Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2649▼ 259 respecto a la semana anterior
Críticas / altas1356▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
95 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 3.1% | — | Redhat Ansible EngineRedhat CloudformsRedhat OpenstackRedhat Virtualization+2 | 3/7/2018 | 17/6/2026 | Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the… | |
| Modificada | Alta (7.5) | 27% | — | Redhat CloudformsRedhat Enterprise LinuxSprockets Project SprocketsDebian Linux | 26/6/2018 | 17/6/2026 | There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production.… | |
| Modificada | Crítica (9.8) | 4.4% | — | Rubyzip Project RubyzipDebian LinuxRedhat Cloudforms | 26/6/2018 | 17/6/2026 | rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains… | |
| Modificada | Media (6.1) | 2.2% | — | Sinatrarb SinatraRedhat Cloudforms | 31/5/2018 | 17/6/2026 | Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception. | |
| Modificada | Alta (8.8) | 2.5% | — | Redhat Ansible TowerRedhat Cloudforms | 2/5/2018 | 17/6/2026 | Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrary code on the Tower server. | |
| Modificada | Alta (7.2) | 2.0% | — | Redhat Ansible TowerRedhat Cloudforms | 2/5/2018 | 17/6/2026 | Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the… | |
| Modificada | Alta (7.5) | 1.2% | — | Redhat Cloudforms Management Engine | 1/5/2018 | 16/6/2026 | Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secret_token.rb secret. | |
| Modificada | Crítica (9.8) | 27% | — | ParamikoRedhat Ansible EngineRedhat CloudformsRedhat Virtualization+7 | 13/3/2018 | 17/6/2026 | transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by… | |
| Modificada | Alta (8.8) | 13% | — | PostgresqlCanonical Ubuntu LinuxRedhat Cloudforms | 2/3/2018 | 17/6/2026 | A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected. | |
| Modificada | Alta (7.4) | 0.88% | — | Redhat Cloudforms | 28/2/2018 | 17/6/2026 | A flaw was found in the CloudForms account configuration when using VMware. By default, a shared account is used that has privileged access to VMRC (VMWare Remote Console) functions that may not be appropriate for users of CloudForms (and thus this account). An attacker could use this vulnerability to view and make… | |
| Modificada | Alta (7) | 0.48% | — | PostgresqlDebian LinuxCanonical Ubuntu LinuxRedhat Cloudforms | 9/2/2018 | 17/6/2026 | In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in current working directory containing the output of `pg_dumpall -g` under umask which was in effect when the user invoked pg_upgrade, and not under 0077 which is normally used… | |
| Modificada | Alta (8.8) | 1.8% | — | Redhat Cloudforms Management Engine | 11/1/2018 | 17/6/2026 | The check_privileges method in vmdb/app/controllers/application_controller.rb in ManageIQ, as used in Red Hat CloudForms Management Engine (CFME), allows remote authenticated users to bypass authorization and gain privileges by leveraging improper RBAC checking, related to the rbac_user_edit action. | |
| Modificada | Media (6.5) | 1.0% | — | Redhat Cloudforms 3.0 Management Engine | 18/10/2017 | 17/6/2026 | Red Hat CloudForms 3 Management Engine (CFME) allows remote authenticated users to cause a denial of service (resource consumption) via vectors involving calls to the .to_sym rails function and lack of garbage collection of inserted symbols. | |
| Modificada | Alta (8.8) | 87% | — | Supervisord SupervisorFedoraproject FedoraDebian LinuxRedhat Cloudforms | 23/8/2017 | 17/6/2026 | The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups. | |
| Modificada | Alta (8.8) | 2.3% | — | Redhat Cloudforms | 8/6/2017 | 17/6/2026 | ManageIQ in CloudForms before 4.1 allows remote authenticated users to execute arbitrary code. | |
| Modificada | Alta (7.5) | 1.1% | — | Redhat Cloudforms Management Engine | 8/6/2017 | 17/6/2026 | CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate. | |
| Modificada | Media (5.3) | 1.2% | — | Redhat Cloudforms Management Engine | 21/4/2017 | 17/6/2026 | Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext information. | |
| Modificada | Alta (8.8) | 2.3% | — | Redhat Cloudforms Management Engine | 7/10/2016 | 17/6/2026 | Red Hat CloudForms Management Engine 4.1 does not properly handle regular expressions passed to the expression engine via the JSON API and the web-based UI, which allows remote authenticated users to execute arbitrary shell commands by leveraging the ability to view and filter collections. | |
| Modificada | Alta (8.8) | 2.6% | — | Redhat Cloudforms | 26/8/2016 | 17/6/2026 | The web UI in Red Hat CloudForms 4.1 allows remote authenticated users to execute arbitrary code via vectors involving "Lack of field filters." | |
| Modificada | Media (5.1) | 0.34% | — | Redhat Cloudforms Management EngineRedhat Cloudforms | 11/4/2016 | 17/6/2026 | Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend PostgreSQL database, which might allow local users to obtain sensitive data and consequently gain privileges by leveraging access to (1) database exports or (2) log files. | |
| Modificada | Media (6.5) | 1.4% | — | Redhat Cloudforms 3.1 Management Engine | 16/1/2015 | 17/6/2026 | SQL injection vulnerability in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 allows remote authenticated users to execute arbitrary SQL commands via a crafted REST API request to an SQL filter. | |
| Modificada | Alta (10) | 2.9% | — | Redhat Cloudforms 3.1 Management Engine | 16/1/2015 | 17/6/2026 | The customization template in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 uses a default password for the root account when a password is not specified for a new image, which allows remote attackers to gain privileges. | |
| Modificada | Media (5) | 1.6% | — | Redhat Cloudforms 3.0 Management Engine | 27/10/2014 | 17/6/2026 | The (1) get and (2) log methods in the AgentController in Red Hat CloudForms 3.0 Management Engine (CFME) 5.x allow remote attackers to insert arbitrary text into log files via unspecified vectors. | |
| Modificada | Media (6.5) | 1.3% | — | Redhat Cloudforms 3.0.1 Management EngineRedhat Cloudforms 3.0.2 Management EngineRedhat Cloudforms 3.0.3 Management EngineRedhat Cloudforms 3.0.4 Management Engine+2 | 6/10/2014 | 17/6/2026 | vmdb/app/controllers/application_controller/performance.rb in Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to gain privileges via unspecified vectors, related to an "insecure send method." | |
| Modificada | Media (4) | 1.2% | — | Redhat Cloudforms 3.0.1 Management EngineRedhat Cloudforms 3.0.2 Management EngineRedhat Cloudforms 3.0.3 Management EngineRedhat Cloudforms 3.0.4 Management Engine+2 | 6/10/2014 | 17/6/2026 | Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to access sensitive controllers and actions via a direct HTTP or HTTPS request. |