Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

601 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)1.6%—Redhat Ceph StorageRedhat OpenshiftRedhat OpenstackLinuxfoundation Ceph+113/4/202017/6/2026
A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a…
ModificadaAlta (7.2)2.1%—Linuxfoundation HarborPivotal Vmware Harbor Registry20/3/202017/6/2026
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform.
ModificadaMedia (4.9)1.4%—Linuxfoundation HarborPivotal Vmware Harbor Registry20/3/202017/6/2026
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.
ModificadaAlta (8.8)1.0%—Linuxfoundation HarborPivotal Vmware Harbor Registry20/3/202017/6/2026
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform.
ModificadaAlta (8.8)1.6%—Linuxfoundation HarborPivotal Vmware Harbor Registry20/3/202017/6/2026
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry for the Pivotal Platform.
ModificadaCrítica (9.1)1.6%—Linuxfoundation Osquery13/3/202017/6/2026
Incorrect validation of the TLS SNI hostname in osquery versions after 2.9.0 and before 4.2.0 could allow an attacker to MITM osquery traffic in the absence of a configured root chain of trust.
ModificadaAlta (8.6)2.0%—Linuxfoundation Dojox10/3/202017/6/2026
In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript…
ModificadaAlta (7.5)4.0%—Linuxfoundation DojoDebian LinuxOracle Communications Application Session ControllerOracle Communications Policy Management+610/3/202017/6/2026
In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript…
ModificadaAlta (7.5)1.7%—Linuxfoundation Open Network Operating System20/2/202017/6/2026
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the Ethernet VPN application (org.onosproject.evpnopenflow), the host event listener does not handle the following event types: HOST_MOVED, HOST_UPDATED. In combination with other applications, this could lead to the absence of intended code…
ModificadaAlta (7.5)1.7%—Linuxfoundation Open Network Operating System20/2/202017/6/2026
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the virtual tenant network application (org.onosproject.vtn), the host event listener does not handle the following event types: HOST_MOVED. In combination with other applications, this could lead to the absence of intended code execution.
ModificadaAlta (7.5)2.0%—Linuxfoundation Open Network Operating System20/2/202017/6/2026
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the access control application (org.onosproject.acl), the host event listener does not handle the following event types: HOST_REMOVED. In combination with other applications, this could lead to the absence of intended code execution.
ModificadaAlta (7.5)1.7%—Linuxfoundation Open Network Operating System20/2/202017/6/2026
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the mobility application (org.onosproject.mobility), the host event listener does not handle the following event types: HOST_ADDED, HOST_REMOVED, HOST_UPDATED. In combination with other applications, this could lead to the absence of intended…
ModificadaAlta (7.5)1.7%—Linuxfoundation Open Network Operating System20/2/202017/6/2026
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the virtual broadband network gateway application (org.onosproject.virtualbng), the host event listener does not handle the following event types: HOST_MOVED, HOST_REMOVED, HOST_UPDATED. In combination with other applications, this could lead to…
ModificadaAlta (7.5)1.7%—Linuxfoundation Open Network Operating System20/2/202017/6/2026
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the P4 tutorial application (org.onosproject.p4tutorial), the host event listener does not handle the following event types: HOST_MOVED, HOST_REMOVED, HOST_UPDATED. In combination with other applications, this could lead to the absence of…
ModificadaMedia (6.1)1.8%—Linuxfoundation DojoxDebian Linux13/2/202017/6/2026
dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them.
ModificadaAlta (7)0.43%—Linuxfoundation RuncDebian LinuxOpensuse LeapCanonical Ubuntu Linux+112/2/202017/6/2026
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due…
ModificadaCrítica (9.8)0.99%—Linuxfoundation THE Update Framework5/2/202017/6/2026
TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.
ModificadaMedia (5.3)1.8%—Linuxfoundation THE Update Framework14/1/202017/6/2026
TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption.
ModificadaMedia (4.3)1.0%—Linuxfoundation Harbor3/12/201917/6/2026
A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the "search" functionality.
ModificadaMedia (5.5)0.43%—Linuxfoundation Foomatic-filtersDebian LinuxFedoraproject Fedora19/11/201916/6/2026
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running…
ModificadaMedia (5.5)0.40%—Linuxfoundation Foomatic-filtersDebian Linux19/11/201916/6/2026
foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running…
ModificadaAlta (7.5)1.7%—Linuxfoundation HarborVmware Cloud FoundationVmware Harbor Container Registry18/10/201917/6/2026
Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or pull access permissions to a project they don't have access or control for. The Harbor API did not enforce the proper project permissions…
ModificadaAlta (7.5)4.4%—Linuxfoundation RuncDockerFedoraproject FedoraOpensuse Leap+625/9/201917/6/2026
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.
ModificadaMedia (6.5)22%💥 ExploitLinuxfoundation Harbor8/9/201917/6/2026
core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use…
ModificadaAlta (7.5)1.8%—Linuxfoundation Nats-server29/7/201917/6/2026
An integer overflow in NATS Server before 2.0.2 allows a remote attacker to crash the server by sending a crafted request. If authentication is enabled, then the remote attacker must have first authenticated.
Orbitaley — Vulnerabilidades