Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2747▼ 495 respecto a la semana anterior
Críticas / altas1308▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
601 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.79% | — | Linuxfoundation Cortex | 19/12/2022 | 17/6/2026 | Cortex provides multi-tenant, long term storage for Prometheus. A local file inclusion vulnerability exists in Cortex versions 1.13.0, 1.13.1 and 1.14.0, where a malicious actor could remotely read local files as a result of parsing maliciously crafted Alertmanager configurations when submitted to the Alertmanager Set… | |
| Modificada | Media (6.5) | 1.1% | — | Linuxfoundation Containerd | 7/12/2022 | 17/6/2026 | containerd is an open source container runtime. A bug was found in containerd's CRI implementation where a user can exhaust memory on the host. In the CRI stream server, a goroutine is launched to handle terminal resize events if a TTY is requested. If the user's process fails to launch due to, for example, a faulty… | |
| Modificada | Alta (7.5) | 22% | 💥 Exploit | Linuxfoundation Mirage Firewall | 7/12/2022 | 17/6/2026 | qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumption and loss of forwarding) via a crafted multicast UDP packet (IP address range of 224.0.0.0 through 239.255.255.255). | |
| Modificada | Alta (7.5) | 0.64% | — | Linuxfoundation Opendaylight | 27/11/2022 | 17/6/2026 | A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/RoleStore.java deleteRole function is affected when the API interface /auth/v1/roles/ is used. | |
| Modificada | Alta (7.5) | 0.59% | — | Linuxfoundation Opendaylight | 27/11/2022 | 17/6/2026 | A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/UserStore.java deleteUser function is affected when the API interface /auth/v1/users/ is used. | |
| Modificada | Alta (7.5) | 0.73% | — | Linuxfoundation Opendaylight | 27/11/2022 | 17/6/2026 | A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/DomainStore.java deleteDomain function is affected for the /auth/v1/domains/ API interface. | |
| Modificada | Crítica (9.8) | 1.3% | — | Linuxfoundation Pytorch | 26/11/2022 | 17/6/2026 | In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely. | |
| Modificada | Alta (7.4) | 0.96% | — | Linuxfoundation Knative Func | 19/11/2022 | 17/6/2026 | knative.dev/func is is a client library and CLI enabling the development and deployment of Kubernetes functions. Developers using a malicious or compromised third-party buildpack could expose their registry credentials or local docker socket to a malicious `lifecycle` container. This issues has been patched in PR… | |
| Modificada | Media (6.5) | 0.41% | — | Linuxfoundation Kubevela | 16/11/2022 | 17/6/2026 | KubeVela is an open source application delivery platform. Users using the VelaUX APIServer could be affected by this vulnerability. When using Helm Chart as the component delivery method, the request address of the warehouse is not restricted, and there is a blind SSRF vulnerability. Users who're using v1.6, please… | |
| Modificada | Alta (7.5) | 1.2% | 💥 PoC | Linuxfoundation Software FOR Open Networking IN THE Cloud | 14/11/2022 | 17/6/2026 | There is a vulnerability in DHCPv6 packet parsing code that could be explored by remote attacker to craft a packet that could cause buffer overflow in a memcpy call, leading to out-of-bounds memory write that would cause dhcp6relay to crash. Dhcp6relay is a critical process and could cause dhcp relay docker to… | |
| Modificada | Media (6.7) | 0.14% | — | Linuxfoundation YoctoGoogle Android | 7/10/2022 | 17/6/2026 | In cpu dvfs, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07139405; Issue ID: ALPS07139405. | |
| Modificada | Media (6.7) | 0.14% | — | Linuxfoundation YoctoGoogle Android | 7/10/2022 | 17/6/2026 | In wlan, there is a possible use after free due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07299425; Issue ID: ALPS07299425. | |
| Modificada | Alta (7.5) | 0.78% | — | Linuxfoundation YoctoGoogle Android | 7/10/2022 | 17/6/2026 | In Wi-Fi driver, there is a possible way to disconnect Wi-Fi due to an improper resource release. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07030600; Issue ID: ALPS07030600. | |
| Modificada | Media (6.7) | 0.10% | — | Linuxfoundation YoctoGoogle Android | 7/10/2022 | 17/6/2026 | In wlan, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310743; Issue ID: ALPS07310743. | |
| Modificada | Media (6.5) | 1.6% | — | Linuxfoundation DEX | 6/10/2022 | 17/6/2026 | Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex instances with public clients (and by extension, clients accepting tokens issued by those Dex instances) are affected by this vulnerability if they are running a version prior to 2.35.0. An attacker can exploit this… | |
| Modificada | Alta (7.5) | 3.9% | 💥 Exploit | Linuxfoundation Dapr Dashboard | 3/10/2022 | 17/6/2026 | Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitive data. | |
| Modificada | Crítica (9.1) | 1.0% | — | Linuxfoundation Besu | 24/9/2022 | 17/6/2026 | Besu is a Java-based Ethereum client. In versions newer than 22.1.3 and prior to 22.7.1, Besu is subject to an Incorrect Conversion between Numeric Types. An error in 32 bit signed and unsigned types in the calculation of available gas in the CALL operations (including DELEGATECALL) results in incorrect gas being… | |
| Modificada | Alta (7.5) | 1.1% | — | Linuxfoundation Indy-node | 9/9/2022 | 17/6/2026 | indy-node is the server portion of Hyperledger Indy, a distributed ledger purpose-built for decentralized identity. In vulnerable versions of indy-node, an attacker can max out the number of client connections allowed by the ledger, leaving the ledger unable to be used for its intended purpose. However, the ledger… | |
| Modificada | Alta (8.8) | 2.3% | — | Linuxfoundation Indy-node | 6/9/2022 | 17/6/2026 | Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In versions 1.12.4 and prior, the `pool-upgrade` request handler in Indy-Node allows an improperly authenticated attacker to remotely execute code on nodes within the network. The `pool-upgrade` request handler in… | |
| Modificada | Crítica (10) | 0.64% | — | Linuxfoundation Loopback-connector-postgresql | 12/8/2022 | 17/6/2026 | Improper input validation on the `contains` LoopBack filter may allow for arbitrary SQL injection. When the extended filter property `contains` is permitted to be interpreted by the Postgres connector, it is possible to inject arbitrary SQL which may affect the confidentiality and integrity of data stored on the… | |
| Modificada | Crítica (9.1) | 1.2% | — | Linuxfoundation CephRedhat Ceph StorageFedoraproject Fedora | 25/7/2022 | 17/6/2026 | A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed… | |
| Modificada | Crítica (9.1) | 0.61% | — | Linuxfoundation Rocket Chip Generator | 18/7/2022 | 17/6/2026 | Rocket-Chip commit 4f8114374d8824dfdec03f576a8cd68bebce4e56 was discovered to contain insufficient cryptography via the component /rocket/RocketCore.scala. | |
| Modificada | Crítica (9.6) | 0.81% | — | Argoproj Argo CDLinuxfoundation Argo-cd | 12/7/2022 | 17/6/2026 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.4.0 and prior to 2.2.11, 2.3.6, and 2.4.5 is vulnerable to an improper certificate validation bug which could cause Argo CD to trust a malicious (or otherwise untrustworthy) OpenID Connect (OIDC) provider. A patch… | |
| Modificada | Media (6.5) | 0.72% | — | Linuxfoundation Kubeedge | 11/7/2022 | 17/6/2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, a large response received by the viaduct WSClient can cause a DoS from memory exhaustion. The entire body of the response is being read into memory… | |
| Modificada | Media (6.5) | 0.70% | — | Linuxfoundation Kubeedge | 11/7/2022 | 17/6/2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, the Cloud Stream server and the Edge Stream server reads the entire message into memory without imposing a limit on the size of this message. An… |