Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
790 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.47% | — | Sevenspark Shiftnav | 23/1/2023 | 17/6/2026 | The ShiftNav WordPress plugin before 1.7.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | |
| Modificada | Media (5.3) | 0.32% | — | Redhat Openshift | 17/1/2023 | 17/6/2026 | The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component. Even though the CVE-2016-2183 has been fixed in the etcd components, to enable periodic health checks from kubelet, it was necessary to open up a new port (9979) on etcd… | |
| Modificada | Media (5.4) | 0.39% | — | Wpsoul Greenshift | 16/1/2023 | 17/6/2026 | The Greenshift WordPress plugin before 4.8.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. | |
| Modificada | Media (5.9) | 0.68% | — | Redhat Openshift Container PlatformRedhat Openshift Osin | 28/12/2022 | 17/6/2026 | A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch is 8612686d6dda34ae9ef6b5a974e4b7accb4fea29. It is recommended to… | |
| Modificada | Alta (7.4) | 0.55% | — | Redhat Openshift | 9/12/2022 | 17/6/2026 | Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks. | |
| Modificada | Alta (8.1) | 0.74% | — | Redhat Openshift | 8/12/2022 | 17/6/2026 | A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability. | |
| Modificada | Media (4.8) | 0.44% | — | Redhat Openshift | 8/12/2022 | 17/6/2026 | The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks. | |
| Modificada | Crítica (9.8) | 1.1% | — | Shift-tech Bingo!cms | 7/12/2022 | 17/6/2026 | Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a remote unauthenticated attacker to upload an arbitrary file. As a result, an arbitrary script may be executed and/or a file may be altered. | |
| Modificada | Media (5.5) | 0.21% | — | Redhat Openshift | 19/10/2022 | 16/6/2026 | In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with local access to the broker to read this file. | |
| Modificada | Alta (7.5) | 0.65% | — | Redhat Openshift | 19/10/2022 | 16/6/2026 | The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file. | |
| Modificada | Baja (3.5) | 0.50% | — | Redhat Openshift | 17/10/2022 | 17/6/2026 | An input validation vulnerability exists in Openshift Enterprise due to a 1:1 mapping of tenants in Hawkular Metrics and projects/namespaces in OpenShift. If a user creates a project called "MyProject", and then later deletes it another user can then create a project called "MyProject" and access the metrics stored… | |
| Modificada | Alta (8.1) | 1.9% | 💥 PoC | Amazon WEB Services Redshift Java Database Connectivity Driver | 29/9/2022 | 17/6/2026 | In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check the class type when instantiating an object from a class name. | |
| Modificada | Alta (7.1) | 0.35% | — | Buildah Project BuildahRedhat Openshift Container PlatformRedhat Enterprise Linux | 13/9/2022 | 17/6/2026 | An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary… | |
| Modificada | Alta (7.1) | 0.32% | — | Podman Project PodmanRedhat Openshift Container PlatformRedhat Enterprise Linux | 13/9/2022 | 17/6/2026 | An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code… | |
| Modificada | Media (6.5) | 0.56% | — | Redhat Openshift | 1/9/2022 | 17/6/2026 | A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate was stored incorrectly in the oauth-serving-cert ConfigMaps, and accessible to any authenticated OpenShift user or service-account. A malicious user could exploit this flaw by reading the… | |
| Modificada | Media (6.3) | 0.58% | — | Redhat Openshift Container Platform | 1/9/2022 | 17/6/2026 | In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of the cluster router's HAProxy configuration files. This malformed entry can match any arbitrary hostname, or all hostnames in the cluster, and direct traffic to an arbitrary… | |
| Modificada | Media (6.5) | 0.41% | — | Redhat Ansible Automation PlatformRedhat Openshift Container PlatformFedoraproject Fedora | 1/9/2022 | 17/6/2026 | An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an invalid certificate, resulting in a loss of confidentiality. | |
| Modificada | Alta (8.6) | 2.2% | — | Dpdk Data Plane Development KITFedoraproject FedoraDebian LinuxRedhat Enterprise Linux Fast Datapath+4 | 31/8/2022 | 17/6/2026 | A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK. | |
| Modificada | Alta (7.5) | 1.6% | — | Redhat Openshift Application RuntimesRedhat Single Sign-onRedhat UndertowNetapp Active IQ Unified Manager+3 | 31/8/2022 | 17/6/2026 | A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet… | |
| Modificada | Alta (7.5) | 1.3% | — | Redhat Build OF QuarkusRedhat Integration Camel KRedhat Jboss Enterprise Application PlatformRedhat Openshift Application Runtimes+6 | 31/8/2022 | 17/6/2026 | A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629. | |
| Modificada | Media (4.9) | 1.7% | — | Openstack Oslo.utilsRedhat Openshift Container PlatformRedhat Openstack PlatformDebian Linux | 29/8/2022 | 17/6/2026 | A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext. | |
| Modificada | Media (6.5) | 0.30% | — | Dpdk Data Plane Development KITOpenvswitchRedhat Openshift Container Platform | 29/8/2022 | 17/6/2026 | A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts… | |
| Modificada | Alta (7.5) | 0.82% | — | Redhat Openshift Serverless | 26/8/2022 | 17/6/2026 | It was found that the CVE-2021-27918, CVE-2021-31525 and CVE-2021-33196 have been incorrectly mentioned as fixed in RHSA for Serverless 1.16.0 and Serverless client kn 1.16.0. These have been fixed with Serverless 1.17.0. | |
| Modificada | Media (5.5) | 0.29% | — | Linux KernelIBM Spectrum Copy Data ManagementIBM Spectrum Protect PlusDebian Linux+19 | 26/8/2022 | 17/6/2026 | A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS. | |
| Modificada | Media (6.5) | 0.56% | — | Redhat Ceph StorageRedhat Openshift Container StorageRedhat Openshift Data FoundationRedhat Openstack Platform+3 | 25/8/2022 | 17/6/2026 | A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks. |