Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
599 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 1.1% | — | Linuxfoundation Spinnaker | 10/7/2026 | 21/7/2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations allow unsafe YAML tag processing in rosco manifests. This can lead to remote code execution on rosco pods when performing… | |
| Analizada | Alta (8.8) | 1.0% | — | Linuxfoundation Spinnaker | 10/7/2026 | 21/7/2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or CloudFoundry baking. The use of a non-safe constructor allows arbitrary loading of Java classes,… | |
| Aplazada | Alta (8.2) | 0.20% | — | Linuxfoundation LimaAI | 10/7/2026 | 14/7/2026 | Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to 2.1.3, on an instance of Lima running with the qemu driver, an arbitrary user in the VM could access /run/lima-guestagent.sock when the guest agent is enabled, which could result in running arbitrary commands with root… | |
| Aplazada | Alta (7) | 0.15% | — | Linuxfoundation OsqueryAI | 10/7/2026 | 14/7/2026 | osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Windows, a local unprivileged attacker can cause a heap buffer out-of-bounds write if there is a query of the authenticode table targeting a maliciously crafted binary, due to publisher information… | |
| Aplazada | Alta (7) | 0.15% | — | Linuxfoundation OsqueryAI | 10/7/2026 | 14/7/2026 | osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Windows, a local unprivileged attacker can cause a heap buffer out-of-bounds write if there is a query of the processes table targeting a maliciously crafted process, due to unchecked PEB string lengths… | |
| Aplazada | Media (4.4) | 0.13% | — | Linuxfoundation OsqueryAI | 10/7/2026 | 10/7/2026 | osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, an unprivileged attacker can read the contents of an osquery file carve until the carve completes and the temporary files are deleted because in-progress carve directories are not created with private… | |
| Analizada | Media (5.4) | 0.29% | — | Linuxfoundation Nats-server | 8/7/2026 | 9/7/2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client could be registered as the configured no_auth_user through a parser path used when the first client operation was not CONNECT, bypassing user-level connection restrictions such as… | |
| Analizada | Alta (7.5) | 0.60% | — | Linuxfoundation Nats-server | 8/7/2026 | 9/7/2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener could route requests for the MQTT-over-WebSocket path into MQTT handling even when MQTT was not configured, allowing an unauthenticated client with access to the WebSocket… | |
| Analizada | Media (6.5) | 0.56% | — | Linuxfoundation Nats-server | 8/7/2026 | 9/7/2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client able to send account-scoped connection monitoring requests could crash the server by supplying Connz pagination Offset and Limit values that overflowed internal arithmetic before the… | |
| Analizada | Media (5.3) | 0.31% | — | Linuxfoundation Nats-server | 8/7/2026 | 13/7/2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.8, message trace destination checks were applied to ordinary client connections but not consistently to messages arriving through leafnode connections, allowing a leafnode operator to send trace… | |
| Analizada | Alta (8.8) | 0.37% | — | Linuxfoundation Nats-server | 8/7/2026 | 13/7/2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, when no_auth_user was configured, a parser fast path intended for ordinary client connections could also apply to route or leafnode listeners, allowing an unauthenticated peer to… | |
| Analizada | Media (6.5) | 0.46% | — | Linuxfoundation Nats-server | 8/7/2026 | 13/7/2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user could receive messages on denied subjects when a wildcard subscription overlapped with a configured wildcard deny rule but was not a subset of it, and queue… | |
| Analizada | Media (6.5) | 0.46% | — | Linuxfoundation Nats-server | 8/7/2026 | 13/7/2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user with subscription deny permissions could bypass a plain subject deny rule by using a queue subscription, because queue-specific deny evaluation could override… | |
| Analizada | Alta (7.5) | 0.74% | — | Linuxfoundation Nats-server | 8/7/2026 | 13/7/2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2.11.17, an unauthenticated peer with network access to a leafnode listener with compression enabled could crash the server during the pre-authentication leafnode handshake by sending repeated leafnode… | |
| Analizada | Media (4.3) | 0.35% | — | Linuxfoundation Nats-server | 8/7/2026 | 13/7/2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an authenticated MQTT client could subscribe to the internal $MQTT.deliver.pubrel subject family, bypassing configured subscribe permissions and exposing MQTT QoS2 protocol metadata for… | |
| Analizada | Alta (7.1) | 0.44% | — | Linuxfoundation Nats-server | 8/7/2026 | 13/7/2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.1 and 2.12.9, an MQTT client could include protocol control characters in subscription filters that were later forwarded as NATS protocol data to route or leafnode connections, corrupting the forwarded… | |
| Analizada | Alta (7.5) | 0.74% | — | Linuxfoundation Nats-server | 8/7/2026 | 13/7/2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an unauthenticated MQTT client could cause the server to retain large incomplete MQTT CONNECT packets before authentication completed, consuming server memory while the parser waited for the… | |
| Analizada | Media (4.3) | 0.34% | — | Linuxfoundation Nats-server | 8/7/2026 | 13/7/2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, MQTT retained message delivery and QoS1+ durable replay could deliver messages whose original topics matched a subscriber configured subscribe deny rule because these delivery paths did not… | |
| Analizada | Media (5.5) | 0.19% | — | Linuxfoundation Onnx | 8/7/2026 | 13/7/2026 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.9.0 before 1.22.0, onnx.version_converter.convert_version() can dereference a null pointer in Upsample_6_7::adapt_upsample_6_7() in onnx/version_converter/adapters/upsample_6_7.h when processing an untrusted model… | |
| Analizada | Alta (7.5) | 0.46% | — | Linuxfoundation Opentelemetry Instrumentation FOR Java | 1/7/2026 | 6/7/2026 | OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.27.0, the RMI context propagation payload reader limits the number of context entries but does not limit the aggregate size of the strings read from the stream. An attacker who… | |
| Analizada | Media (6.5) | 0.38% | — | Linuxfoundation Opentelemetry Instrumentation FOR Java | 1/7/2026 | 6/7/2026 | OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.28.0, the JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when the password is double-quoted. As a result, clear-text database passwords can… | |
| Analizada | Alta (8.4) | 0.35% | — | Linuxfoundation Containerd | 1/7/2026 | 2/7/2026 | containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. When restoring a container from a checkpoint, containerd… | |
| Analizada | Alta (8.2) | 0.17% | — | Linuxfoundation Containerd | 1/7/2026 | 2/7/2026 | containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plugin restores container.log from a checkpoint image without validating a symlinked path. This could result in reading an arbitrary file on the host via kubectl logs. This issue has been fixed in… | |
| Analizada | Media (5.6) | 0.30% | — | Linuxfoundation Containerd | 1/7/2026 | 2/7/2026 | containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the image references specified within a checkpoint image's configuration. An attacker with permissions to create pods can use a crafted… | |
| Analizada | Media (5.3) | 0.27% | — | Linuxfoundation Containerd | 1/7/2026 | 2/7/2026 | containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM)… |