Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

601 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.7%—Linuxfoundation Nats-server7/3/202117/6/2026
This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the server using configs that represent a service export/import cycles. Disclaimer from the maintainers: Running a NATS service which is exposed to untrusted users presents a heightened risk. Any remote…
ModificadaMedia (5.3)0.72%—Linuxfoundation Harbor2/2/202117/6/2026
In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path.
ModificadaCrítica (9.6)0.99%—Linuxfoundation DEX28/12/202017/6/2026
Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a critical set of vulnerabilities which impacts users leveraging the SAML connector. The vulnerabilities enables potential signature bypass due to issues with XML encoding in the underlying Go library. The vulnerabilities…
ModificadaAlta (7.5)1.2%—Linuxfoundation Indy-node24/12/202017/6/2026
Hyperledger Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In Hyperledger Indy before version 1.12.4, there is lack of signature verification on a specific transaction which enables an attacker to make certain unauthorized alterations to the ledger. Updating a DID…
ModificadaMedia (5.2)0.95%—Linuxfoundation Osquery16/12/202017/6/2026
osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. In osquery before version 4.6.0, by using sqlite's ATTACH verb, someone with administrative access to osquery can cause reads and writes to arbitrary sqlite databases on disk. This _does_ allow arbitrary files to be…
ModificadaAlta (8.8)1.5%—Linuxfoundation Spinnaker11/12/202017/6/2026
Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of SpEL expressions that allows an attacker to read and write arbitrary files within the orca container via authenticated HTTP…
ModificadaMedia (5.2)3.2%💥 PoCLinuxfoundation ContainerdFedoraproject FedoraDebian Linux1/12/202017/6/2026
containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd before versions 1.3.9 and 1.4.3, the containerd-shim API is improperly exposed to host network containers. Access controls for the shim’s API socket verified that the connecting process had an…
ModificadaCrítica (9.8)2.1%—Linuxfoundation Nats-serverFedoraproject Fedora6/11/202017/6/2026
The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled.
ModificadaAlta (7.5)2.2%—Linuxfoundation Nats-serverFedoraproject Fedora6/11/202017/6/2026
The JWT library in NATS nats-server before 2.1.9 allows a denial of service (a nil dereference in Go code).
ModificadaMedia (6.1)2.3%—Linuxfoundation ContainerdCanonical Ubuntu LinuxDebian Linux16/10/202017/6/2026
In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Schema 2 format includes a URL for the location of a specific image layer (otherwise known as a “foreign layer”), the…
ModificadaAlta (7.5)1.5%—Linuxfoundation Nats.denoLinuxfoundation Nats.jsLinuxfoundation Nats.ws30/9/202017/6/2026
NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server.
ModificadaMedia (4.3)1.3%—Linuxfoundation Harbor30/9/202017/6/2026
Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor.
ModificadaAlta (8.2)0.67%—Linuxfoundation THE Update Framework9/9/202017/6/2026
Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously downloaded root metadata file which failed verification at download time. This allows an attacker who is able to serve multiple new versions of root metadata (i.e. by a person-in-the-middle attack)…
ModificadaAlta (7.5)1.7%—Linuxfoundation Acrn31/8/202017/6/2026
Missing access control restrictions in the Hypervisor component of the ACRN Project (v2.0 and v1.6.1) allow a malicious entity, with root access in the Service VM userspace, to abuse the PCIe assign/de-assign Hypercalls via crafted ioctls and payloads. This attack results in a corrupt state and Denial of Service (DoS)…
ModificadaMedia (4.3)1.3%—Linuxfoundation Harbor15/7/202017/6/2026
Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.
ModificadaAlta (8.2)0.59%—Linuxfoundation Osquery10/7/202017/6/2026
osquery before version 4.4.0 enables a privilege escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated privileges this enables local escalation.…
ModificadaMedia (6.5)1.6%—Redhat Ceph StorageRedhat OpenstackFedoraproject FedoraOpensuse Leap+226/6/202017/6/2026
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made.…
ModificadaAlta (8)0.65%—Linuxfoundation Ceph22/6/202017/6/2026
An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr daemons do not properly restrict access, resulting in gaining access to unauthorized resources. This flaw allows an authenticated client to modify the configuration and possibly conduct further…
ModificadaMedia (5.5)0.43%—Linuxfoundation Jaeger19/6/202017/6/2026
Sensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when the Kafka data store is used. This flaw allows an attacker with access to the container's log file to discover the Kafka credentials.
ModificadaAlta (7.5)2.1%—Linuxfoundation Indy-node11/6/202017/6/2026
In Indy Node 1.12.2, there is an Uncontrolled Resource Consumption vulnerability. Indy Node has a bug in TAA handling code. The current primary can be crashed with a malformed transaction from a client, which leads to a view change. Repeated rapid view changes have the potential of bringing down the network. This is…
ModificadaMedia (6)2.4%💥 PoCLinuxfoundation CNI Network PluginsRedhat Openshift Container PlatformFedoraproject FedoraRedhat Enterprise Linux3/6/202017/6/2026
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to…
ModificadaMedia (5.3)1.4%—Linuxfoundation Free Range Routing13/5/202017/6/2026
An issue was discovered in FRRouting FRR (aka Free Range Routing) through 7.3.1. When using the split-config feature, the init script creates an empty config file with world-readable default permissions, leading to a possible information leak via tools/frr.in and tools/frrcommon.sh.in. NOTE: some parties consider this…
ModificadaMedia (6.1)1.6%—Linuxfoundation CephRedhat Ceph StorageRedhat Openshift Container PlatformFedoraproject Fedora+223/4/202017/6/2026
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.
ModificadaAlta (7.5)2.7%—Linuxfoundation CephCanonical Ubuntu Linux22/4/202017/6/2026
An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception.
ModificadaAlta (7.5)2.1%—Linuxfoundation CephRedhat Ceph Storage21/4/202017/6/2026
A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated attacker could use this flaw to cause information disclosure on the host machine running the Ceph dashboard.