Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
–

11.335 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.8)0.93%—Genshi Template EngineAI26/6/202626/6/2026
Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions.
AnalizadaBaja (3.8)0.13%—Redhat Openshift VirtualizationKubevirt26/6/20266/7/2026
A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely until a newline character is received, with no length limit or read deadline. A user with access to a VM guest that has the downward metrics…
AnalizadaMedia (6.4)0.24%—KubevirtRedhat Openshift Virtualization26/6/20266/7/2026
A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-forward request to a VirtualMachineInstance (VMI), virt-api reads the target IP from vmi.Status.Interfaces[0].IP and passes it directly to net.Dial() without validation. For VMIs using non-masquerade…
AnalizadaMedia (4.2)0.14%—KubevirtRedhat Openshift Virtualization26/6/20266/7/2026
A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data to a launcher-rooted path using os.WriteFile and os.Chown without symlink protection. A user with access to the virt-launcher container can plant a symlink at the cache file path, causing virt-handler to…
AplazadaMedia (6.5)0.33%—Wpexperts License Manager FOR WoocommerceAI25/6/202629/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.
AnalizadaMedia (6.5)0.13%—KubevirtRedhat Openshift Virtualization24/6/20266/7/2026
A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity (namespace/name) solely from the request body without validating it against the connection's origin. Each virt-launcher pod connects through a per-VMI pipe socket, but no…
ModificadaAlta (7.3)0.27%—KubevirtRedhat Openshift Virtualization24/6/202621/9/2026
A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream operations resolve the path via /proc/self/fd/N using link-following syscalls. When the leaf is a symlink, the kernel dereferences it,…
Pendiente de análisisBaja (1.1)0.29%—Thinkst CanarytokensAI24/6/202625/6/2026
Stored Cross-Site Scripting in the exposed AWS API key store of Thinkst Applied Research Canarytokens. Anonymous exploitation requires knowledge of a random identifier. This issue affects Canarytokens: from Docker tag sha-4116b92cb before sha-f5aa5c4e, from Git commit 4116b92cb before f5aa5c4e.
AnalizadaMedia (5.3)0.22%—Openstack Swift23/6/202629/6/2026
In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redirect container update…
AplazadaAlta (7.5)0.50%—Openlink Virtuoso-opensourceAI23/6/202623/6/2026
An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
AplazadaAlta (7.5)0.50%—Openlink Virtuoso-opensourceAI23/6/202623/6/2026
An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
AplazadaAlta (7.5)0.35%—Openlink Virtuoso-opensourceAI23/6/202625/6/2026
An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
AplazadaAlta (7.5)0.68%—Openlink Virtuoso-opensourceAI23/6/202615/7/2026
An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
AplazadaAlta (7.5)0.50%—Openlink Virtuoso-opensourceAI23/6/202625/6/2026
An issue in the sqlo_key_part_best component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
AplazadaAlta (7.5)0.68%—Openlink Virtuoso-opensourceAI23/6/202615/7/2026
An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
AplazadaAlta (7.5)0.42%—Openlink Virtuoso-opensourceAI23/6/20266/10/2026
Un problema en el componente sqlo_untry de openlink virtuoso-opensource v7.2.11 permite a los atacantes causar una denegación de servicio (DoS) a través de sentencias SQL manipuladas.
AplazadaAlta (7.5)0.58%—Openlink Virtuoso-opensourceAI23/6/20266/10/2026
Un problema en el componente time_t_to_dt de openlink virtuoso-opensource v7.2.11 permite a los atacantes causar una denegación de servicio (DoS) mediante sentencias SQL especialmente diseñadas.
AplazadaAlta (7.5)0.42%—Openlink Virtuoso-opensourceAI23/6/20266/10/2026
Un problema en el componente t_set_push de openlink virtuoso-opensource v7.2.11 permite a los atacantes causar una denegación de servicio (DoS) a través de sentencias SQL manipuladas.
AplazadaAlta (7.5)0.42%—Openlink Virtuoso-opensourceAI23/6/20266/10/2026
Un problema en el componente sslr_qst_get de openlink virtuoso-opensource v7.2.11 permite a los atacantes causar una denegación de servicio (DoS) a través de sentencias SQL manipuladas.
AplazadaAlta (7.5)0.58%—Openlink Virtuoso-opensourceAI23/6/20266/10/2026
Un problema en el componente st_compare de openlink virtuoso-opensource v7.2.11 permite a los atacantes causar una denegación de servicio (DoS) mediante sentencias SQL manipuladas.
AnalizadaMedia (6.8)0.38%—Redhat Cluster Logging OperatorRedhat Logging Subsystem FOR RED HAT Openshift23/6/20268/7/2026
A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output destinations without verifying that the ClusterLogForwarder creator has permission to use those credentials, allowing a delegated editor to exfiltrate SA tokens and…
AnalizadaAlta (8.7)0.77%—TraefikGolang GORedhat Openshift AI23/6/202626/9/2026
Traefik anterior a 2.10.5 y 3.0.0-beta4 está afectado por una vulnerabilidad de denegación de servicio en el manejo de solicitudes HTTP/2 heredada de la implementación de HTTP/2 de la biblioteca estándar de Go (CVE-2023-44487 / CVE-2023-39325, la técnica 'Rapid Reset'). Un atacante remoto puede crear y cancelar…
ModificadaMedia (6.1)0.13%—Openbsd OpensshRedhat Enterprise Linux23/6/20267/10/2026
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the…
ModificadaBaja (3.7)0.65%—Openbsd OpensshRedhat Hardened ImagesRedhat Enterprise Linux23/6/202624/9/2026
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving…
ModificadaMedia (6.5)0.60%—Openbsd OpensshRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux23/6/20267/10/2026
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters.…