Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
601 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.6% | — | Redhat Ceph StorageRedhat OpenshiftRedhat OpenstackLinuxfoundation Ceph+1 | 13/4/2020 | 17/6/2026 | A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a… | |
| Modificada | Alta (7.2) | 2.1% | — | Linuxfoundation HarborPivotal Vmware Harbor Registry | 20/3/2020 | 17/6/2026 | Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform. | |
| Modificada | Media (4.9) | 1.4% | — | Linuxfoundation HarborPivotal Vmware Harbor Registry | 20/3/2020 | 17/6/2026 | Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform. | |
| Modificada | Alta (8.8) | 1.0% | — | Linuxfoundation HarborPivotal Vmware Harbor Registry | 20/3/2020 | 17/6/2026 | Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform. | |
| Modificada | Alta (8.8) | 1.6% | — | Linuxfoundation HarborPivotal Vmware Harbor Registry | 20/3/2020 | 17/6/2026 | Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry for the Pivotal Platform. | |
| Modificada | Crítica (9.1) | 1.6% | — | Linuxfoundation Osquery | 13/3/2020 | 17/6/2026 | Incorrect validation of the TLS SNI hostname in osquery versions after 2.9.0 and before 4.2.0 could allow an attacker to MITM osquery traffic in the absence of a configured root chain of trust. | |
| Modificada | Alta (8.6) | 2.0% | — | Linuxfoundation Dojox | 10/3/2020 | 17/6/2026 | In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript… | |
| Modificada | Alta (7.5) | 4.0% | — | Linuxfoundation DojoDebian LinuxOracle Communications Application Session ControllerOracle Communications Policy Management+6 | 10/3/2020 | 17/6/2026 | In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript… | |
| Modificada | Alta (7.5) | 1.7% | — | Linuxfoundation Open Network Operating System | 20/2/2020 | 17/6/2026 | An issue was discovered in Open Network Operating System (ONOS) 1.14. In the Ethernet VPN application (org.onosproject.evpnopenflow), the host event listener does not handle the following event types: HOST_MOVED, HOST_UPDATED. In combination with other applications, this could lead to the absence of intended code… | |
| Modificada | Alta (7.5) | 1.7% | — | Linuxfoundation Open Network Operating System | 20/2/2020 | 17/6/2026 | An issue was discovered in Open Network Operating System (ONOS) 1.14. In the virtual tenant network application (org.onosproject.vtn), the host event listener does not handle the following event types: HOST_MOVED. In combination with other applications, this could lead to the absence of intended code execution. | |
| Modificada | Alta (7.5) | 2.0% | — | Linuxfoundation Open Network Operating System | 20/2/2020 | 17/6/2026 | An issue was discovered in Open Network Operating System (ONOS) 1.14. In the access control application (org.onosproject.acl), the host event listener does not handle the following event types: HOST_REMOVED. In combination with other applications, this could lead to the absence of intended code execution. | |
| Modificada | Alta (7.5) | 1.7% | — | Linuxfoundation Open Network Operating System | 20/2/2020 | 17/6/2026 | An issue was discovered in Open Network Operating System (ONOS) 1.14. In the mobility application (org.onosproject.mobility), the host event listener does not handle the following event types: HOST_ADDED, HOST_REMOVED, HOST_UPDATED. In combination with other applications, this could lead to the absence of intended… | |
| Modificada | Alta (7.5) | 1.7% | — | Linuxfoundation Open Network Operating System | 20/2/2020 | 17/6/2026 | An issue was discovered in Open Network Operating System (ONOS) 1.14. In the virtual broadband network gateway application (org.onosproject.virtualbng), the host event listener does not handle the following event types: HOST_MOVED, HOST_REMOVED, HOST_UPDATED. In combination with other applications, this could lead to… | |
| Modificada | Alta (7.5) | 1.7% | — | Linuxfoundation Open Network Operating System | 20/2/2020 | 17/6/2026 | An issue was discovered in Open Network Operating System (ONOS) 1.14. In the P4 tutorial application (org.onosproject.p4tutorial), the host event listener does not handle the following event types: HOST_MOVED, HOST_REMOVED, HOST_UPDATED. In combination with other applications, this could lead to the absence of… | |
| Modificada | Media (6.1) | 1.8% | — | Linuxfoundation DojoxDebian Linux | 13/2/2020 | 17/6/2026 | dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them. | |
| Modificada | Alta (7) | 0.43% | — | Linuxfoundation RuncDebian LinuxOpensuse LeapCanonical Ubuntu Linux+1 | 12/2/2020 | 17/6/2026 | runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due… | |
| Modificada | Crítica (9.8) | 0.99% | — | Linuxfoundation THE Update Framework | 5/2/2020 | 17/6/2026 | TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature. | |
| Modificada | Media (5.3) | 1.8% | — | Linuxfoundation THE Update Framework | 14/1/2020 | 17/6/2026 | TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption. | |
| Modificada | Media (4.3) | 1.0% | — | Linuxfoundation Harbor | 3/12/2019 | 17/6/2026 | A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the "search" functionality. | |
| Modificada | Media (5.5) | 0.43% | — | Linuxfoundation Foomatic-filtersDebian LinuxFedoraproject Fedora | 19/11/2019 | 16/6/2026 | foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running… | |
| Modificada | Media (5.5) | 0.40% | — | Linuxfoundation Foomatic-filtersDebian Linux | 19/11/2019 | 16/6/2026 | foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running… | |
| Modificada | Alta (7.5) | 1.7% | — | Linuxfoundation HarborVmware Cloud FoundationVmware Harbor Container Registry | 18/10/2019 | 17/6/2026 | Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or pull access permissions to a project they don't have access or control for. The Harbor API did not enforce the proper project permissions… | |
| Modificada | Alta (7.5) | 4.4% | — | Linuxfoundation RuncDockerFedoraproject FedoraOpensuse Leap+6 | 25/9/2019 | 17/6/2026 | runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory. | |
| Modificada | Media (6.5) | 22% | 💥 Exploit | Linuxfoundation Harbor | 8/9/2019 | 17/6/2026 | core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use… | |
| Modificada | Alta (7.5) | 1.8% | — | Linuxfoundation Nats-server | 29/7/2019 | 17/6/2026 | An integer overflow in NATS Server before 2.0.2 allows a remote attacker to crash the server by sending a crafted request. If authentication is enabled, then the remote attacker must have first authenticated. |