Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
81 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.81% | 💥 PoC | Redhat Ansible Automation ControllerRedhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside | 4/10/2023 | 17/6/2026 | An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise. | |
| Modificada | Media (5.5) | 0.29% | — | Pulpproject Pulp AnsibleRedhat Ansible Automation PlatformRedhat SatelliteRedhat Update Infrastructure | 25/10/2022 | 17/6/2026 | The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only. | |
| Modificada | Media (6.1) | 0.51% | — | Redhat Ansible Automation Platform | 13/9/2022 | 17/6/2026 | Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection | |
| Modificada | Media (6.5) | 0.41% | — | Redhat Ansible Automation PlatformRedhat Openshift Container PlatformFedoraproject Fedora | 1/9/2022 | 17/6/2026 | An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an invalid certificate, resulting in a loss of confidentiality. | |
| Modificada | Alta (8.8) | 0.24% | — | Redhat Ansible Automation Platform Early AccessRedhat Ansible Automation Platform Text-only AdvisoriesRedhat Ansible TowerRedhat Ansible Automation Platform | 25/8/2022 | 17/6/2026 | A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment. | |
| Modificada | Media (6.5) | 0.87% | — | Redhat Ansible Automation Platform | 18/8/2022 | 17/6/2026 | A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser account and also remove the superuser privileges. | |
| Modificada | Media (5.5) | 0.25% | — | Redhat Ansible Automation PlatformRedhat Ansible Galaxy | 18/4/2022 | 17/6/2026 | A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly excluded via the ``build_ignore`` list in "galaxy.yml" include files in the ``.tar.gz`` file. This contains sensitive info, such as the user's Ansible Galaxy API key and… | |
| Modificada | Media (5.5) | 0.39% | — | Redhat Ansible Automation Platform Early AccessRedhat Ansible EngineRedhat OpenstackRedhat Virtualization+5 | 3/3/2022 | 17/6/2026 | A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality. | |
| Modificada | Alta (7.1) | 0.90% | — | Redhat Ansible Automation PlatformRedhat Ansible EngineRedhat Ansible Tower | 22/9/2021 | 17/6/2026 | A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters. This flaw allows… | |
| Modificada | Alta (7.5) | 2.1% | — | Redhat Ansible EngineRedhat Ansible Automation PlatformRedhat Ansible TowerDebian Linux | 29/4/2021 | 17/6/2026 | A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to… | |
| Modificada | Crítica (9.8) | 1.2% | — | Onap Open Network Automation Platform | 19/3/2020 | 17/6/2026 | In ONAP OOM through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services without any authentication. All ONAP Operations Manager (OOM) setups are affected. | |
| Modificada | Crítica (9.8) | 1.2% | — | Onap Open Network Automation Platform | 19/3/2020 | 17/6/2026 | In ONAP DCAE through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services without any authentication. All ONAP Operations Manager (OOM) setups are affected. | |
| Modificada | Crítica (9.8) | 1.2% | — | Onap Open Network Automation Platform | 19/3/2020 | 17/6/2026 | In ONAP Logging through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services without any authentication. All ONAP Operations Manager (OOM) setups are affected. | |
| Modificada | Crítica (9.8) | 1.7% | — | Onap Open Network Automation Platform | 19/3/2020 | 17/6/2026 | In ONAP CLI through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services without any authentication. All ONAP Operations Manager (OOM) setups are affected. | |
| Modificada | Crítica (9.8) | 1.7% | — | Onap Open Network Automation Platform | 19/3/2020 | 17/6/2026 | In ONAP MSB through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services without any authentication. All ONAP Operations Manager (OOM) setups are affected. | |
| Modificada | Crítica (9.8) | 1.7% | — | Onap Open Network Automation Platform | 19/3/2020 | 17/6/2026 | In ONAP SO through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services without any authentication. All ONAP Operations Manager (OOM) setups are affected. | |
| Modificada | Crítica (9.8) | 1.5% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was discovered in ONAP SDNC before Dublin. By executing sla/dgUpload with a crafted filename parameter, an unauthenticated attacker can execute an arbitrary command. All SDC setups that include admportal are affected. | |
| Modificada | Crítica (9.1) | 1.2% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was detected in ONAP APPC through Dublin and SDC through Dublin. By setting a USER_ID parameter in an HTTP header, an attacker may impersonate an arbitrary existing user without any authentication. All APPC and SDC setups are affected. | |
| Modificada | Crítica (9.1) | 1.2% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was discovered in ONAP APPC before Dublin. By using an exposed unprotected Jolokia interface, an unauthenticated attacker can read or overwrite an arbitrary file. All APPC setups are affected. | |
| Modificada | Alta (8.8) | 1.3% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsXml with a crafted module parameter, an authenticated user can execute an arbitrary command. All SDC setups that include admportal are affected. | |
| Modificada | Media (6.5) | 0.58% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was discovered in ONAP Portal through Dublin. By executing a call to ONAPPORTAL/portalApi/loggedinUser, an attacker who possesses a user's cookie may retrieve that user's password from the database. All Portal setups are affected. | |
| Modificada | Alta (7.5) | 0.73% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was detected in ONAP Portal through Dublin. By executing a padding oracle attack using the ONAPPORTAL/processSingleSignOn UserId field, an attacker is able to decrypt arbitrary information encrypted with the same symmetric key as UserId. All Portal setups are affected. | |
| Modificada | Crítica (9.8) | 2.1% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was discovered in ONAP VNFSDK through Dublin. By accessing port 8000 of demo-vnfsdk-vnfsdk, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected. | |
| Modificada | Crítica (9.8) | 2.1% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was discovered in ONAP SDC through Dublin. By accessing port 7000 of demo-sdc-sdc-wfd-fe pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected. | |
| Modificada | Crítica (9.8) | 2.1% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was discovered in ONAP SDC through Dublin. By accessing port 7001 of demo-sdc-sdc-wfd-be pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected. |