Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
601 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.73% | — | Linuxfoundation Software FOR Open Networking IN THE Cloud | 12/3/2024 | 17/6/2026 | Software for Open Networking in the Cloud (SONiC) Elevation of Privilege Vulnerability | |
| Analizada | Media (6.7) | 0.10% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 4/3/2024 | 17/6/2026 | In flashc, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541638; Issue ID: ALPS08541638. | |
| Modificada | Media (6.7) | 0.12% | — | Linuxfoundation YoctoRdkcentral RdkbGoogle AndroidOpenwrt | 4/3/2024 | 17/6/2026 | In lk, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528255; Issue ID: ALPS08528255. | |
| Modificada | Crítica (9.1) | 0.59% | — | Linuxfoundation OnnxFedoraproject Fedora | 23/2/2024 | 17/6/2026 | Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy. | |
| Modificada | Alta (7.5) | 1.2% | — | Linuxfoundation OnnxFedoraproject Fedora | 23/2/2024 | 17/6/2026 | Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882. | |
| Analizada | Alta (7.5) | 0.80% | — | Linuxfoundation Backstage Backend-common | 23/2/2024 | 17/6/2026 | `@backstage/backend-common` is a common functionality library for backends for Backstage, an open platform for building developer portals. In `@backstage/backend-common` prior to versions 0.21.1, 0.20.2, and 0.19.10, paths checks with the `resolveSafeChildPath` utility were not exhaustive enough, leading to risk of… | |
| Analizada | Crítica (9.8) | 1.2% | — | Linuxfoundation Yocto | 19/2/2024 | 17/6/2026 | Yocto Project is an open source collaboration project that helps developers create custom Linux-based systems regardless of the hardware architecture. In Yocto Projects Bitbake before 2.6.2 (before and included Yocto Project 4.3.1), with the Toaster server (included in bitbake) running, missing input validation allows… | |
| Modificada | Alta (8.6) | 19% | 💥 Exploit | Linuxfoundation RuncFedoraproject Fedora | 31/1/2024 | 17/9/2026 | runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for… | |
| Modificada | Alta (7.5) | 0.43% | — | Linuxfoundation DEX | 25/1/2024 | 17/6/2026 | Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves HTTPS with insecure TLS 1.0 and TLS 1.1. `cmd/dex/serve.go` line 425 seemingly sets TLS 1.2 as minimum version, but the whole `tlsConfig` is ignored after `TLS cert reloader` was introduced in v2.37.0.… | |
| Modificada | Alta (8.3) | 0.48% | — | Argoproj Argo CDLinuxfoundation Argo-cd | 19/1/2024 | 17/6/2026 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.15 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack… | |
| Modificada | Media (5.7) | 0.56% | — | Redhat RED HAT Developer HUBLinuxfoundation Backstage | 4/1/2024 | 17/6/2026 | A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded GitLab token includes a newline at the end of the string. The sanitized error can display on the frontend, including the raw access token. Upon gaining access to this… | |
| Modificada | Media (6.5) | 0.27% | — | Linuxfoundation Cubefs | 3/1/2024 | 17/6/2026 | CubeFS is an open-source cloud-native file storage system. CubeFS prior to version 3.3.1 was found to leak users secret keys and access keys in the logs in multiple components. When CubeCS creates new users, it leaks the users secret key. This could allow a lower-privileged user with access to the logs to retrieve… | |
| Modificada | Crítica (9.8) | 0.30% | — | Linuxfoundation Cubefs | 3/1/2024 | 17/6/2026 | CubeFS is an open-source cloud-native file storage system. A vulnerability was found in CubeFS prior to version 3.3.1 that could allow users to read sensitive data from the logs which could allow them escalate privileges. CubeFS leaks configuration keys in plaintext format in the logs. These keys could allow anyone to… | |
| Modificada | Crítica (9.8) | 0.44% | — | Linuxfoundation Cubefs | 3/1/2024 | 17/6/2026 | CubeFS is an open-source cloud-native file storage system. Prior to version 3.3.1, CubeFS used an insecure random string generator to generate user-specific, sensitive keys used to authenticate users in a CubeFS deployment. This could allow an attacker to predict and/or guess the generated string and impersonate a… | |
| Modificada | Media (5.9) | 0.35% | — | Linuxfoundation Cubefs | 3/1/2024 | 17/6/2026 | CubeFS is an open-source cloud-native file storage system. A vulnerability was found during in the CubeFS master component in versions prior to 3.3.1 that could allow an untrusted attacker to steal user passwords by carrying out a timing attack. The root case of the vulnerability was that CubeFS used raw string… | |
| Modificada | Media (6.5) | 0.56% | — | Linuxfoundation Cubefs | 3/1/2024 | 17/6/2026 | CubeFS is an open-source cloud-native file storage system. A security vulnerability was found in CubeFS HandlerNode in versions prior to 3.3.1 that could allow authenticated users to send maliciously-crafted requests that would crash the ObjectNode and deny other users from using it. The root cause was improper… | |
| Modificada | Media (6.7) | 0.11% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 4/12/2023 | 17/6/2026 | In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07909204; Issue ID: ALPS07909204. | |
| Modificada | Media (6.5) | 0.37% | — | Linuxfoundation Harbor | 9/11/2023 | 17/6/2026 | A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below, Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with network access to create jobs/stop job tasks and retrieve job task information. | |
| Modificada | Alta (7.5) | 0.37% | — | Linuxfoundation Nats-serverNats Nkeys | 31/10/2023 | 17/6/2026 | NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recently gained support for encryption, not just for signing/authentication. This is used in nats-server 2.10 (Sep 2023) and… | |
| Modificada | Media (6.5) | 0.66% | — | Linuxfoundation Nats-server | 30/10/2023 | 17/6/2026 | NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the intention of the configuration was for each user to have an account. The earliest affected version is 2.2.0. | |
| Modificada | Media (6.7) | 0.09% | — | Linuxfoundation YoctoMediatek IOT YoctoGoogle Android | 2/10/2023 | 17/6/2026 | In apusys, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07713478; Issue ID: ALPS07713478. | |
| Modificada | Alta (7.5) | 0.51% | — | Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel | 2/10/2023 | 17/6/2026 | In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07932637; Issue ID: ALPS07932637. | |
| Modificada | Crítica (9.9) | 0.66% | — | Linuxfoundation Edge Virtualization Engine | 21/9/2023 | 17/6/2026 | As noted in the “VTPM.md” file in the eve documentation, “VTPM is a server listening on port 8877 in EVE, exposing limited functionality of the TPM to the clients. VTPM allows clients to execute tpm2-tools binaries from a list of hardcoded options” The communication with this server is done using protobuf, and the… | |
| Modificada | Alta (8.8) | 0.17% | — | Linuxfoundation Edge Virtualization Engine | 21/9/2023 | 17/6/2026 | On boot, the Pillar eve container checks for the existence and content of “/config/authorized_keys”. If the file is present, and contains a supported public key, the container will go on to open port 22 and enable sshd with the given keys as the authorized keys for root login. An attacker could easily add their own… | |
| Modificada | Alta (8.8) | 0.13% | — | Linuxfoundation Edge Virtualization Engine | 20/9/2023 | 17/6/2026 | In EVE OS, the “measured boot” mechanism prevents a compromised device from accessing the encrypted data located in the vault. As per the “measured boot” design, the PCR values calculated at different stages of the boot process will change if any of their respective parts are changed. This includes, among other… |