Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

601 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.68%—Linuxfoundation Auth Backend26/11/202117/6/2026
Backstage is an open platform for building developer portals. In affected versions the auth-backend plugin allows a malicious actor to trick another user into visiting a vulnerable URL that executes an XSS attack. This attack can potentially allow the attacker to exfiltrate access tokens or other secrets from the…
ModificadaAlta (7.5)1.1%—Linuxfoundation Fabric18/11/202117/6/2026
A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.0.1, v2.3.0. It can easily break down as many orderers as the attacker wants. This bug can be leveraged by constructing a message whose header is invalid to the interface Order. This bug has been admitted and fixed by the developers of Fabric.
ModificadaAlta (7.5)1.3%—Linuxfoundation Fabric18/11/202117/6/2026
A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.1.0. This bug can be leveraged by constructing a message whose payload is nil and sending this message with the method 'forwardToLeader'. This bug has been admitted and fixed by the developers of Fabric. If leveraged, any leader node will crash.
ModificadaMedia (5)2.2%—Linuxfoundation Open Container Initiative Distribution SpecificationLinuxfoundation Open Container Initiative Image Format SpecificationFedoraproject Fedora17/11/202117/6/2026
The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specification version 1.0.0 and prior, the Content-Type header alone was used to determine the type of document during push and pull operations. Documents that contain both…
ModificadaAlta (8.7)1.5%—Linuxfoundation THE Update Framework19/10/202117/6/2026
python-tuf is a Python reference implementation of The Update Framework (TUF). In both clients (`tuf/client` and `tuf/ngclient`), there is a path traversal vulnerability that in the worst case can overwrite files ending in `.json` anywhere on the client system on a call to `get_one_valid_targetinfo()`. It occurs…
ModificadaMedia (4.9)1.3%—Linuxfoundation Backstage18/10/202117/6/2026
Backstage is an open platform for building developer portals. In affected versions A malicious actor could read sensitive files from the environment where Scaffolder Tasks are run. The attack is executed by crafting a custom Scaffolder template with a `github:publish:pull-request` action and a particular source path.…
ModificadaAlta (7.8)0.52%—Linuxfoundation ContainerdFedoraproject FedoraDebian Linux4/10/202117/6/2026
containerd is an open source container runtime with an emphasis on simplicity, robustness and portability. A bug was found in containerd where container root directories and some plugins had insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory contents and execute…
ModificadaCrítica (9.8)1.3%—Linuxfoundation Tremor17/9/202117/6/2026
Tremor is an event processing system for unstructured data. A vulnerability exists between versions 0.7.2 and 0.11.6. This vulnerability is a memory safety Issue when using `patch` or `merge` on `state` and assign the result back to `state`. In this case, affected versions of Tremor and the tremor-script crate…
ModificadaMedia (5.3)1.4%—Linuxfoundation Cortex3/8/202117/6/2026
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some…
ModificadaMedia (6.3)1.6%—Linuxfoundation ContainerdFedoraproject Fedora19/7/202117/6/2026
containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expected owner…
ModificadaAlta (7.5)2.1%—Linuxfoundation Grpc Swift9/7/202117/6/2026
LengthPrefixedMessageReader in gRPC Swift 1.1.0 and earlier allocates buffers of arbitrary length, which allows remote attackers to cause uncontrolled resource consumption and deny service.
ModificadaAlta (7.5)2.1%—Linuxfoundation Grpc Swift9/7/202117/6/2026
HTTP2ToRawGRPCServerCodec in gRPC Swift 1.1.1 and earlier allows remote attackers to deny service via the delivery of many small messages within a single HTTP/2 frame, leading to Uncontrolled Recursion and stack consumption.
ModificadaAlta (7.5)2.1%—Linuxfoundation Grpc Swift9/7/202117/6/2026
Mismanaged state in GRPCWebToHTTP2ServerCodec.swift in gRPC Swift 1.1.0 and 1.1.1 allows remote attackers to deny service by sending malformed requests.
ModificadaMedia (6.5)1.3%—Linuxfoundation Backstage3/6/202117/6/2026
Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In `@backstage/techdocs-common` versions prior to 0.6.3, a malicious actor could read sensitive files from the environment where TechDocs documentation is built and published by…
ModificadaAlta (7.3)1.2%—Linuxfoundation @backstage/plugin-techdocs3/6/202117/6/2026
Backstage is an open platform for building developer portals. In versions of Backstage's Techdocs Plugin (`@backstage/plugin-techdocs`) prior to 0.9.5, a malicious internal actor can potentially upload documentation content with malicious scripts by embedding the script within an `object` element. This may give access…
ModificadaAlta (8.1)1.3%—Linuxfoundation @backstage/techdocs-common3/6/202117/6/2026
Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In versions of `@backstage/tehdocs-common` prior to 0.6.4, a malicious internal actor is able to upload documentation content with malicious scripts. These scripts would normally…
ModificadaCrítica (9.8)1.7%—Linuxfoundation DEX28/5/202117/6/2026
A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an attacker to bypass SAML authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. This flaw affects dex…
ModificadaAlta (8.5)6.6%—Linuxfoundation RuncFedoraproject Fedora27/5/202117/6/2026
runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on a race condition.
ModificadaMedia (5.5)0.37%—Linuxfoundation Cortex30/4/202117/6/2026
The Alertmanager in CNCF Cortex before 1.8.1 has a local file disclosure vulnerability when -experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be used as an attack vector to send any file content via a webhook. The alertmanager templates can be used as an attack vector to send any…
ModificadaAlta (7.2)2.1%—Linuxfoundation CephRedhat Ceph StorageFedoraproject FedoraDebian Linux15/4/202117/6/2026
An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_id can exploit the ability of any user to request a global_id previously associated with another…
ModificadaMedia (5.5)0.34%—Linuxfoundation UmociSylabs Singularity6/4/202117/6/2026
Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that causes symlink traversal when "umoci unpack" or "umoci raw unpack" is used.
ModificadaAlta (7.2)1.5%—Linuxfoundation Container Network Interface26/3/202117/6/2026
An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'type' field in the network configuration, it is possible to use special elements such as "../" separators to reference binaries elsewhere on the system. This flaw allows an…
ModificadaAlta (7.5)1.4%—Linuxfoundation Nats-serverNats JWT Library16/3/202117/6/2026
NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled.
ModificadaMedia (6.3)2.0%—Linuxfoundation ContainerdFedoraproject Fedora10/3/202117/6/2026
In containerd (an industry-standard container runtime) before versions 1.3.10 and 1.4.4, containers launched through containerd's CRI implementation (through Kubernetes, crictl, or any other pod/container client that uses the containerd CRI service) that share the same image may receive incorrect environment…
ModificadaMedia (6.5)1.7%—Linuxfoundation Besu9/3/202117/6/2026
Hyperledger Besu is an open-source, MainNet compatible, Ethereum client written in Java. In Besu before version 1.5.1 there is a denial-of-service vulnerability involving the HTTP JSON-RPC API service. If username and password authentication is enabled for the HTTP JSON-RPC API service, then prior to making any…
Orbitaley — Vulnerabilidades