Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

255 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (10)0.46%—Cloudfoundry UAAAICloudfoundry CF DeploymentAI1/6/202622/7/2026
Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic Curve) private keys are inadvertently exposed through the public /token_keys endpoint. This endpoint is designed to provide public key material for JWT token…
Pendiente de análisisAlta (7.5)0.65%—Cloudfoundry Cf-auth-proxyAICloudfoundry Log-cache ReleaseAI1/6/202622/7/2026
Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to every log and metric for every application and platform component via minting a JWT that the cf-auth-proxy accepts as a valid logs.admin token. Affected versions: -…
Pendiente de análisisAlta (8.1)0.42%—Cloudfoundry Diego-releaseAICloudfoundry Smb-volume-releaseAICloudfoundry CF DeploymentAI1/6/202622/7/2026
Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the mount-option allowlist, enabling privilege escalation and security control bypass on multi-tenant Diego cells. Affected…
AnalizadaMedia (6.8)0.11%—Cloud Foundry Bosh27/5/202617/6/2026
AgentClient#handle_method (lines 264-303) processes every NATS reply. It calls inject_compile_log (line 273) on every response, which reads response['value']['result']['compile_log_id'] (line 332-338) and passes it to download_and_delete_blob. Separately, any response containing 'exception' goes through…
AnalizadaMedia (4.3)0.13%—Cloud Foundry Bosh27/5/202617/6/2026
When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is consumed by AgentClient. inject_compile_log (line 332-339) reads response['value']['result']['compile_log_id'] and format_exception (line 318-325) reads exception['blobstore_id']; both pass the agent-supplied string…
AnalizadaAlta (8.7)0.46%—Netfoundry Zrok8/5/202617/6/2026
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.2, the zrok WebDAV drive backend (davServer.Dir) restricts path traversal through lexical normalization but does not prevent symlink following. When a symbolic link inside the shared DriveRoot points to a location outside…
AnalizadaCrítica (10)1.1%—Microsoft Azure AI Foundry7/5/202617/6/2026
Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.
AnalizadaMedia (5)0.20%—Cloudfoundry Cf-deploymentCloudfoundry Routing Release1/5/202617/6/2026
Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure a route-service that would allow it to send requests to HTTP services on internal networks reachable by the Gorouter,…
AnalizadaMedia (5.3)0.36%—Netfoundry Zrok17/4/202617/6/2026
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the unaccess handler (controller/unaccess.go) contains a logical error in its ownership guard: when a frontend record has environment_id = NULL (the marker for admin-created global frontends), the condition short-circuits…
AnalizadaAlta (7.5)0.59%—Netfoundry Zrok17/4/202617/6/2026
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, endpoints.GetSessionCookie parses an attacker-supplied cookie chunk count and calls make([]string, count) with no upper bound before any token validation occurs. The function is reached on every request to an…
AnalizadaMedia (6.1)0.26%—Netfoundry Zrok17/4/202617/6/2026
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template engine uses Go's text/template (which performs no HTML escaping) instead of html/template. The GitHub OAuth callback handlers in both publicProxy and dynamicProxy embed the attacker-controlled…
Pendiente de análisisAlta (8.6)0.36%—Cloudfoundry UAAAICloudfoundry CF DeploymentAI17/4/202617/6/2026
Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UAA-protected systems. This vulnerability exists when SAML 2.0 bearer assertions are enabled for a client, as the UAA accepts SAML 2.0 bearer assertions that are neither signed nor encrypted. This…
AnalizadaCrítica (9.8)0.90%—Microsoft Azure AI Foundry3/4/202624/7/2026
Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
Pendiente de análisisAlta (7.5)0.20%—Cloudfoundry Capi ReleaseAICloudfoundry CF DeploymentAI17/3/202617/6/2026
Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on all platforms allows any user who has bypassed the firewall to potentially replace droplets and therefore applications allowing them to access secure application information.
ModificadaMedia (6.5)0.23%—Cloudfoundry Cf-deploymentCloudfoundry Uaa-release5/3/202617/6/2026
Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0.
AplazadaAlta (7.5)0.28%—Foundry Container ServiceAI18/12/202517/6/2026
Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace to communicate with each other. This issue resulted in bypass of access control due to the presence of a vulnerable endpoint in Foundry Container Service that executed user-controlled commands…
AnalizadaAlta (7.5)0.20%—Cloudfoundry Cf-deploymentCloudfoundry UAA Release13/5/202517/6/2026
Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs.
AplazadaMedia (5.9)0.27%—Maxfoundry MaxbuttonsAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in maxfoundry MaxButtons maxbuttons allows Stored XSS.This issue affects MaxButtons: from n/a through <= 9.8.3.
AplazadaAlta (7.1)0.15%—Maxfoundry MaxabAI11/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in maxfoundry MaxA/B maxab allows Stored XSS.This issue affects MaxA/B: from n/a through <= 2.2.2.
AplazadaCrítica (9.3)1.4%—Truefoundry CognitaAI7/3/202517/6/2026
Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for production by TrueFoundry. A path traversal issue exists at /v1/internal/upload-to-local-directory which is enabled when the Local env variable is set to true, such as when Cognita is setup using Docker.…
AplazadaMedia (6.9)0.49%—Truefoundry CognitaAI7/3/202517/6/2026
Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for production by TrueFoundry. An insecure CORS configuration in the Cognita backend server allows arbitrary websites to send cross site requests to the application. This vulnerability is fixed in commit…
AplazadaMedia (6.5)0.51%—Foundry ArtifactsAI18/2/202517/6/2026
Foundry Artifacts was found to be vulnerable to a Denial Of Service attack due to disk being potentially filled up based on an user supplied argument (size).
AnalizadaMedia (4.3)0.34%—Maxfoundry Media Library Folders15/2/202517/6/2026
The Media Library Folders plugin for WordPress is vulnerable to unauthorized plugin settings change due to a missing capability check on several AJAX actions in all versions up to, and including, 8.3.0. This makes it possible for authenticated attackers, with Author-level access and above, to change plugin settings…
AplazadaMedia (5.4)0.19%—Cloudfoundry UAAAI31/1/202517/6/2026
A UAA configured with multiple identity zones, does not properly validate session information across those zones. A User authenticated against a corporate IDP can re-use their jsessionid to access other zones.
AnalizadaMedia (4.7)0.43%—Maxfoundry Maxbuttons20/12/202417/6/2026
The WordPress Button Plugin MaxButtons WordPress plugin before 9.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).