Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
698 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 2.3% | — | Kubernetes Container Storage Interface Snapshotter | 21/1/2021 | 17/6/2026 | Kubernetes CSI snapshot-controller prior to v2.1.3 and v3.0.2 could panic when processing a VolumeSnapshot custom resource when: - The VolumeSnapshot referenced a non-existing PersistentVolumeClaim and the VolumeSnapshot did not reference any VolumeSnapshotClass. - The snapshot-controller crashes, is automatically… | |
| Modificada | Crítica (9.8) | 4.9% | — | GrafanaSaml Project SamlRedhat Openshift Container PlatformRedhat Openshift Service Mesh+2 | 21/12/2020 | 17/6/2026 | A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. | |
| Modificada | Alta (7.1) | 0.31% | — | Redhat CephRedhat Ceph StorageRedhat Openshift Container PlatformRedhat Openstack Platform+1 | 18/12/2020 | 17/6/2026 | User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all… | |
| Modificada | Media (6.7) | 0.48% | — | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise Linux | 15/12/2020 | 17/6/2026 | A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a locked down (usually due to Secure Boot) guest system running on top of PowerVM or KVM hypervisors (pseries platform) a root like local user could use this flaw to further increase their privileges to that of a running… | |
| Modificada | Alta (7.8) | 1.7% | 💥 PoC | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise MRG+2 | 11/12/2020 | 17/6/2026 | A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permissions to issue ioctl commands to midi devices could trigger a use-after-free issue. A write to this specific memory while freed and before use causes the flow of execution to change and possibly allow… | |
| Modificada | Alta (8.8) | 2.0% | — | Katacontainers Kata Containers | 7/12/2020 | 17/6/2026 | An issue was discovered in Kata Containers through 1.11.3 and 2.x through 2.0-rc1. The runtime will execute binaries given using annotations without any kind of validation. Someone who is granted access rights to a cluster will be able to have kata-runtime execute arbitrary binaries as root on the worker nodes. | |
| Modificada | Media (6.1) | 0.65% | — | Elastic KibanaRedhat Openshift Container Platform | 2/12/2020 | 17/6/2026 | The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the original openshift-logging console link (kibana console) to different one, created based on the new CR for the new kibana resource. This could lead to an arbitrary URL… | |
| Modificada | Media (5.2) | 3.2% | 💥 PoC | Linuxfoundation ContainerdFedoraproject FedoraDebian Linux | 1/12/2020 | 17/6/2026 | containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd before versions 1.3.9 and 1.4.3, the containerd-shim API is improperly exposed to host network containers. Access controls for the shim’s API socket verified that the connecting process had an… | |
| Modificada | Media (5.5) | 0.42% | — | Heketi Project HeketiRedhat Gluster StorageRedhat Openshift Container PlatformRedhat Enterprise Linux | 24/11/2020 | 17/6/2026 | An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords. | |
| Modificada | Alta (8.8) | 1.0% | — | Redhat CephRedhat Ceph StorageRedhat Openshift Container PlatformFedoraproject Fedora | 23/11/2020 | 17/6/2026 | A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with access to the Ceph cluster network to authenticate with the Ceph service via a… | |
| Modificada | Alta (7.1) | 0.37% | — | Katacontainers Kata-containers | 17/11/2020 | 17/6/2026 | An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath volume and mounting either a file or directory into a container as readonly, the file/directory is mounted as readOnly inside the container, but is still writable inside the guest. For a container… | |
| Modificada | Media (5.4) | 0.67% | — | IBM APP Connect Enterprise Certified Container | 3/11/2020 | 17/6/2026 | IBM App Connect Enterprise Certified Container 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly… | |
| Modificada | Media (6.5) | 0.86% | — | HP Bluedata EpicHP Ezmeral Container Platform | 26/10/2020 | 17/6/2026 | The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval. Specifically, they display the kdc_admin_password in the source file of the url… | |
| Modificada | Media (6.1) | 2.3% | — | Linuxfoundation ContainerdCanonical Ubuntu LinuxDebian Linux | 16/10/2020 | 17/6/2026 | In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Schema 2 format includes a URL for the location of a specific image layer (otherwise known as a “foreign layer”), the… | |
| Modificada | Media (5.3) | 1.4% | — | Podman Project PodmanRedhat Openshift Container PlatformRedhat Enterprise LinuxFedoraproject Fedora | 23/9/2020 | 17/6/2026 | An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent… | |
| Modificada | Media (6.4) | 1.6% | — | GNU Grub2Redhat Enterprise Linux Atomic HostRedhat Openshift Container PlatformRedhat Enterprise Linux+11 | 29/7/2020 | 17/6/2026 | Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of… | |
| Modificada | Media (6.4) | 0.98% | — | GNU Grub2Redhat Enterprise Linux Atomic HostRedhat Openshift Container PlatformCanonical Ubuntu Linux+10 | 29/7/2020 | 17/6/2026 | GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and… | |
| Modificada | Media (6.4) | 1.4% | — | GNU Grub2Redhat Enterprise Linux Atomic HostRedhat Openshift Container PlatformCanonical Ubuntu Linux+10 | 29/7/2020 | 17/6/2026 | GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects… | |
| Modificada | Alta (8.8) | 0.32% | — | DockerRedhat Openshift Container PlatformRedhat Enterprise Linux Server | 13/7/2020 | 17/6/2026 | The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304. This issue could allow a malicious or compromised container to compromise the container host and… | |
| Modificada | Alta (7.5) | 1.1% | — | Redhat Openshift Container Platform | 12/6/2020 | 17/6/2026 | A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an API Server error to read the logs, and use the leaked OAuthToken to log into the API Server with… | |
| Modificada | Alta (8.8) | 0.47% | — | Katacontainers RuntimeFedoraproject Fedora | 10/6/2020 | 17/6/2026 | A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path, potentially allowing for code execution on the host. This issue affects: Kata Containers 1.11… | |
| Modificada | Media (6.3) | 1.1% | 💥 PoC | Katacontainers Runtime | 10/6/2020 | 17/6/2026 | Kata Containers doesn't restrict containers from accessing the guest's root filesystem device. Malicious containers can exploit this to gain code execution on the guest and masquerade as the kata-agent. This issue affects Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than… | |
| Modificada | Alta (7.2) | 2.1% | — | Elastic KibanaRedhat Openshift Container Platform | 3/6/2020 | 17/6/2026 | Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana… | |
| Modificada | Media (6) | 2.4% | 💥 PoC | Linuxfoundation CNI Network PluginsRedhat Openshift Container PlatformFedoraproject FedoraRedhat Enterprise Linux | 3/6/2020 | 17/6/2026 | A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to… | |
| Modificada | Alta (8.8) | 0.31% | — | Katacontainers Runtime | 19/5/2020 | 17/6/2026 | Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the host. A malicious guest can overwrite the image file to gain control of all subsequent guest VMs. Since Kata Containers uses the same VM image file with all VMMs, this issue may also affect QEMU and… |