Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
698 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.93% | — | Redhat Openshift Container Platform | 2/6/2021 | 17/6/2026 | A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an attacker to cause a denial of service attack on an OpenShift Container Platform cluster if they can deploy pods. The highest threat from this vulnerability is to system… | |
| Modificada | Media (4.3) | 0.71% | — | Elastic KibanaRedhat Openshift Container Platform | 2/6/2021 | 17/6/2026 | It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary actions in OCP's distribution of Kibana, such as clickjacking. | |
| Modificada | Baja (3.3) | 0.69% | — | Containers-image Project Containers-imageRedhat Enterprise Linux | 27/5/2021 | 17/6/2026 | A malicious container image can consume an unbounded amount of memory when being pulled to a container runtime host, such as Red Hat Enterprise Linux using podman, or OpenShift Container Platform. An attacker can use this flaw to trick a user, with privileges to pull container images, into crashing the process… | |
| Modificada | Media (5.5) | 0.26% | — | Gnome NetworkmanagerRedhat Openshift Container PlatformRedhat Enterprise LinuxFedoraproject Fedora | 26/5/2021 | 17/6/2026 | A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability. | |
| Modificada | Alta (7.1) | 1.7% | — | Redhat Openshift Container Platform | 14/5/2021 | 17/6/2026 | A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by using a specially crafted raw container image (.tar file) which contains symbolic links. The vulnerability is limited to the command `oc image extract`. If a symbolic link is first created pointing… | |
| Modificada | Media (6.5) | 1.6% | — | Storage Project StorageRedhat Openshift Container PlatformRedhat Enterprise LinuxFedoraproject Fedora | 1/4/2021 | 17/6/2026 | A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the… | |
| Modificada | Alta (7.2) | 1.5% | — | Linuxfoundation Container Network Interface | 26/3/2021 | 17/6/2026 | An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'type' field in the network configuration, it is possible to use special elements such as "../" separators to reference binaries elsewhere on the system. This flaw allows an… | |
| Modificada | Alta (7.8) | 0.28% | — | Redhat Openshift Container Platform | 24/3/2021 | 17/6/2026 | An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hadoop as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. | |
| Modificada | Alta (7) | 0.33% | — | Redhat Openshift Container Platform | 24/3/2021 | 17/6/2026 | An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hive as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. | |
| Modificada | Alta (7) | 0.26% | — | Redhat Openshift Container Platform | 24/3/2021 | 17/6/2026 | An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/presto as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. | |
| Modificada | Alta (7.5) | 2.8% | — | PygmentsRedhat Openshift Container PlatformRedhat Openstack PlatformRedhat Software Collections+3 | 23/3/2021 | 17/6/2026 | An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword. | |
| Modificada | Media (6.3) | 0.59% | — | Redhat OpenshiftRedhat Openshift Container Platform | 19/3/2021 | 17/6/2026 | A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the GlusterFS StorageClass against leaking of the restuserkey. An attacker with basic-user permissions is able to obtain the value of restuserkey, and use it to authenticate… | |
| Modificada | Alta (7.2) | 1.3% | — | Redhat Openshift Container Platform | 19/3/2021 | 17/6/2026 | A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloads on master nodes. Pods with permission to access the host network, running on master nodes, can retrieve security credentials for the master AWS IAM role, allowing… | |
| Modificada | Alta (7.5) | 3.2% | — | Lldpd Project LldpdOpenvswitchRedhat Openshift Container PlatformRedhat Openstack+13 | 18/3/2021 | 17/6/2026 | A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability. | |
| Modificada | Alta (8.8) | 1.2% | — | Redhat Openshift BuilderRedhat Openshift Container Platform | 16/3/2021 | 17/6/2026 | A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are automatically mounted into the container image under construction. An OpenShift user, able to execute code during build time inside this container can re-use the credentials to overwrite arbitrary… | |
| Modificada | Alta (7.4) | 1.3% | — | Redhat Kubernetes-clientRedhat A-mq OnlineRedhat Build OF QuarkusRedhat Codeready Studio+5 | 16/3/2021 | 17/6/2026 | A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system… | |
| Modificada | Media (6.8) | 1.4% | — | Microsoft Azure Container InstancesMicrosoft Azure Container RegistryMicrosoft Azure Kubernetes ServiceMicrosoft Azure Service Fabric+1 | 11/3/2021 | 19/8/2026 | Azure Virtual Machine Information Disclosure Vulnerability | |
| Modificada | Media (6.3) | 2.0% | — | Linuxfoundation ContainerdFedoraproject Fedora | 10/3/2021 | 17/6/2026 | In containerd (an industry-standard container runtime) before versions 1.3.10 and 1.4.4, containers launched through containerd's CRI implementation (through Kubernetes, crictl, or any other pod/container client that uses the containerd CRI service) that share the same image may receive incorrect environment… | |
| Modificada | Media (4.4) | 0.37% | — | Linux KernelFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux+1 | 4/3/2021 | 17/6/2026 | A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.12-rc1 in the way the user calls ioctl DRM_IOCTL_NOUVEAU_CHANNEL_ALLOC. This flaw allows a local user to crash the system. | |
| Modificada | Alta (7.3) | 0.65% | — | Bitnami Containers | 3/3/2021 | 17/6/2026 | In Bitnami Containers, all Laravel container versions prior to: 6.20.0-debian-10-r107 for Laravel 6, 7.30.1-debian-10-r108 for Laravel 7 and 8.5.11-debian-10-r0 for Laravel 8, the file /tmp/app/.env is generated at the time that the docker image bitnami/laravel was built, and the value of APP_KEY is fixed under… | |
| Modificada | Alta (7.8) | 0.40% | — | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise Linux | 23/2/2021 | 17/6/2026 | There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is registered). As result of BPF execution, the local user can trigger… | |
| Modificada | Alta (8.8) | 1.1% | — | Redhat Openshift Container Platform | 23/2/2021 | 17/6/2026 | A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs with high privileges using a chrooted environment instead of runc. If an attacker can gain access to this build container, they can potentially utilize the raw devices of the underlying node, such as the network and… | |
| Modificada | Alta (7) | 0.26% | — | Podman Project PodmanRedhat Openshift Container PlatformRedhat Enterprise Linux | 11/2/2021 | 17/6/2026 | A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw can be abused by a low-privileged user inside the container to access any other file in the container, even if owned by the root user inside the container. It does not… | |
| Modificada | Crítica (9.8) | 1.6% | — | Containers Project Containers | 26/1/2021 | 17/6/2026 | An issue was discovered in the containers crate before 0.9.11 for Rust. When a panic occurs, a util::{mutate,mutate2} double drop can be performed. | |
| Modificada | Alta (7.8) | 1.3% | — | Emerson Rosemount Transmitter Interface SoftwarePepperl-fuchs PactwareWago Dtminspector 3Wago Fdtcontainer Application+3 | 22/1/2021 | 17/6/2026 | M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage. |