Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

601 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.70%—Linuxfoundation Kubeedge11/7/202217/6/2026
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, the CloudCore Router does not impose a limit on the size of responses to requests made by the REST handler. An attacker could use this weakness to…
ModificadaMedia (6.5)1.00%—Linuxfoundation Kubeedge11/7/202217/6/2026
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, EdgeCore may be susceptible to a DoS attack on CloudHub if an attacker was to send a well-crafted HTTP request to `/edge.crt`. If an attacker can…
ModificadaMedia (6.5)0.82%—Linuxfoundation Kubeedge11/7/202217/6/2026
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, several endpoints in the Cloud AdmissionController may be susceptible to a DoS attack if an HTTP request containing a very large Body is sent to it.…
ModificadaAlta (7.5)1.7%—Linuxfoundation Kubeedge11/7/202217/6/2026
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, the ServiceBus server on the edge side may be susceptible to a DoS attack if an HTTP request containing a very large Body is sent to it. It is…
ModificadaMedia (5.7)0.82%—Linuxfoundation Kubeedge27/6/202217/6/2026
KubeEdge is built upon Kubernetes and extends native containerized application orchestration and device management to hosts at the Edge. In affected versions a malicious message response from KubeEdge can crash the CSI Driver controller server by triggering a nil-pointer dereference panic. As a consequence, the CSI…
ModificadaMedia (5.7)0.61%—Linuxfoundation Kubeedge27/6/202217/6/2026
KubeEdge is built upon Kubernetes and extends native containerized application orchestration and device management to hosts at the Edge. In affected versions a malicious message can crash CloudCore by triggering a nil-pointer dereference in the UDS Server. Since the UDS Server only communicates with the CSI Driver on…
ModificadaMedia (5.5)0.38%—Linuxfoundation ContainerdDebian LinuxFedoraproject Fedora9/6/202217/6/2026
containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs inside a container can cause the containerd daemon to consume memory without bound during invocation of the `ExecSync` API. This can cause containerd to consume all available memory on the computer,…
ModificadaAlta (7.8)0.39%—Linuxfoundation RuncFedoraproject Fedora17/5/202217/6/2026
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with…
ModificadaAlta (7.5)2.7%—Linuxfoundation ImgcryptFedoraproject Fedora25/3/202217/6/2026
The imgcrypt library provides API exensions for containerd to support encrypted container images and implements the ctd-decoder command line tool for use by containerd to decrypt encrypted container images. The imgcrypt function `CheckAuthorization` is supposed to check whether the current used is authorized to access…
ModificadaAlta (7.5)1.2%—Linuxfoundation Grpc Swift25/3/202217/6/2026
grpc-swift is the Swift language implementation of gRPC, a remote procedure call (RPC) framework. Prior to version 1.7.2, a grpc-swift server is vulnerable to a denial of service attack via a reachable assertion. This is due to incorrect logic when handling GOAWAY frames. The attack is low-effort: it takes very little…
ModificadaMedia (5.9)0.49%—Mobyproject MobyFedoraproject FedoraLinuxfoundation RuncDebian Linux24/3/202217/6/2026
Moby is an open-source project created by Docker to enable and accelerate software containerization. A bug was found in Moby (Docker Engine) prior to version 20.10.14 where containers were incorrectly started with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling…
ModificadaMedia (6.5)2.3%—Linuxfoundation Nats-serverNats Streaming Server10/3/202217/6/2026
NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-server before 0.24.3 is also affected.
ModificadaAlta (7.5)27%💥 PoCLinuxfoundation ContainerdDebian LinuxFedoraproject Fedora3/3/202217/6/2026
containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration could gain access to read-only copies of…
ModificadaAlta (8.8)1.3%—Linuxfoundation Nats-serverNats Streaming Server8/2/202217/6/2026
NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature.
ModificadaCrítica (9.1)1.7%—Linuxfoundation ContainerdFedoraproject Fedora5/1/202217/6/2026
containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod scheduled to the node may bind mount, via hostPath volume, any privileged,…
ModificadaCrítica (9.8)2.6%—Linuxfoundation Spinnaker4/1/202217/6/2026
Spinnaker is an open source, multi-cloud continuous delivery platform. Spinnaker has improper permissions allowing pipeline creation & execution. This lets an arbitrary user with access to the gate endpoint to create a pipeline and execute it without authentication. If users haven't setup Role-based access control…
ModificadaAlta (7.1)0.34%—Linuxfoundation Spinnaker4/1/202217/6/2026
Spinnaker is an open source, multi-cloud continuous delivery platform. A path traversal vulnerability was discovered in uses of TAR files by AppEngine for deployments. This uses a utility to extract files locally for deployment without validating the paths in that deployment don't override system files. This would…
ModificadaAlta (7.5)1.1%—Linuxfoundation Tremor-script27/12/202117/6/2026
An issue was discovered in the tremor-script crate before 0.11.6 for Rust. A merge operation may result in a use-after-free.
ModificadaCrítica (9.8)1.2%—Linuxfoundation Tremor-script27/12/202117/6/2026
An issue was discovered in the tremor-script crate before 0.11.6 for Rust. A patch operation may result in a use-after-free.
ModificadaCrítica (9.8)30%—Linuxfoundation DojoOracle Communications Policy ManagementOracle Primavera UnifierOracle Weblogic Server+117/12/202117/6/2026
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
ModificadaAlta (8.1)0.45%—Linuxfoundation Longhorn17/12/202117/6/2026
A Missing Authentication for Critical Function vulnerability in longhorn of SUSE Longhorn allows attackers to connect to a longhorn-engine replica instance granting it the ability to read and write data to and from a replica that they should not have access to. This issue affects: SUSE Longhorn longhorn versions prior…
ModificadaCrítica (9.6)0.66%—Linuxfoundation Longhorn17/12/202117/6/2026
A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to execute any binary present in the image on the host without authentication. This issue affects: SUSE Longhorn longhorn versions prior to 1.1.3; longhorn versions prior to 1.2.3.
ModificadaAlta (7.5)1.5%—Linuxfoundation Besu13/12/202117/6/2026
Besu is an Ethereum client written in Java. Starting in version 21.10.0, changes in the implementation of the SHL, SHR, and SAR operations resulted in the introduction of a signed type coercion error in values that represent negative values for 32 bit signed integers. Smart contracts that ask for shifts between…
ModificadaMedia (5)1.8%—Linuxfoundation RuncDebian Linux6/12/202117/6/2026
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc, netlink is used internally as a serialization system for specifying the relevant container configuration to the `C` portion of the code (responsible for the based namespace setup of containers). In all versions…
AnalizadaAlta (8.5)1.2%—Linuxfoundation Backstage29/11/202117/6/2026
@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. In affected versions a malicious actor with write access to a registered scaffolder template is able to manipulate the template in a way that writes files to arbitrary paths on the scaffolder-backend host instance. This…
Orbitaley — Vulnerabilidades