Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
97 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.44% | — | Rancher FleetAI | 30/6/2026 | 2/7/2026 | A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up to 0.12.16, 0.13.0 up to 0.13.12, 0.14.0 up to 0.14.7 and 0.15.0 up to 0.15.3 could be used to traverse outside of the intended directory, causing a denial of service. | |
| Pendiente de análisis | Alta (7) | 0.39% | — | Rancher FleetAIRancher-webhookAI | 30/6/2026 | 2/7/2026 | A Rancher FleetWorkspace admission path allowed side effects to occur in the Rancher webhook handler for versions 0.7.0 up to 0.7.10, 0.8.0 up to 0.8.7, 0.9.0 up to 0.9.6 and 0.10.0 up to 0.10.7. An unauthenticated attacker with network access to the in-cluster rancher-webhook service could submit a crafted admission… | |
| Analizada | Media (5.4) | 0.22% | — | Jenkins EC2 Fleet | 24/6/2026 | 26/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing AWS credentials stored in Jenkins. | |
| Analizada | Media (5.4) | 0.25% | — | Jenkins EC2 Fleet | 24/6/2026 | 26/6/2026 | A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing AWS credentials stored in Jenkins. | |
| Analizada | Media (6.9) | 0.39% | — | Fleetdm Fleet | 14/5/2026 | 17/6/2026 | Fleet is open source device management software. Prior to version 4.80.1, a vulnerability in Fleet's IP extraction logic allows unauthenticated attackers to bypass API rate limiting by spoofing client IP headers. This may allow brute-force login attempts or other abuse against Fleet instances exposed to the public… | |
| Analizada | Media (6) | 0.94% | — | Fleetdm Fleet | 14/5/2026 | 17/6/2026 | Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet's software installer pipeline could allow a crafted software package to execute arbitrary commands as root (macOS/Linux) or SYSTEM (Windows) on managed endpoints when an uninstall is triggered. When a software package… | |
| Analizada | Alta (8.7) | 0.54% | — | Fleetdm Fleet | 14/5/2026 | 17/6/2026 | Fleet is open source device management software. Prior to version 4.81.0, Fleet contained a denial-of-service (DoS) issue in the gRPC Launcher `PublishLogs` endpoint. In affected versions, certain unexpected input values were not handled gracefully, which could cause the Fleet server process to terminate while… | |
| Analizada | Alta (8.2) | 0.38% | — | Fleetdm Fleet | 14/5/2026 | 17/6/2026 | Fleet is open source device management software. Prior to version 4.82.0, a vulnerability in Fleet's Windows MDM enrollment flow allows authentication tokens from any Azure AD tenant to be accepted. Because Fleet validates JWT signatures using Microsoft's multi-tenant JWKS endpoint but does not enforce the `aud`… | |
| Analizada | Media (6.9) | 0.43% | — | Fleetdm Fleet | 14/5/2026 | 17/6/2026 | Fleet is open source device management software. Prior to version 4.80.1, Fleet trusted client-supplied IP address headers when determining the source IP for incoming requests. This allowed authenticated and unauthenticated clients to spoof their apparent IP address and bypass per-IP rate limiting controls. Fleet… | |
| Analizada | Alta (8.2) | 0.21% | — | Fleetdm Fleet | 14/5/2026 | 17/6/2026 | Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows MDM management endpoint could allow requests to be processed without proper client certificate validation. In certain circumstances, this could allow an attacker to impersonate an enrolled Windows device and… | |
| Pendiente de análisis | Crítica (9.9) | 0.44% | — | Fleet Helm DeployerAI | 13/5/2026 | 17/6/2026 | Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`. | |
| Analizada | Alta (7.8) | 0.11% | — | Fleetdm Fleet | 8/4/2026 | 25/7/2026 | Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation flow on collects a local user's password via a GUI dialog and interpolates it directly into a Tcl/expect script executed via exec.Command("expect", "-c", script). Because the password is inserted… | |
| Analizada | Media (6.6) | 0.26% | — | Fleetdm Fleet | 27/3/2026 | 17/6/2026 | Fleet is open source device management software. Prior to 4.81.1, a vulnerability in Fleet's Windows MDM command processing allows a malicious enrolled device to access MDM commands intended for other devices, potentially exposing sensitive configuration data such as WiFi credentials, VPN secrets, and certificate… | |
| Analizada | Media (4.9) | 0.30% | — | Fleetdm Fleet | 27/3/2026 | 17/6/2026 | Fleet is open source device management software. Prior to 4.81.0, Fleet contained an issue in the user invitation flow where the email address provided during invite acceptance was not validated against the email address associated with the invite. An attacker who obtained a valid invite token could create an account… | |
| Analizada | Media (6.6) | 0.46% | — | Fleetdm Fleet | 27/3/2026 | 17/6/2026 | Fleet is open source device management software. Prior to 4.81.0, a denial-of-service vulnerability in Fleet's gRPC Launcher endpoint allows an authenticated host to crash the entire Fleet server process by sending an unexpected log type value. The server terminates immediately, disrupting all connected hosts, MDM… | |
| Analizada | Media (5.7) | 1.8% | — | Fleetdm Fleet | 27/3/2026 | 17/6/2026 | Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software installer pipeline allows an attacker to achieve arbitrary code execution as root (macOS/Linux) or SYSTEM (Windows) on managed hosts when an uninstall is triggered for a crafted software package.… | |
| Analizada | Media (6.3) | 0.44% | — | Fleetdm Fleet | 27/3/2026 | 17/6/2026 | Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap package configuration allows an authenticated user with Team Admin or Global Admin privileges to modify arbitrary team configurations, exfiltrate sensitive data from the Fleet database, and inject… | |
| Analizada | Media (6.2) | 0.25% | — | Fleetdm Fleet | 27/3/2026 | 17/6/2026 | Fleet is open source device management software. Prior to 4.81.0, a second-order SQL injection vulnerability in Fleet's Apple MDM profile delivery pipeline could allow an attacker with a valid MDM enrollment certificate to exfiltrate or modify the contents of the Fleet database, including user credentials, API tokens,… | |
| Analizada | Media (4.9) | 0.42% | — | Fleetdm Fleet | 27/3/2026 | 17/6/2026 | Fleet is open source device management software. Prior to 4.81.1, a broken access control vulnerability in Fleet's host transfer API allows a team maintainer to transfer hosts from any team into their own team, bypassing team isolation boundaries. Once transferred, the attacker gains full control over the stolen… | |
| Analizada | Alta (8.7) | 0.48% | — | Fleetdm Fleet | 27/3/2026 | 17/6/2026 | Fleet is open source device management software. Prior to 4.81.0, Fleet contained multiple unauthenticated HTTP endpoints that read request bodies without enforcing a size limit. An unauthenticated attacker could exploit this behavior by sending large or repeated HTTP payloads, causing excessive memory allocation and… | |
| Analizada | Media (6) | 0.46% | — | Fleetdm Fleet | 27/3/2026 | 17/6/2026 | Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic could allow previously issued password reset tokens to remain valid after a user changes their password. As a result, a stale password reset token could be reused to reset the account password even… | |
| Analizada | Baja (1.3) | 0.39% | — | Fleetdm Fleet | 26/2/2026 | 17/6/2026 | Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s configuration API could expose Google Calendar service account credentials to authenticated users with low-privilege roles. This may allow unauthorized access to Google Calendar resources associated with the… | |
| Analizada | Baja (1.2) | 0.35% | — | Fleetdm Fleet | 26/2/2026 | 17/6/2026 | Fleet is open source device management software. In versions prior to 4.80.1, a broken authorization check in Fleet’s certificate template deletion API could allow a team administrator to delete certificate templates belonging to other teams within the same Fleet instance. Fleet supports certificate templates that are… | |
| Analizada | Baja (1.7) | 0.27% | — | Fleetdm Fleet | 26/2/2026 | 17/6/2026 | Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s Android MDM Pub/Sub handling could allow unauthenticated requests to trigger device unenrollment events. This may result in unauthorized removal of individual Android devices from Fleet management. If Android MDM… | |
| Analizada | Baja (0.6) | 0.13% | — | Fleetdm Fleet | 26/2/2026 | 17/6/2026 | Fleet is open source device management software. In versions prior to 4.80.1, Fleet generated device lock and wipe PINs using a predictable algorithm based solely on the current Unix timestamp. Because no secret key or additional entropy was used, the resulting PIN could potentially be derived if the approximate time… |