Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
39 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9) | 0.69% | — | Garden | 9/10/2023 | 17/6/2026 | Garden provides automation for Kubernetes development and testing. Prior tov ersions 0.13.17 and 0.12.65, Garden has a dependency on the cryo library, which is vulnerable to code injection due to an insecure implementation of deserialization. Garden stores serialized objects using cryo in the Kubernetes `ConfigMap`… | |
| Modificada | Media (6.5) | 0.45% | — | Earthgarden Waiting Project Earthgarden Waiting | 20/9/2023 | 17/6/2026 | An information leak in Earthgarden_waiting 13.6.1 allows attackers to obtain the channel access token and send crafted messages. | |
| Modificada | Media (6.5) | 0.64% | — | Wisdomgarden Tronclass Ilearn | 27/3/2023 | 17/6/2026 | WisdomGarden Tronclass has improper access control when uploading file. An authenticated remote attacker with general user privilege can exploit this vulnerability to access files belonging to other users by modifying the file ID within URL. | |
| Modificada | Crítica (9.8) | 1.2% | — | Garden | 11/4/2022 | 17/6/2026 | Garden is an automation platform for Kubernetes development and testing. In versions prior to 0.12.39 multiple endpoints did not require authentication. In some operating modes this allows for an attacker to gain access to the application erroneously. The configuration is leaked through the /api endpoint on the local… | |
| Modificada | Alta (7.5) | 1.9% | — | Gardener | 5/6/2019 | 17/6/2026 | In Gardener before 0.20.0, incorrect access control in seed clusters allows information disclosure by sending HTTP GET requests from one's own shoot clusters to foreign shoot clusters. This occurs because traffic from shoot to seed via the VPN endpoint is not blocked. | |
| Modificada | Alta (8.5) | 1.3% | — | Gardener | 9/10/2018 | 17/6/2026 | Following the Gardener architecture, the Kubernetes apiserver of a Gardener managed shoot cluster resides in the corresponding seed cluster. Due to missing network isolation a shoot's apiserver can access services/endpoints in the private network of its corresponding seed cluster. Combined with other minor Kubernetes… | |
| Modificada | Media (6.5) | 1.2% | — | Cloudfoundry Garden-runc | 18/9/2018 | 17/6/2026 | Cloud Foundry Garden-runC release, versions prior to 1.16.1, prevents deletion of some app environments based on file attributes. A remote authenticated malicious user may create and delete apps with crafted file attributes to cause a denial of service for new app instances or scaling up of existing apps. | |
| Modificada | Media (6.5) | 1.1% | — | Cloudfoundry Garden-runcCloudfoundry Cf-deployment | 30/4/2018 | 17/6/2026 | Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may push an app with a malicious Docker image that will consume more space on a Diego cell than allocated in their quota, potentially causing a DoS against the cell. | |
| Modificada | Alta (8.8) | 0.92% | — | Cloudfoundry Cf-deploymentCloudfoundry Garden-runc-release | 29/3/2018 | 17/6/2026 | Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to obtain leaked credentials and perform authenticated actions using those credentials. | |
| Modificada | Alta (7.5) | 1.3% | — | Cloudfoundry Garden | 19/3/2018 | 17/6/2026 | In Garden versions 0.22.0-0.329.0, a vulnerability has been discovered in the garden-linux nstar executable that allows access to files on the host system. By staging an application on Cloud Foundry using Diego and Garden installations with a malicious custom buildpack an end user could read files on the host system… | |
| Modificada | Crítica (9.8) | 1.6% | — | Cloudfoundry Garden LinuxPivotal Software Cloud Foundry Elastic Runtime | 25/5/2017 | 17/6/2026 | Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw in managing container files during Docker image preparation that could be used to delete, corrupt or overwrite host files and directories, including other container filesystems on the host. | |
| Modificada | Media (5.4) | 0.27% | — | Pacificmags Better Homes AND Gardens AUS | 21/10/2014 | 17/6/2026 | The Better Homes and Gardens Aus (aka com.pacificmagazines.betterhomesandgardens) application @7F0801B2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Mocoga Kakao Bingo Garden | 21/10/2014 | 17/6/2026 | The Kakao Bingo Garden (aka com.mocoga.bingogarden) application 1.0.14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.1% | — | Aquagardensoft Mysql-lists | 27/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in mysql-lists 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |