linux29/8/202217/6/2026
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
ModificadaMedia (6.5)0.30%—Dpdk Data Plane Development KITOpenvswitchRedhat Openshift Container Platform29/8/202217/6/2026
A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts…
ModificadaAlta (7.5)0.82%—Redhat Openshift Serverless26/8/202217/6/2026
It was found that the CVE-2021-27918, CVE-2021-31525 and CVE-2021-33196 have been incorrectly mentioned as fixed in RHSA for Serverless 1.16.0 and Serverless client kn 1.16.0. These have been fixed with Serverless 1.17.0.
ModificadaMedia (5.5)0.29%—Linux KernelIBM Spectrum Copy Data ManagementIBM Spectrum Protect PlusDebian Linux+1926/8/202217/6/2026
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
ModificadaMedia (6.5)0.56%—Redhat Ceph StorageRedhat Openshift Container StorageRedhat Openshift Data FoundationRedhat Openstack Platform+325/8/202217/6/2026
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.
Orbitaley — Vulnerabilidades