Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

119 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.1)0.42%—Helmut Wandl Advanced SettingsAI6/11/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Upload a Web Shell to a Web Server.This issue affects Advanced Settings: from n/a through <= 3.1.1.
AplazadaMedia (4.3)0.12%—Helmut Wandl Advanced SettingsAI9/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Cross Site Request Forgery.This issue affects Advanced Settings: from n/a through <= 3.1.1.
AplazadaCrítica (9.4)0.35%—Onyxia-apiAIKubernetesAIHelmAI5/9/202517/6/2026
Onyxia is a data science environment for kubernetes. In versions 4.6.0 through 4.8.0, Onyxia-API leaked the credentials of private helm repositories in the public (unauthenticated) /public/catalogs endpoint.vOnly instances using private helm repositories (i.e setting username & password in the catalogs configuration)…
AnalizadaMedia (5.8)0.32%—Openfga Helm ChartsOpenfga18/8/202517/6/2026
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.9.3 to v1.9.4 ( openfga-0.2.40 <= Helm chart <= openfga-0.2.41, v1.9.3 <= docker <= v.1.9.4) are vulnerable to improper policy enforcement when certain Check and ListObject calls…
AnalizadaMedia (6.5)0.33%—Helm14/8/202517/6/2026
Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, it is possible to craft a JSON Schema file in a manner which could cause Helm to use all available memory and have an out of memory (OOM) termination. This issue has been resolved in Helm 3.18.5. A workaround involves ensuring all Helm…
AnalizadaMedia (6.5)0.33%—Helm14/8/202517/6/2026
Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, when parsing Chart.yaml and index.yaml files, an improper validation of type error can lead to a panic. This issue has been resolved in Helm 3.18.5. A workaround involves ensuring YAML files are formatted as Helm expects prior to processing…
AplazadaCrítica (10)0.70%—Bitnami Helm ChartsAI24/7/202517/6/2026
Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document root. In affected versions, this can lead to unauthenticated access to sensitive credentials via HTTP/S. A remote attacker could retrieve these secrets by accessing…
AnalizadaAlta (8.6)0.44%—Helm8/7/202517/6/2026
Helm is a package manager for Charts for Kubernetes. Prior to 3.18.4, a specially crafted Chart.yaml file along with a specially linked Chart.lock file can lead to local code execution when dependencies are updated. Fields in a Chart.yaml file, that are carried over to a Chart.lock file when dependencies are updated…
AplazadaMedia (4.3)0.14%—Helmut Wandl Advanced SettingsAI17/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Cross Site Request Forgery.This issue affects Advanced Settings: from n/a through <= 3.0.1.
AnalizadaMedia (5.8)0.48%—Openfga Helm ChartsOpenfga22/5/202517/6/2026
OpenFGA is an authorization/permission engine. OpenFGA versions 1.8.0 through 1.8.12 (corresponding to Helm chart openfga-0.2.16 through openfga-0.2.30 and docker 1.8.0 through 1.8.12) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. Users are affected under four specific…
AnalizadaMedia (5.8)0.39%—Openfga Helm ChartsOpenfga30/4/202517/6/2026
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v1.3.6 (Helm chart <= openfga-0.2.28, docker <= v.1.8.10) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. This issue has been…
AnalizadaMedia (6.5)0.48%—Helm9/4/202517/6/2026
Helm is a package manager for Charts for Kubernetes. A JSON Schema file within a chart can be crafted with a deeply nested chain of references, leading to parser recursion that can exceed the stack size limit and trigger a stack overflow. This issue has been resolved in Helm v3.17.3.
AnalizadaMedia (6.5)0.45%—Helm9/4/202517/6/2026
Helm is a tool for managing Charts. A chart archive file can be crafted in a manner where it expands to be significantly larger uncompressed than compressed (e.g., >800x difference). When Helm loads this specially crafted chart, memory can be exhausted causing the application to terminate. This issue has been resolved…
AnalizadaMedia (5.8)0.43%—Openfga Helm ChartsOpenfga19/2/202517/6/2026
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA < v1.8.4 (Helm chart < openfga-0.2.22, docker < v.1.8.4) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. Users on OpenFGA v1.8.4 or…
AnalizadaMedia (5.8)0.45%—Openfga Helm ChartsOpenfga13/1/202517/6/2026
OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19, docker v1.3.8 to v.1.8.2) are vulnerable to authorization bypass under the following conditions: 1. calling Check API or ListObjects with a model that uses…
AplazadaBaja (2.8)0.18%—Argoproj Argo HelmAI22/11/202417/6/2026
Argo Helm is a collection of community maintained charts for `argoproj.github.io` projects. Prior to version 0.45.0, the `workflow-role`) lacks granularity in its privileges, giving permissions to `workflowtasksets` and `workflowartifactgctasks` to all workflow Pods, when only certain types of Pods created by the…
ModificadaAlta (7.5)0.63%—Mbconnectline Mbnet.mini FirmwareHelmholz REX 100 Firmware15/10/202417/6/2026
An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
ModificadaCrítica (9.8)0.80%—Mbconnectline Mbnet.mini FirmwareHelmholz REX 100 Firmware15/10/202417/6/2026
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
ModificadaCrítica (9.8)1.5%—Mbconnectline Mbnet.mini FirmwareHelmholz REX 100 Firmware15/10/202417/6/2026
An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
ModificadaAlta (7.8)0.09%—Mbconnectline Mbnet.mini FirmwareHelmholz Myrex24 V2 Virtual ServerHelmholz REX 300 FirmwareHelmholz REX 200 Firmware+1115/10/202417/6/2026
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
ModificadaAlta (7.5)0.62%—Helmholz Myrex24 V2 Virtual ServerHelmholz REX 300 FirmwareHelmholz REX 200 FirmwareHelmholz REX 250 Firmware+915/10/202417/6/2026
An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost.
ModificadaAlta (7.8)0.31%—Mbconnectline Mbnet.mini FirmwareHelmholz REX 100 Firmware15/10/202417/6/2026
An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.
AnalizadaAlta (7.5)0.86%—Apollographql Apollo-routerApollographql Apollo Helms-charts RouterApollographql Apollo Router27/8/202417/6/2026
The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of the Apollo Router running versions >=1.21.0 and < 1.52.1 are impacted by a denial of service vulnerability if _all_ of the following are true: 1. The Apollo…
AnalizadaAlta (7.5)0.99%—Apollographql Apollo-routerApollographql Apollo GatewayApollographql Apollo Helms-charts RouterApollographql Apollo Query-planner+127/8/202417/6/2026
Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver autonomously and incrementally. Instances of @apollo/query-planner >=2.0.0 and <2.8.5 are impacted by a denial-of-service vulnerability.…
AnalizadaCrítica (9.1)0.60%—Datahub-helm20/3/202417/6/2026
datahub-helm provides the Kubernetes Helm charts for deploying Datahub and its dependencies on a Kubernetes cluster. Starting in version 0.1.143 and prior to version 0.2.182, due to configuration issues in the helm chart, if there was a successful initial deployment during a limited window of time, personal access…