Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
154 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.7) | 0.48% | — | Redhat Advanced Cluster ManagementAIRedhat Multicloud Operators ChannelAI | 12/8/2026 | 27/8/2026 | A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets and ConfigMaps within any Channel… | |
| Pendiente de análisis | Alta (7.7) | 0.48% | — | Multicloud-operators SubscriptionAI | 12/8/2026 | 27/8/2026 | A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Namespace field, the user can cause the system to copy sensitive Secret… | |
| Pendiente de análisis | Media (6.4) | 0.33% | — | Multicloud-operators ChannelAI | 12/8/2026 | 5/9/2026 | A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the system handles sensitive information, known as Secrets, across different parts of the system (namespaces). By exploiting this, an attacker can modify these Secrets in… | |
| Pendiente de análisis | Media (5.5) | 0.39% | — | Feast OperatorAI | 10/8/2026 | 19/8/2026 | A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by an automated process with elevated privileges, allowing the tenant to steal sensitive credentials. This could lead to a direct escalation of privileges, granting the… | |
| Pendiente de análisis | Alta (7.7) | 0.83% | — | FeastAIFeast-operatorAI | 10/8/2026 | 14/8/2026 | A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is "no_auth," meaning no security manager is installed. This default allows unauthenticated and unauthorized access to feature-server, registry-server, and offline-server endpoints. A remote attacker,… | |
| Pendiente de análisis | Alta (8.8) | 0.73% | — | Data Science Pipelines OperatorAIMysqlAI | 10/8/2026 | 21/9/2026 | A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Source Name (DSN) string. By manipulating these parameters, an attacker can enable… | |
| Pendiente de análisis | Alta (7.5) | 0.61% | — | MariadbAIMinioAIRedhat Data Science Pipelines OperatorAI | 10/8/2026 | 21/9/2026 | A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords and MinIO access/secret keys, if they can access the MinIO Route or MariaDB Service. The flaw occurs because the operator uses a… | |
| Pendiente de análisis | Alta (8.7) | 0.70% | — | Kubeflow Data Science Pipelines OperatorAI | 10/8/2026 | 21/9/2026 | A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to execute commands within pods and manage cluster-wide roles, could be… | |
| Pendiente de análisis | Alta (8.1) | 0.60% | — | Trustyai-service-operatorAI | 10/8/2026 | 21/9/2026 | A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote code, leading to arbitrary code… | |
| Analizada | Crítica (9.8) | 0.34% | — | IBM Application Gateway Operator | 5/8/2026 | 10/8/2026 | IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources. | |
| Analizada | Media (6.8) | 0.46% | — | Redhat Cost Management Metrics Operator | 30/7/2026 | 12/8/2026 | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token endpoint. When authentication.type is set to service-account, the operator sends the tenant's Red Hat SSO client_id and client_secret to this… | |
| Analizada | Alta (7.6) | 0.32% | — | Redhat Cost Management Metrics Operator | 30/7/2026 | 12/8/2026 | A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL,… | |
| Analizada | Media (6.8) | 0.39% | — | Redhat Cost Management Metrics Operator | 30/7/2026 | 17/8/2026 | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer token is attached to HTTP requests sent… | |
| Aplazada | Crítica (9.9) | 0.78% | — | Banzai Cloud Logging OperatorAI | 29/7/2026 | 10/9/2026 | Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such as Flow record_transformer.records values directly into fluent.conf without escaping, allowing a… | |
| Pendiente de análisis | Alta (7.1) | 0.23% | — | Kong Kubernetes Ingress ControllerAIKong OperatorAIKong GatewayAI | 29/7/2026 | 30/7/2026 | Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. The embedded KIC collects CA-certificate Secrets across all watched namespaces using a label selector alone, without… | |
| Pendiente de análisis | Media (6.5) | 0.35% | — | Tempo OperatorAI | 13/7/2026 | 13/7/2026 | The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces. | |
| Pendiente de análisis | Media (6.3) | 0.28% | — | Trustyai-service-operatorAITrustyai GorchAI | 8/7/2026 | 31/8/2026 | A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication is enabled, the gorch service exposes unproxied orchestrator and detector metrics ports. This allows any pod on the cluster network to directly access these ports, bypassing the kube-rbac-proxy and… | |
| Pendiente de análisis | Media (6.3) | 0.27% | — | Trustyai Service OperatorAIGorchAINemoguardrailsAI | 8/7/2026 | 31/8/2026 | A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enabled, these services can expose their communication channels without requiring users to prove their identity. This allows any other program within the cluster to access the… | |
| Analizada | Media (6.8) | 0.38% | — | Redhat Cluster Logging OperatorRedhat Logging Subsystem FOR RED HAT Openshift | 23/6/2026 | 8/7/2026 | A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output destinations without verifying that the ClusterLogForwarder creator has permission to use those credentials, allowing a delegated editor to exfiltrate SA tokens and… | |
| Modificada | Alta (8.3) | 0.30% | — | Redhat Openshift Container PlatformRedhat Windows Machine Config Operator | 22/6/2026 | 9/9/2026 | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH session can capture WICD and kubelet… | |
| Modificada | Alta (8.8) | 0.11% | — | Redhat Openshift Container PlatformRedhat Windows Machine Config Operator | 22/6/2026 | 9/9/2026 | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows… | |
| Modificada | Media (6.4) | 0.36% | — | Grafana Operator | 13/6/2026 | 23/7/2026 | We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM severity security fix for a path traversal/privilege escalation vulnerability in the Grafana Operator. ### Summary The Grafana Operator supports loading dashboards & library panels using the jsonnet data templating language. The… | |
| Pendiente de análisis | Alta (7.1) | 0.22% | — | Openshift Pipelines OperatorAITektonAIKueueAICert-managerAI | 4/6/2026 | 6/9/2026 | A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any… | |
| Pendiente de análisis | Media (5.1) | 0.13% | — | IBM MQAIIBM MQ OperatorAI | 27/5/2026 | 17/6/2026 | IBM MQ Operator SC2: v3.2.0 through 3.2.23CD: v3.3.0, v3.4.0, v3.4.1, v3.5.0, v3.5.1 - v3.5.3, v3.6.0 - v3.6.4, v3.7.0 - v3.7.2, v3.8.0, v3.8.1, v3.9.0, v3.9.1LTS: v2.0.0 - 2.0.29 and IBM supplied MQ Advanced container images SC2: 9.4.0.6 through r1, 9.4.0.6-r2, 9.4.0.7-r1, 9.4.0.10-r1, 9.4.0.10-r2, 9.4.0.11-r1,… | |
| Modificada | Media (6.5) | 0.49% | — | Apache Flink Kubernetes Operator | 26/5/2026 | 24/7/2026 | Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI is currently not validated so that it points to user-owned files or addresses. This lets a user with CR create permissions read files from the operator… |