Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2747▼ 495 respecto a la semana anterior
Críticas / altas1308▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

601 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.79%—Linuxfoundation Cortex19/12/202217/6/2026
Cortex provides multi-tenant, long term storage for Prometheus. A local file inclusion vulnerability exists in Cortex versions 1.13.0, 1.13.1 and 1.14.0, where a malicious actor could remotely read local files as a result of parsing maliciously crafted Alertmanager configurations when submitted to the Alertmanager Set…
ModificadaMedia (6.5)1.1%—Linuxfoundation Containerd7/12/202217/6/2026
containerd is an open source container runtime. A bug was found in containerd's CRI implementation where a user can exhaust memory on the host. In the CRI stream server, a goroutine is launched to handle terminal resize events if a TTY is requested. If the user's process fails to launch due to, for example, a faulty…
ModificadaAlta (7.5)22%💥 ExploitLinuxfoundation Mirage Firewall7/12/202217/6/2026
qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumption and loss of forwarding) via a crafted multicast UDP packet (IP address range of 224.0.0.0 through 239.255.255.255).
ModificadaAlta (7.5)0.64%—Linuxfoundation Opendaylight27/11/202217/6/2026
A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/RoleStore.java deleteRole function is affected when the API interface /auth/v1/roles/ is used.
ModificadaAlta (7.5)0.59%—Linuxfoundation Opendaylight27/11/202217/6/2026
A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/UserStore.java deleteUser function is affected when the API interface /auth/v1/users/ is used.
ModificadaAlta (7.5)0.73%—Linuxfoundation Opendaylight27/11/202217/6/2026
A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/DomainStore.java deleteDomain function is affected for the /auth/v1/domains/ API interface.
ModificadaCrítica (9.8)1.3%—Linuxfoundation Pytorch26/11/202217/6/2026
In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.
ModificadaAlta (7.4)0.96%—Linuxfoundation Knative Func19/11/202217/6/2026
knative.dev/func is is a client library and CLI enabling the development and deployment of Kubernetes functions. Developers using a malicious or compromised third-party buildpack could expose their registry credentials or local docker socket to a malicious `lifecycle` container. This issues has been patched in PR…
ModificadaMedia (6.5)0.41%—Linuxfoundation Kubevela16/11/202217/6/2026
KubeVela is an open source application delivery platform. Users using the VelaUX APIServer could be affected by this vulnerability. When using Helm Chart as the component delivery method, the request address of the warehouse is not restricted, and there is a blind SSRF vulnerability. Users who're using v1.6, please…
ModificadaAlta (7.5)1.2%💥 PoCLinuxfoundation Software FOR Open Networking IN THE Cloud14/11/202217/6/2026
There is a vulnerability in DHCPv6 packet parsing code that could be explored by remote attacker to craft a packet that could cause buffer overflow in a memcpy call, leading to out-of-bounds memory write that would cause dhcp6relay to crash. Dhcp6relay is a critical process and could cause dhcp relay docker to…
ModificadaMedia (6.7)0.14%—Linuxfoundation YoctoGoogle Android7/10/202217/6/2026
In cpu dvfs, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07139405; Issue ID: ALPS07139405.
ModificadaMedia (6.7)0.14%—Linuxfoundation YoctoGoogle Android7/10/202217/6/2026
In wlan, there is a possible use after free due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07299425; Issue ID: ALPS07299425.
ModificadaAlta (7.5)0.78%—Linuxfoundation YoctoGoogle Android7/10/202217/6/2026
In Wi-Fi driver, there is a possible way to disconnect Wi-Fi due to an improper resource release. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07030600; Issue ID: ALPS07030600.
ModificadaMedia (6.7)0.10%—Linuxfoundation YoctoGoogle Android7/10/202217/6/2026
In wlan, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310743; Issue ID: ALPS07310743.
ModificadaMedia (6.5)1.6%—Linuxfoundation DEX6/10/202217/6/2026
Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex instances with public clients (and by extension, clients accepting tokens issued by those Dex instances) are affected by this vulnerability if they are running a version prior to 2.35.0. An attacker can exploit this…
ModificadaAlta (7.5)3.9%💥 ExploitLinuxfoundation Dapr Dashboard3/10/202217/6/2026
Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitive data.
ModificadaCrítica (9.1)1.0%—Linuxfoundation Besu24/9/202217/6/2026
Besu is a Java-based Ethereum client. In versions newer than 22.1.3 and prior to 22.7.1, Besu is subject to an Incorrect Conversion between Numeric Types. An error in 32 bit signed and unsigned types in the calculation of available gas in the CALL operations (including DELEGATECALL) results in incorrect gas being…
ModificadaAlta (7.5)1.1%—Linuxfoundation Indy-node9/9/202217/6/2026
indy-node is the server portion of Hyperledger Indy, a distributed ledger purpose-built for decentralized identity. In vulnerable versions of indy-node, an attacker can max out the number of client connections allowed by the ledger, leaving the ledger unable to be used for its intended purpose. However, the ledger…
ModificadaAlta (8.8)2.3%—Linuxfoundation Indy-node6/9/202217/6/2026
Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In versions 1.12.4 and prior, the `pool-upgrade` request handler in Indy-Node allows an improperly authenticated attacker to remotely execute code on nodes within the network. The `pool-upgrade` request handler in…
ModificadaCrítica (10)0.64%—Linuxfoundation Loopback-connector-postgresql12/8/202217/6/2026
Improper input validation on the `contains` LoopBack filter may allow for arbitrary SQL injection. When the extended filter property `contains` is permitted to be interpreted by the Postgres connector, it is possible to inject arbitrary SQL which may affect the confidentiality and integrity of data stored on the…
ModificadaCrítica (9.1)1.2%—Linuxfoundation CephRedhat Ceph StorageFedoraproject Fedora25/7/202217/6/2026
A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed…
ModificadaCrítica (9.1)0.61%—Linuxfoundation Rocket Chip Generator18/7/202217/6/2026
Rocket-Chip commit 4f8114374d8824dfdec03f576a8cd68bebce4e56 was discovered to contain insufficient cryptography via the component /rocket/RocketCore.scala.
ModificadaCrítica (9.6)0.81%—Argoproj Argo CDLinuxfoundation Argo-cd12/7/202217/6/2026
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.4.0 and prior to 2.2.11, 2.3.6, and 2.4.5 is vulnerable to an improper certificate validation bug which could cause Argo CD to trust a malicious (or otherwise untrustworthy) OpenID Connect (OIDC) provider. A patch…
ModificadaMedia (6.5)0.72%—Linuxfoundation Kubeedge11/7/202217/6/2026
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, a large response received by the viaduct WSClient can cause a DoS from memory exhaustion. The entire body of the response is being read into memory…
ModificadaMedia (6.5)0.70%—Linuxfoundation Kubeedge11/7/202217/6/2026
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, the Cloud Stream server and the Edge Stream server reads the entire message into memory without imposing a limit on the size of this message. An…
Orbitaley — Vulnerabilidades