Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2731▼ 513 respecto a la semana anterior
Críticas / altas1299▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

601 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.24%—Linuxfoundation Fluid8/5/202317/6/2026
Fluid is an open source Kubernetes-native distributed dataset orchestrator and accelerator for data-intensive applications. Starting in version 0.7.0 and prior to version 0.8.6, if a malicious user gains control of a Kubernetes node running fluid csi pod (controlled by the `csi-nodeplugin-fluid` node-daemonset), they…
ModificadaAlta (7.5)1.1%—Linuxfoundation Rekor8/5/202317/6/2026
Rekor is an open source software supply chain transparency log. Rekor prior to version 1.1.1 may crash due to out of memory (OOM) conditions caused by reading archive metadata files into memory without checking their sizes first. Verification of a JAR file submitted to Rekor can cause an out of memory crash if files…
ModificadaMedia (5.5)0.19%—Linuxfoundation Baremetal Operator26/4/202317/6/2026
Baremetal Operator (BMO) is a bare metal host provisioning integration for Kubernetes. Prior to version 0.3.0, ironic and ironic-inspector deployed within Baremetal Operator using the included `deploy.sh` store their `.htpasswd` files as ConfigMaps instead of Secrets. This causes the plain-text username and hashed…
ModificadaMedia (6.7)0.20%—Linuxfoundation Open Cluster Management24/4/202317/6/2026
A flaw was found in the Open Cluster Management (OCM) when a user have access to the worker nodes which has the cluster-manager-registration-controller or cluster-manager deployments. A malicious user can take advantage of this and bind the cluster-admin to any service account or using the service account to list all…
ModificadaAlta (8.8)0.47%—Linuxfoundation Kubewarden-controller19/4/202317/6/2026
An Improper Privilege Management vulnerability in SUSE kubewarden allows attackers to read arbitrary secrets if they get access to the ServiceAccount kubewarden-controller This issue affects: SUSE kubewarden kubewarden-controller versions prior to 1.6.0.
ModificadaBaja (2.7)0.78%—Linuxfoundation Vitess14/4/202317/6/2026
Vitess is a database clustering system for horizontal scaling of MySQL. Users can either intentionally or inadvertently create a keyspace containing `/` characters such that from that point on, anyone who tries to view keyspaces from VTAdmin will receive an error. Trying to list all the keyspaces using `vtctldclient…
ModificadaAlta (8.8)0.66%—Linuxfoundation Openfeature14/4/202317/6/2026
The OpenFeature Operator allows users to expose feature flags to applications. Assuming the pre-existence of a vulnerability that allows for arbitrary code execution, an attacker could leverage the lax permissions configured on `open-feature-operator-controller-manager` to escalate the privileges of any SA in the…
ModificadaMedia (6.5)0.51%—Linuxfoundation Cubefs12/4/202317/6/2026
CubeFS through 3.2.1 allows Kubernetes cluster-level privilege escalation. This occurs because DaemonSet has cfs-csi-cluster-role and can thus list all secrets, including the admin secret.
ModificadaAlta (7.8)0.34%—Linuxfoundation Runc29/3/202317/6/2026
runc is a CLI tool for spawning and running containers according to the OCI specification. It was found that AppArmor can be bypassed when `/proc` inside the container is symlinked with a specific mount configuration. This issue has been fixed in runc version 1.1.5, by prohibiting symlinked `/proc`. See PR #3785 for…
ModificadaMedia (6.3)0.32%—Linuxfoundation Runc29/3/202317/6/2026
runc is a CLI tool for spawning and running containers according to the OCI specification. In affected versions it was found that rootless runc makes `/sys/fs/cgroup` writable in following conditons: 1. when runc is executed inside the user namespace, and the `config.json` does not specify the cgroup namespace to be…
ModificadaMedia (4.3)0.64%—Linuxfoundation Argo-cd27/3/20239/7/2026
An access control issue in Argo CD v2.4.12 and below allows unauthenticated attackers to enumerate existing applications.
ModificadaAlta (7)0.45%—Linuxfoundation RuncRedhat Openshift Container PlatformRedhat Enterprise LinuxDebian Linux3/3/202317/6/2026
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921…
ModificadaAlta (7.8)0.26%—Linuxfoundation Zowe1/3/202317/6/2026
A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands via plugin install/update commands, or maliciously formed environment variables. Impacts Zowe CLI.
ModificadaCrítica (9.8)0.95%—Linuxfoundation Modular Open Smart Network17/2/202317/6/2026
Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization.
ModificadaAlta (7.8)0.54%—Linuxfoundation Containerd16/2/202317/6/2026
containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use…
ModificadaMedia (5.5)0.36%—Linuxfoundation Containerd16/2/202317/6/2026
containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service. This bug has been fixed in…
ModificadaMedia (5.4)0.45%—Linuxfoundation Backstage Catalog-modelLinuxfoundation Backstage Core-componentsLinuxfoundation Backstage Plugin-catalog-backend14/2/202317/6/2026
Backstage is an open platform for building developer portals. `@backstage/catalog-model` prior to version 1.2.0, `@backstage/core-components` prior to 0.12.4, and `@backstage/plugin-catalog-backend` prior to 1.7.2 are affected by a cross-site scripting vulnerability. This vulnerability allows a malicious actor with…
ModificadaAlta (7.5)0.97%—Linuxfoundation Opentelemetry-go Contrib8/2/202317/6/2026
opentelemetry-go-contrib is a collection of extensions for OpenTelemetry-Go. The v0.38.0 release of `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` uses the `httpconv.ServerRequest` function to annotate metric measurements for the `http.server.request_content_length`,…
ModificadaAlta (7.5)1.6%—Linuxfoundation Onnx26/1/202317/6/2026
Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"
ModificadaMedia (5.3)0.44%—Linuxfoundation Zowe API Mediation Layer18/1/202317/6/2026
It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happening only in the situation when zOSMF doesn’t have the APAR PH12143 applied. This issue affects: 1.16 versions to 1.19. What happens is that the services using the ZAAS…
ModificadaAlta (7.5)6.2%💥 PoCLinuxfoundation Harbor13/1/202317/6/2026
An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature."
ModificadaMedia (6.1)0.51%—Linuxfoundation Fossology4/1/202317/6/2026
A vulnerability has been found in fossology and classified as problematic. This vulnerability affects unknown code. The manipulation of the argument sql/VarValue leads to cross site scripting. The attack can be initiated remotely. The patch is identified as 8e0eba001662c7eb35f045b70dd458a4643b4553. It is recommended…
ModificadaMedia (6.7)0.26%—Mediatek Mt7603 FirmwareThelinuxfoundation YoctoMediatek Mt7613 FirmwareMediatek Mt7615 Firmware+93/1/202317/6/2026
In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220705066; Issue ID: GN20220705066.
ModificadaAlta (7.5)0.54%—Linuxfoundation Spinnaker3/1/202317/6/2026
Spinnaker is an open source, multi-cloud continuous delivery platform for releasing software changes, and Spinnaker's Rosco microservice produces machine images. Rosco prior to versions 1.29.2, 1.28.4, and 1.27.3 does not property mask secrets generated via packer builds. This can lead to exposure of sensitive AWS…
ModificadaMedia (5.3)1.9%💥 PoCLinuxfoundation Harbor26/12/202217/6/2026
Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.