Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

698 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.72%—Jenkins Anchore Container Image Scanner21/9/202217/6/2026
Jenkins Anchore Container Image Scanner Plugin 1.0.24 and earlier does not escape content provided by the Anchore engine API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control API responses by Anchore engine.
ModificadaAlta (7.1)0.35%—Buildah Project BuildahRedhat Openshift Container PlatformRedhat Enterprise Linux13/9/202217/6/2026
An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary…
ModificadaAlta (7.1)0.32%—Podman Project PodmanRedhat Openshift Container PlatformRedhat Enterprise Linux13/9/202217/6/2026
An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code…
ModificadaMedia (6.3)0.58%—Redhat Openshift Container Platform1/9/202217/6/2026
In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of the cluster router's HAProxy configuration files. This malformed entry can match any arbitrary hostname, or all hostnames in the cluster, and direct traffic to an arbitrary…
ModificadaMedia (6.5)0.41%—Redhat Ansible Automation PlatformRedhat Openshift Container PlatformFedoraproject Fedora1/9/202217/6/2026
An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an invalid certificate, resulting in a loss of confidentiality.
ModificadaAlta (8.6)2.2%—Dpdk Data Plane Development KITFedoraproject FedoraDebian LinuxRedhat Enterprise Linux Fast Datapath+431/8/202217/6/2026
A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.
ModificadaMedia (6.5)1.3%—Dell Container Storage Modules30/8/202217/6/2026
Dell Container Storage Modules 1.2 contains a path traversal vulnerability in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to unintentional access to path outside of restricted directory.
ModificadaAlta (8.8)1.4%—Dell Container Storage Modules30/8/202217/6/2026
Dell Container Storage Modules 1.2 contains an OS command injection in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to to execute arbitrary OS commands on the affected system.
ModificadaMedia (4.9)1.7%—Openstack Oslo.utilsRedhat Openshift Container PlatformRedhat Openstack PlatformDebian Linux29/8/202217/6/2026
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
ModificadaMedia (6.5)0.30%—Dpdk Data Plane Development KITOpenvswitchRedhat Openshift Container Platform29/8/202217/6/2026
A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts…
ModificadaMedia (5.5)0.29%—Linux KernelIBM Spectrum Copy Data ManagementIBM Spectrum Protect PlusDebian Linux+1926/8/202217/6/2026
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
ModificadaMedia (6.5)0.56%—Redhat Ceph StorageRedhat Openshift Container StorageRedhat Openshift Data FoundationRedhat Openstack Platform+325/8/202217/6/2026
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.
ModificadaMedia (6.8)1.1%—Redhat KeycloakRedhat Single Sign-onRedhat Openshift Container Platform23/8/202217/6/2026
A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an attacker can bypass the MFA authentication by sending a SOAP request with an AuthnRequest and Authorization header with the user's credentials. The highest threat from this…
ModificadaCrítica (9.8)1.2%—Redhat Openshift Container Platform22/8/202217/6/2026
A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker to access resources that would otherwise be restricted to specified IP ranges. The highest threat from this vulnerability is to data confidentiality and integrity as…
ModificadaAlta (7)0.46%—GNU Grub2Redhat Developer ToolsRedhat OpenshiftRedhat Enterprise Linux+86/7/202217/6/2026
A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data…
ModificadaMedia (4.5)0.47%—GNU Grub2Redhat Developer ToolsRedhat OpenshiftRedhat Enterprise Linux+96/7/202217/6/2026
A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman…
ModificadaMedia (4.5)0.46%—GNU Grub2Fedoraproject FedoraRedhat Developer ToolsRedhat Openshift+106/7/202217/6/2026
A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform…
ModificadaMedia (4.9)0.93%—IBM APP Connect Enterprise Certified Container5/7/202217/6/2026
IBM App Connect Enterprise Certified Container 4.2 could allow a user from the administration console to cause a denial of service by creating a specially crafted request. IBM X-Force ID: 228221.
ModificadaAlta (8.8)0.89%—IBM Spectrum Protect Plus Container Backup AND Restore30/6/202217/6/2026
IBM Spectrum Protect Plus Container Backup and Restore (10.1.5 through 10.1.10.2 for Kubernetes and 10.1.7 through 10.1.10.2 for Red Hat OpenShift) could allow a remote attacker to bypass IBM Spectrum Protect Plus role based access control restrictions, caused by improper disclosure of session information. By…
ModificadaAlta (7.8)0.92%—Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure DiagnosticsMicrosoft Azure Security Center+615/6/202217/6/2026
Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
ModificadaMedia (5.5)0.38%—Linuxfoundation ContainerdDebian LinuxFedoraproject Fedora9/6/202217/6/2026
containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs inside a container can cause the containerd daemon to consume memory without bound during invocation of the `ExecSync` API. This can cause containerd to consume all available memory on the computer,…
ModificadaAlta (7.5)3.2%—Kubernetes Cri-oFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux7/6/202217/6/2026
A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. This output is then read by CRI-O after command execution, and it is read in a manner where the entire…
ModificadaMedia (6.5)1.3%—Redhat IgnitionRedhat Openshift Container PlatformRedhat Enterprise LinuxFedoraproject Fedora17/5/202217/6/2026
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible…
ModificadaAlta (8.8)4.2%💥 PoCPodman Project PodmanPsgo Project PsgoRedhat Developer ToolsRedhat Enterprise Linux Server Update Services FOR SAP Solutions+1229/4/202217/6/2026
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem,…
ModificadaMedia (5.3)0.24%—Kubernetes Cri-oFedoraproject FedoraMobyproject MobyRedhat Openshift Container Platform18/4/202217/6/2026
A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable…