Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.9) | 1.6% | — | KubevirtRedhat Openshift Virtualization | 29/7/2020 | 17/6/2026 | A flaw was found in kubevirt 0.29 and earlier. Virtual Machine Instances (VMIs) can be used to gain access to the host's filesystem. Successful exploitation allows an attacker to assume the privileges of the VM process on the host system. In worst-case scenarios an attacker can read and modify any file on the system… | |
| Modificada | Media (6.4) | 1.6% | — | GNU Grub2Redhat Enterprise Linux Atomic HostRedhat Openshift Container PlatformRedhat Enterprise Linux+11 | 29/7/2020 | 17/6/2026 | Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of… | |
| Modificada | Media (6.4) | 0.98% | — | GNU Grub2Redhat Enterprise Linux Atomic HostRedhat Openshift Container PlatformCanonical Ubuntu Linux+10 | 29/7/2020 | 17/6/2026 | GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and… | |
| Modificada | Media (6.4) | 1.4% | — | GNU Grub2Redhat Enterprise Linux Atomic HostRedhat Openshift Container PlatformCanonical Ubuntu Linux+10 | 29/7/2020 | 17/6/2026 | GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects… | |
| Modificada | Media (6.5) | 1.2% | — | Redhat AMQRedhat Jboss Enterprise Application Platform Continuous DeliveryRedhat Jboss FuseRedhat Openshift Application Runtimes+1 | 24/7/2020 | 17/6/2026 | A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations are never removed from the remote InvocationTracker after a response is received in the EJB Client, as well as the server. This flaw allows an attacker to craft a denial of service… | |
| Modificada | Media (6.5) | 1.2% | — | Redhat AMQRedhat Jboss-ejb-clientRedhat Jboss Enterprise Application Platform Continuous DeliveryRedhat Jboss Fuse+2 | 24/7/2020 | 17/6/2026 | A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavailable. An attacker can take advantage and cause denial of service attack and make services… | |
| Modificada | Alta (8.8) | 0.32% | — | DockerRedhat Openshift Container PlatformRedhat Enterprise Linux Server | 13/7/2020 | 17/6/2026 | The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304. This issue could allow a malicious or compromised container to compromise the container host and… | |
| Modificada | Alta (7.5) | 1.1% | — | Redhat Openshift Container Platform | 12/6/2020 | 17/6/2026 | A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an API Server error to read the logs, and use the leaked OAuthToken to log into the API Server with… | |
| Modificada | Alta (7.5) | 1.2% | — | Redhat UndertowNetapp Oncommand InsightRedhat Jboss Enterprise Application PlatformRedhat Openshift Application Runtimes | 10/6/2020 | 17/6/2026 | A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of service. | |
| Modificada | Alta (7.2) | 2.1% | — | Elastic KibanaRedhat Openshift Container Platform | 3/6/2020 | 17/6/2026 | Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana… | |
| Modificada | Media (6) | 2.4% | 💥 PoC | Linuxfoundation CNI Network PluginsRedhat Openshift Container PlatformFedoraproject FedoraRedhat Enterprise Linux | 3/6/2020 | 17/6/2026 | A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to… | |
| Modificada | Media (6.5) | 0.98% | — | Redhat UndertowNetapp Oncommand InsightRedhat FuseRedhat Jboss Enterprise Application Platform+4 | 26/5/2020 | 17/6/2026 | A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling. | |
| Modificada | Alta (8.8) | 2.6% | — | Redhat KeycloakRedhat Decision ManagerRedhat Jboss FuseRedhat Openshift Application Runtimes+3 | 13/5/2020 | 17/6/2026 | A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution. | |
| Modificada | Alta (8.8) | 1.0% | — | Redhat Jboss FuseRedhat KeycloakRedhat Openshift Application Runtimes | 12/5/2020 | 17/6/2026 | A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized access to the application. | |
| Modificada | Media (6.6) | 0.13% | — | Redhat Openshift Container Platform | 12/5/2020 | 17/6/2026 | A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This flaw allows an attacker with access to a backup to obtain OAuth tokens and then use them to log into the cluster as any user who logged into the cluster via the WebUI or via the… | |
| Modificada | Media (4.3) | 0.82% | — | Redhat KeycloakRedhat Openshift Application RuntimesRedhat Single Sign-on | 11/5/2020 | 17/6/2026 | A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section. | |
| Modificada | Media (4.2) | 0.66% | — | Redhat SoteriaRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Continuous DeliveryRedhat Openshift Application Runtimes | 4/5/2020 | 17/6/2026 | A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from another request. | |
| Modificada | Alta (8.6) | 1.2% | — | KialiRedhat Openshift Service Mesh | 27/4/2020 | 17/6/2026 | An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to view and alter the Istio configuration. | |
| Modificada | Media (5.9) | 0.88% | — | Redhat Openshift Container Platform | 24/4/2020 | 17/6/2026 | A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified CORS allowed origins during installation. An attacker, able to man-in-the-middle the connection between the user's browser and the openshift console, could use this flaw to perform a phishing… | |
| Modificada | Media (6.1) | 1.6% | — | Linuxfoundation CephRedhat Ceph StorageRedhat Openshift Container PlatformFedoraproject Fedora+2 | 23/4/2020 | 17/6/2026 | A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input. | |
| Modificada | Alta (8.2) | 0.99% | — | Redhat Openshift Container Platform | 22/4/2020 | 17/6/2026 | A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator allowing an attacker able to gain access to those logs, to read and write to the storage backing the internal image registry. The highest threat from this vulnerability is… | |
| Modificada | Alta (8.1) | 1.6% | — | Redhat UndertowRedhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Jboss Fuse+2 | 21/4/2020 | 17/6/2026 | A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping… | |
| Modificada | Media (6.8) | 1.6% | — | Redhat Ceph StorageRedhat OpenshiftRedhat OpenstackLinuxfoundation Ceph+1 | 13/4/2020 | 17/6/2026 | A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a… | |
| Modificada | Alta (7) | 0.26% | — | Redhat Openshift | 2/4/2020 | 17/6/2026 | An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting versions before the following 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. | |
| Modificada | Alta (7) | 0.26% | — | Redhat Openshift | 2/4/2020 | 17/6/2026 | An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mariadb-apb, affecting versions before the following 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4 . An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. |