Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▼ 513 respecto a la semana anterior
Críticas / altas1299▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
601 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.24% | — | Linuxfoundation Fluid | 8/5/2023 | 17/6/2026 | Fluid is an open source Kubernetes-native distributed dataset orchestrator and accelerator for data-intensive applications. Starting in version 0.7.0 and prior to version 0.8.6, if a malicious user gains control of a Kubernetes node running fluid csi pod (controlled by the `csi-nodeplugin-fluid` node-daemonset), they… | |
| Modificada | Alta (7.5) | 1.1% | — | Linuxfoundation Rekor | 8/5/2023 | 17/6/2026 | Rekor is an open source software supply chain transparency log. Rekor prior to version 1.1.1 may crash due to out of memory (OOM) conditions caused by reading archive metadata files into memory without checking their sizes first. Verification of a JAR file submitted to Rekor can cause an out of memory crash if files… | |
| Modificada | Media (5.5) | 0.19% | — | Linuxfoundation Baremetal Operator | 26/4/2023 | 17/6/2026 | Baremetal Operator (BMO) is a bare metal host provisioning integration for Kubernetes. Prior to version 0.3.0, ironic and ironic-inspector deployed within Baremetal Operator using the included `deploy.sh` store their `.htpasswd` files as ConfigMaps instead of Secrets. This causes the plain-text username and hashed… | |
| Modificada | Media (6.7) | 0.20% | — | Linuxfoundation Open Cluster Management | 24/4/2023 | 17/6/2026 | A flaw was found in the Open Cluster Management (OCM) when a user have access to the worker nodes which has the cluster-manager-registration-controller or cluster-manager deployments. A malicious user can take advantage of this and bind the cluster-admin to any service account or using the service account to list all… | |
| Modificada | Alta (8.8) | 0.47% | — | Linuxfoundation Kubewarden-controller | 19/4/2023 | 17/6/2026 | An Improper Privilege Management vulnerability in SUSE kubewarden allows attackers to read arbitrary secrets if they get access to the ServiceAccount kubewarden-controller This issue affects: SUSE kubewarden kubewarden-controller versions prior to 1.6.0. | |
| Modificada | Baja (2.7) | 0.78% | — | Linuxfoundation Vitess | 14/4/2023 | 17/6/2026 | Vitess is a database clustering system for horizontal scaling of MySQL. Users can either intentionally or inadvertently create a keyspace containing `/` characters such that from that point on, anyone who tries to view keyspaces from VTAdmin will receive an error. Trying to list all the keyspaces using `vtctldclient… | |
| Modificada | Alta (8.8) | 0.66% | — | Linuxfoundation Openfeature | 14/4/2023 | 17/6/2026 | The OpenFeature Operator allows users to expose feature flags to applications. Assuming the pre-existence of a vulnerability that allows for arbitrary code execution, an attacker could leverage the lax permissions configured on `open-feature-operator-controller-manager` to escalate the privileges of any SA in the… | |
| Modificada | Media (6.5) | 0.51% | — | Linuxfoundation Cubefs | 12/4/2023 | 17/6/2026 | CubeFS through 3.2.1 allows Kubernetes cluster-level privilege escalation. This occurs because DaemonSet has cfs-csi-cluster-role and can thus list all secrets, including the admin secret. | |
| Modificada | Alta (7.8) | 0.34% | — | Linuxfoundation Runc | 29/3/2023 | 17/6/2026 | runc is a CLI tool for spawning and running containers according to the OCI specification. It was found that AppArmor can be bypassed when `/proc` inside the container is symlinked with a specific mount configuration. This issue has been fixed in runc version 1.1.5, by prohibiting symlinked `/proc`. See PR #3785 for… | |
| Modificada | Media (6.3) | 0.32% | — | Linuxfoundation Runc | 29/3/2023 | 17/6/2026 | runc is a CLI tool for spawning and running containers according to the OCI specification. In affected versions it was found that rootless runc makes `/sys/fs/cgroup` writable in following conditons: 1. when runc is executed inside the user namespace, and the `config.json` does not specify the cgroup namespace to be… | |
| Modificada | Media (4.3) | 0.64% | — | Linuxfoundation Argo-cd | 27/3/2023 | 9/7/2026 | An access control issue in Argo CD v2.4.12 and below allows unauthenticated attackers to enumerate existing applications. | |
| Modificada | Alta (7) | 0.45% | — | Linuxfoundation RuncRedhat Openshift Container PlatformRedhat Enterprise LinuxDebian Linux | 3/3/2023 | 17/6/2026 | runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921… | |
| Modificada | Alta (7.8) | 0.26% | — | Linuxfoundation Zowe | 1/3/2023 | 17/6/2026 | A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands via plugin install/update commands, or maliciously formed environment variables. Impacts Zowe CLI. | |
| Modificada | Crítica (9.8) | 0.95% | — | Linuxfoundation Modular Open Smart Network | 17/2/2023 | 17/6/2026 | Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization. | |
| Modificada | Alta (7.8) | 0.54% | — | Linuxfoundation Containerd | 16/2/2023 | 17/6/2026 | containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use… | |
| Modificada | Media (5.5) | 0.36% | — | Linuxfoundation Containerd | 16/2/2023 | 17/6/2026 | containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service. This bug has been fixed in… | |
| Modificada | Media (5.4) | 0.45% | — | Linuxfoundation Backstage Catalog-modelLinuxfoundation Backstage Core-componentsLinuxfoundation Backstage Plugin-catalog-backend | 14/2/2023 | 17/6/2026 | Backstage is an open platform for building developer portals. `@backstage/catalog-model` prior to version 1.2.0, `@backstage/core-components` prior to 0.12.4, and `@backstage/plugin-catalog-backend` prior to 1.7.2 are affected by a cross-site scripting vulnerability. This vulnerability allows a malicious actor with… | |
| Modificada | Alta (7.5) | 0.97% | — | Linuxfoundation Opentelemetry-go Contrib | 8/2/2023 | 17/6/2026 | opentelemetry-go-contrib is a collection of extensions for OpenTelemetry-Go. The v0.38.0 release of `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` uses the `httpconv.ServerRequest` function to annotate metric measurements for the `http.server.request_content_length`,… | |
| Modificada | Alta (7.5) | 1.6% | — | Linuxfoundation Onnx | 26/1/2023 | 17/6/2026 | Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd" | |
| Modificada | Media (5.3) | 0.44% | — | Linuxfoundation Zowe API Mediation Layer | 18/1/2023 | 17/6/2026 | It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happening only in the situation when zOSMF doesn’t have the APAR PH12143 applied. This issue affects: 1.16 versions to 1.19. What happens is that the services using the ZAAS… | |
| Modificada | Alta (7.5) | 6.2% | 💥 PoC | Linuxfoundation Harbor | 13/1/2023 | 17/6/2026 | An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature." | |
| Modificada | Media (6.1) | 0.51% | — | Linuxfoundation Fossology | 4/1/2023 | 17/6/2026 | A vulnerability has been found in fossology and classified as problematic. This vulnerability affects unknown code. The manipulation of the argument sql/VarValue leads to cross site scripting. The attack can be initiated remotely. The patch is identified as 8e0eba001662c7eb35f045b70dd458a4643b4553. It is recommended… | |
| Modificada | Media (6.7) | 0.26% | — | Mediatek Mt7603 FirmwareThelinuxfoundation YoctoMediatek Mt7613 FirmwareMediatek Mt7615 Firmware+9 | 3/1/2023 | 17/6/2026 | In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220705066; Issue ID: GN20220705066. | |
| Modificada | Alta (7.5) | 0.54% | — | Linuxfoundation Spinnaker | 3/1/2023 | 17/6/2026 | Spinnaker is an open source, multi-cloud continuous delivery platform for releasing software changes, and Spinnaker's Rosco microservice produces machine images. Rosco prior to versions 1.29.2, 1.28.4, and 1.27.3 does not property mask secrets generated via packer builds. This can lead to exposure of sensitive AWS… | |
| Modificada | Media (5.3) | 1.9% | 💥 PoC | Linuxfoundation Harbor | 26/12/2022 | 17/6/2026 | Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists. |