Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

790 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.93%—Redhat Openshift11/4/202217/6/2026
The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only affects Red Hat OpenShift 4.9.
ModificadaAlta (7.5)1.3%—Crun Project CrunFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux4/4/202217/6/2026
A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable…
ModificadaAlta (7.5)1.4%—Podman Project PodmanRedhat Developer ToolsRedhat Openshift Container PlatformRedhat Enterprise Linux+104/4/202217/6/2026
A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with…
ModificadaBaja (3.7)0.77%—Redhat Openshift Container PlatformRedhat Openshift Machine-config-operator1/4/202217/6/2026
It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accessed externally from clusters without authentication. The MCS endpoint (port 22623) provides ignition configuration used for bootstrapping Nodes and can include some sensitive data, e.g. registry pull…
ModificadaAlta (7)0.43%—Linux KernelRedhat 3scale API ManagementRedhat Build OF QuarkusRedhat Codeready Linux Builder EUS+283/3/202217/6/2026
.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.
ModificadaMedia (6.3)0.49%—Redhat LibvirtRedhat Openshift Container PlatformRedhat Enterprise LinuxNetapp Ontap Select Deploy Administration Utility2/3/202217/6/2026
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.
ModificadaAlta (7.5)17%—HaproxyRedhat Openshift Container PlatformRedhat Software CollectionsRedhat Enterprise Linux+12/3/202217/6/2026
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.
AnalizadaAlta (7.8)24%⚠ Explotación activa💥 ExploitPolkit Project PolkitDebian LinuxCanonical Ubuntu LinuxRedhat Virtualization+216/2/202217/6/2026
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to…
ModificadaMedia (6.5)0.76%—Argoproj Argo CDRedhat Openshift Gitops16/2/202217/6/2026
A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-server, the unprivileged user is able to read all resources of the cluster including all secrets which might enable privilege escalations. The highest threat from this…
ModificadaMedia (4.2)0.77%—Kubernetes Cri-oRedhat Openshift Container Platform9/2/202217/6/2026
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.
ModificadaAlta (7.5)81%💥 PoCApache Log4jFedoraproject FedoraRedhat Codeready StudioRedhat Integration Camel K+4214/12/202117/6/2026
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in…
ModificadaCrítica (9.1)2.8%—Lapack Project LapackOpenblas Project OpenblasJulialang JuliaRedhat Ceph Storage+48/12/202117/6/2026
An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory.
ModificadaMedia (5.3)0.85%—Redhat Wildfly ElytronRedhat Build OF QuarkusRedhat Codeready StudioRedhat Data Grid+95/8/202117/6/2026
A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.
ModificadaMedia (4.6)0.28%—Redhat Openshift30/7/202117/6/2026
It was found in OpenShift, before version 4.8, that the generated certificate for the in-cluster Service CA, incorrectly included additional certificates. The Service CA is automatically mounted into all pods, allowing them to safely connect to trusted in-cluster services that present certificates signed by the…
ModificadaAlta (7)0.26%—Kubernetes-nmstateRedhat Openshift Virtualization7/6/202117/6/2026
An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before kubernetes-nmstate-handler-container-v2.3.0-30 are affected.
ModificadaAlta (7.1)0.70%—Redhat Noobaa-operatorRedhat Openshift Container Platform2/6/202117/6/2026
A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in the application response, resulting in arbitrary JavaScript being…
ModificadaAlta (7)0.22%—Redhat Openshift2/6/202117/6/2026
An insecure modification flaw in the /etc/kubernetes/kubeconfig file was found in OpenShift. This flaw allows an attacker with access to a running container which mounts /etc/kubernetes or has local access to the node, to copy this kubeconfig file and attempt to add their own node to the OpenShift cluster. The highest…
ModificadaMedia (6.5)0.93%—Redhat Openshift Container Platform2/6/202117/6/2026
A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an attacker to cause a denial of service attack on an OpenShift Container Platform cluster if they can deploy pods. The highest threat from this vulnerability is to system…
ModificadaMedia (4.3)0.71%—Elastic KibanaRedhat Openshift Container Platform2/6/202117/6/2026
It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary actions in OCP's distribution of Kibana, such as clickjacking.
ModificadaAlta (8.8)0.97%—Netlify Kiali-operatorRedhat Openshift Service Mesh1/6/202117/6/2026
An incorrect access control flaw was found in the kiali-operator in versions before 1.33.0 and before 1.24.7. This flaw allows an attacker with a basic level of access to the cluster (to deploy a kiali operand) to use this vulnerability and deploy a given image to anywhere in the cluster, potentially gaining access to…
ModificadaMedia (6.1)0.63%—Redhat Openshift27/5/202117/6/2026
A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaw to get the access token via physical access, or an XSS attack on the victim's browser. This flaw affects openshift/console versions before openshift/console-4.
ModificadaMedia (6.1)1.4%—Redhat FuseRedhat Jboss Enterprise Application PlatformRedhat Openshift Application RuntimesRedhat Resteasy27/5/202117/6/2026
A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.
ModificadaMedia (5.5)0.26%—Gnome NetworkmanagerRedhat Openshift Container PlatformRedhat Enterprise LinuxFedoraproject Fedora26/5/202117/6/2026
A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability.
ModificadaAlta (7.1)1.7%—Redhat Openshift Container Platform14/5/202117/6/2026
A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by using a specially crafted raw container image (.tar file) which contains symbolic links. The vulnerability is limited to the command `oc image extract`. If a symbolic link is first created pointing…
ModificadaAlta (8.8)2.5%—Shapeshift Keepkey Firmware6/5/202117/6/2026
Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.1.0 allow a stack buffer overflow via crafted messages. The overflow in ethereum_extractThorchainSwapData() in ethereum.c can circumvent stack protections and lead to code execution. The vulnerable interface is reachable remotely…
Orbitaley — Vulnerabilidades