Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
6104 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.15% | — | Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux | 15/4/2026 | 1/9/2026 | A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to properly handle raw bytes received from a pipe. Because the data is treated as a NUL-terminated C string without explicit termination, it results in an out-of-bounds read… | |
| Modificada | Alta (7.8) | 0.30% | — | GimpRedhat Enterprise Linux | 15/4/2026 | 30/9/2026 | A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a specially crafted GIF file. This can lead to a denial of service or potentially arbitrary code execution. | |
| Analizada | Media (4.8) | 0.38% | — | Redhat Build OF Keycloak | 14/4/2026 | 17/6/2026 | A flaw was found in Keycloak, specifically in the organization selection login page. A remote attacker with `manage-realm` or `manage-organizations` administrative privileges can exploit a Stored Cross-Site Scripting (XSS) vulnerability. This flaw occurs because the `organization.alias` is placed into an inline… | |
| Modificada | Alta (7.8) | 0.40% | — | KerasRedhat Openshift AI | 13/4/2026 | 15/7/2026 | A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the security guarantees of `safe_mode` and enables arbitrary attacker-controlled code… | |
| Modificada | Crítica (9.9) | 0.65% | — | Redhat Openshift AI | 10/4/2026 | 15/7/2026 | A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This could enable an attacker to gain unauthorized access to Kubernetes resources. | |
| Modificada | Alta (7.5) | 1.3% | — | GnutlsRedhat Hardened Images | 9/4/2026 | 1/9/2026 | A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can lead to a NULL pointer dereference, causing the server to crash and resulting in a remote… | |
| Analizada | Alta (7.5) | 6.6% | ⚠ Explotación activa💥 Exploit | Apache TomcatRedhat Jboss WEB ServerRedhat Enterprise LinuxRedhat Enterprise Linux ELS+3 | 9/4/2026 | 21/9/2026 | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue. | |
| Modificada | Alta (7) | 0.14% | — | Libcap Project LibcapRedhat Openshift Container PlatformRedhat Enterprise Linux | 9/4/2026 | 2/10/2026 | A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be… | |
| Modificada | Alta (8.8) | 0.79% | — | Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay | 8/4/2026 | 9/9/2026 | Se encontró una vulnerabilidad en el manejo de Red Hat Quay de las cargas reanudables de capas de imágenes de contenedor. El proceso de carga almacena datos intermedios en la base de datos utilizando un formato que, si se manipula, podría permitir a un atacante ejecutar código arbitrario en el servidor Quay. | |
| Modificada | Media (6.3) | 0.43% | — | Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay | 8/4/2026 | 10/9/2026 | Se encontró una falla en el proceso de carga de imágenes de contenedores de Red Hat Quay. Un usuario autenticado con acceso de push a cualquier repositorio en el registro puede interferir con las cargas de imágenes en curso de otros usuarios, incluyendo aquellas en repositorios a los que no tienen acceso. Esto podría… | |
| Modificada | Media (6.5) | 0.40% | — | Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay | 8/4/2026 | 10/9/2026 | Se encontró una falla en mirror-registry. Usuarios autenticados pueden explotar la función de exportación de registros al proporcionar una dirección web (URL) especialmente diseñada. Esto permite al backend de la aplicación realizar peticiones arbitrarias a recursos de red internos, una vulnerabilidad conocida como… | |
| Analizada | Media (5.3) | 0.29% | — | Redhat Mirror Registry FOR RED HAT Openshift | 8/4/2026 | 25/7/2026 | Se encontró una falla en el OpenShift Mirror Registry. Esta vulnerabilidad permite a un atacante remoto no autenticado enumerar nombres de usuario y direcciones de correo electrónico válidos a través de diferentes mensajes de error durante fallas de autenticación y creación de cuentas. | |
| Modificada | Media (5.5) | 0.46% | — | Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay | 8/4/2026 | 22/9/2026 | Se encontró un fallo en la característica de configuración de caché de proxy de Red Hat Quay. Cuando un administrador de organización configura un registro ascendente para el almacenamiento en caché de proxy, Quay realiza una conexión de red al nombre de host del registro especificado sin verificar que apunte a un… | |
| Analizada | Media (6.4) | 0.14% | — | Redhat Process Automation Manager | 8/4/2026 | 24/7/2026 | Se encontró una falla de escalada de privilegios en un contenedor en ciertas imágenes de Red Hat Process Automation Manager. Este problema se origina en que el archivo /etc/p4ssd se crea con permisos de escritura para el grupo durante la fase de construcción. En ciertas condiciones, un atacante que puede ejecutar… | |
| Analizada | Media (6.4) | 0.14% | — | Redhat Openshift Update Service | 8/4/2026 | 24/7/2026 | Una falla de escalada de privilegios de contenedor fue encontrada en ciertas imágenes de OpenShift Update Service (OSUS). Este problema se origina en que el archivo /etc/p4ssd se crea con permisos de escritura para el grupo durante el tiempo de compilación. En ciertas condiciones, un atacante que puede ejecutar… | |
| Analizada | Media (6.4) | 0.16% | — | Redhat WEB Terminal | 8/4/2026 | 24/7/2026 | Una falla de escalada de privilegios de contenedor fue encontrada en ciertas imágenes de Web Terminal. Este problema se origina en que el archivo /etc/p4ssd se crea con permisos de escritura para el grupo durante el tiempo de compilación. En ciertas condiciones, un atacante que puede ejecutar comandos dentro de un… | |
| Analizada | Media (6.7) | 0.11% | — | Redhat Advanced Cluster Management FOR Kubernetes | 8/4/2026 | 24/7/2026 | Una falla de escalada de privilegios de contenedor fue encontrada en ciertas imágenes de Multicluster Engine para Kubernetes. Este problema se origina en que el archivo /etc/p4ssd es creado con permisos de escritura para el grupo durante el tiempo de compilación. En ciertas condiciones, un atacante que puede ejecutar… | |
| Modificada | Media (6.4) | 0.18% | — | Redhat Ansible Automation Platform | 8/4/2026 | 24/9/2026 | Una falla de escalada de privilegios en un contenedor fue encontrada en ciertas imágenes de Ansible Automation Platform. Este problema surge porque el archivo /etc/p4ssd se crea con permisos de escritura para el grupo durante el proceso de construcción. En ciertas condiciones, un atacante que puede ejecutar comandos… | |
| Analizada | Alta (7) | 0.13% | — | LibsshRedhat Hardened Images | 7/4/2026 | 31/8/2026 | A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insecure default… | |
| Modificada | Media (5.5) | 0.17% | — | LibarchiveRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 7/4/2026 | 1/9/2026 | A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without subsequent fields), the function fails to perform adequate… | |
| Modificada | Alta (8.2) | 0.16% | — | Redhat Advanced Cluster Management FOR Kubernetes | 7/4/2026 | 8/9/2026 | A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This enables… | |
| Modificada | Media (5.5) | 0.40% | — | GNU TARRedhat Hardened ImagesRedhat Enterprise Linux | 6/4/2026 | 22/9/2026 | A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without… | |
| Analizada | Alta (7.1) | 0.16% | — | Xiph TheoraRedhat Enterprise Linux | 6/4/2026 | 17/6/2026 | A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local attacker could exploit this by tricking a user into opening a specially crafted AVI file containing a truncated header… | |
| Modificada | Media (5.3) | 0.27% | — | Redhat Build OF Keycloak | 6/4/2026 | 26/6/2026 | A flaw was found in Keycloak. A remote attacker can exploit a Cross-Origin Resource Sharing (CORS) header injection vulnerability in Keycloak's User-Managed Access (UMA) token endpoint. This flaw occurs because the `azp` claim from a client-supplied JSON Web Token (JWT) is used to set the `Access-Control-Allow-Origin`… | |
| Analizada | Media (5.3) | 0.62% | — | Kernel Util-linuxRedhat Hardened Images | 3/4/2026 | 31/8/2026 | Se encontró una falla en util-linux. La canonicalización incorrecta del nombre de host en la utilidad 'login(1)', cuando se invoca con la opción '-h', puede modificar el nombre de host remoto proporcionado antes de establecer 'PAM_RHOST'. Un atacante remoto podría explotar esto al proporcionar un nombre de host… |