Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
119 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.42% | — | Helmut Wandl Advanced SettingsAI | 6/11/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Upload a Web Shell to a Web Server.This issue affects Advanced Settings: from n/a through <= 3.1.1. | |
| Aplazada | Media (4.3) | 0.12% | — | Helmut Wandl Advanced SettingsAI | 9/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Cross Site Request Forgery.This issue affects Advanced Settings: from n/a through <= 3.1.1. | |
| Aplazada | Crítica (9.4) | 0.35% | — | Onyxia-apiAIKubernetesAIHelmAI | 5/9/2025 | 17/6/2026 | Onyxia is a data science environment for kubernetes. In versions 4.6.0 through 4.8.0, Onyxia-API leaked the credentials of private helm repositories in the public (unauthenticated) /public/catalogs endpoint.vOnly instances using private helm repositories (i.e setting username & password in the catalogs configuration)… | |
| Analizada | Media (5.8) | 0.32% | — | Openfga Helm ChartsOpenfga | 18/8/2025 | 17/6/2026 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.9.3 to v1.9.4 ( openfga-0.2.40 <= Helm chart <= openfga-0.2.41, v1.9.3 <= docker <= v.1.9.4) are vulnerable to improper policy enforcement when certain Check and ListObject calls… | |
| Analizada | Media (6.5) | 0.33% | — | Helm | 14/8/2025 | 17/6/2026 | Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, it is possible to craft a JSON Schema file in a manner which could cause Helm to use all available memory and have an out of memory (OOM) termination. This issue has been resolved in Helm 3.18.5. A workaround involves ensuring all Helm… | |
| Analizada | Media (6.5) | 0.33% | — | Helm | 14/8/2025 | 17/6/2026 | Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, when parsing Chart.yaml and index.yaml files, an improper validation of type error can lead to a panic. This issue has been resolved in Helm 3.18.5. A workaround involves ensuring YAML files are formatted as Helm expects prior to processing… | |
| Aplazada | Crítica (10) | 0.70% | — | Bitnami Helm ChartsAI | 24/7/2025 | 17/6/2026 | Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document root. In affected versions, this can lead to unauthenticated access to sensitive credentials via HTTP/S. A remote attacker could retrieve these secrets by accessing… | |
| Analizada | Alta (8.6) | 0.44% | — | Helm | 8/7/2025 | 17/6/2026 | Helm is a package manager for Charts for Kubernetes. Prior to 3.18.4, a specially crafted Chart.yaml file along with a specially linked Chart.lock file can lead to local code execution when dependencies are updated. Fields in a Chart.yaml file, that are carried over to a Chart.lock file when dependencies are updated… | |
| Aplazada | Media (4.3) | 0.14% | — | Helmut Wandl Advanced SettingsAI | 17/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Cross Site Request Forgery.This issue affects Advanced Settings: from n/a through <= 3.0.1. | |
| Analizada | Media (5.8) | 0.48% | — | Openfga Helm ChartsOpenfga | 22/5/2025 | 17/6/2026 | OpenFGA is an authorization/permission engine. OpenFGA versions 1.8.0 through 1.8.12 (corresponding to Helm chart openfga-0.2.16 through openfga-0.2.30 and docker 1.8.0 through 1.8.12) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. Users are affected under four specific… | |
| Analizada | Media (5.8) | 0.39% | — | Openfga Helm ChartsOpenfga | 30/4/2025 | 17/6/2026 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v1.3.6 (Helm chart <= openfga-0.2.28, docker <= v.1.8.10) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. This issue has been… | |
| Analizada | Media (6.5) | 0.48% | — | Helm | 9/4/2025 | 17/6/2026 | Helm is a package manager for Charts for Kubernetes. A JSON Schema file within a chart can be crafted with a deeply nested chain of references, leading to parser recursion that can exceed the stack size limit and trigger a stack overflow. This issue has been resolved in Helm v3.17.3. | |
| Analizada | Media (6.5) | 0.45% | — | Helm | 9/4/2025 | 17/6/2026 | Helm is a tool for managing Charts. A chart archive file can be crafted in a manner where it expands to be significantly larger uncompressed than compressed (e.g., >800x difference). When Helm loads this specially crafted chart, memory can be exhausted causing the application to terminate. This issue has been resolved… | |
| Analizada | Media (5.8) | 0.43% | — | Openfga Helm ChartsOpenfga | 19/2/2025 | 17/6/2026 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA < v1.8.4 (Helm chart < openfga-0.2.22, docker < v.1.8.4) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. Users on OpenFGA v1.8.4 or… | |
| Analizada | Media (5.8) | 0.45% | — | Openfga Helm ChartsOpenfga | 13/1/2025 | 17/6/2026 | OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19, docker v1.3.8 to v.1.8.2) are vulnerable to authorization bypass under the following conditions: 1. calling Check API or ListObjects with a model that uses… | |
| Aplazada | Baja (2.8) | 0.18% | — | Argoproj Argo HelmAI | 22/11/2024 | 17/6/2026 | Argo Helm is a collection of community maintained charts for `argoproj.github.io` projects. Prior to version 0.45.0, the `workflow-role`) lacks granularity in its privileges, giving permissions to `workflowtasksets` and `workflowartifactgctasks` to all workflow Pods, when only certain types of Pods created by the… | |
| Modificada | Alta (7.5) | 0.63% | — | Mbconnectline Mbnet.mini FirmwareHelmholz REX 100 Firmware | 15/10/2024 | 17/6/2026 | An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication. | |
| Modificada | Crítica (9.8) | 0.80% | — | Mbconnectline Mbnet.mini FirmwareHelmholz REX 100 Firmware | 15/10/2024 | 17/6/2026 | The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices. | |
| Modificada | Crítica (9.8) | 1.5% | — | Mbconnectline Mbnet.mini FirmwareHelmholz REX 100 Firmware | 15/10/2024 | 17/6/2026 | An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication. | |
| Modificada | Alta (7.8) | 0.09% | — | Mbconnectline Mbnet.mini FirmwareHelmholz Myrex24 V2 Virtual ServerHelmholz REX 300 FirmwareHelmholz REX 200 Firmware+11 | 15/10/2024 | 17/6/2026 | An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used. | |
| Modificada | Alta (7.5) | 0.62% | — | Helmholz Myrex24 V2 Virtual ServerHelmholz REX 300 FirmwareHelmholz REX 200 FirmwareHelmholz REX 250 Firmware+9 | 15/10/2024 | 17/6/2026 | An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost. | |
| Modificada | Alta (7.8) | 0.31% | — | Mbconnectline Mbnet.mini FirmwareHelmholz REX 100 Firmware | 15/10/2024 | 17/6/2026 | An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation. | |
| Analizada | Alta (7.5) | 0.86% | — | Apollographql Apollo-routerApollographql Apollo Helms-charts RouterApollographql Apollo Router | 27/8/2024 | 17/6/2026 | The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of the Apollo Router running versions >=1.21.0 and < 1.52.1 are impacted by a denial of service vulnerability if _all_ of the following are true: 1. The Apollo… | |
| Analizada | Alta (7.5) | 0.99% | — | Apollographql Apollo-routerApollographql Apollo GatewayApollographql Apollo Helms-charts RouterApollographql Apollo Query-planner+1 | 27/8/2024 | 17/6/2026 | Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver autonomously and incrementally. Instances of @apollo/query-planner >=2.0.0 and <2.8.5 are impacted by a denial-of-service vulnerability.… | |
| Analizada | Crítica (9.1) | 0.60% | — | Datahub-helm | 20/3/2024 | 17/6/2026 | datahub-helm provides the Kubernetes Helm charts for deploying Datahub and its dependencies on a Kubernetes cluster. Starting in version 0.1.143 and prior to version 0.2.182, due to configuration issues in the helm chart, if there was a successful initial deployment during a limited window of time, personal access… |