Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

119 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.68%—Helm3/3/202417/6/2026
An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flag is used. This is a security concern in some use cases, such as a --dry-run call by a CI/CD tool. NOTE: the vendor's position is that this behavior was introduced intentionally,…
AnalizadaAlta (7.5)0.93%—Helm21/2/202417/6/2026
Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content. When either an `index.yaml` file or a plugins `plugin.yaml` file were missing all metadata a panic would occur in Helm. In…
AnalizadaMedia (6.4)0.57%—Helm15/2/202417/6/2026
Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. When either the Helm client or SDK is used to save a chart whose name within the `Chart.yaml` file includes a relative path change, the chart would be saved outside its expected directory based on the changes in the…
ModificadaAlta (7.5)0.73%—Apollographql Apollo RouterApollographql Apollo Helms-charts Router18/10/202317/6/2026
The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when a multi-part response is sent. When users send…
ModificadaMedia (4.3)0.33%—Helmholz Myrex24Helmholz Myrex24.virtualMbconnectline Mbconnect24Mbconnectline Mymbconnect2416/10/202317/6/2026
In Red Lion Europe mbCONNECT24 and mymbCONNECT24 and Helmholz myREX24 and myREX24.virtual up to and including 2.14.2 an improperly implemented access validation allows an authenticated, low privileged attacker to gain read access to limited, non-critical device information in his account he should not have access to.
ModificadaMedia (5.4)0.43%—Helmholz REX 250 FirmwareHelmholz REX 200 FirmwareRedlion Mbnet.rokey RKH 210 FirmwareRedlion Mbnet.rokey RKH 216 Firmware+1317/8/202317/6/2026
A vulnerability in Red Lion Europe mbNET/mbNET.rokey and Helmholz REX 200 and REX 250 devices with firmware lower 7.3.2 allows an authenticated remote attacker with high privileges to inject malicious HTML or JavaScript code (XSS).
ModificadaMedia (4.3)0.77%—Helm8/2/202317/6/2026
Helm is a tool that streamlines installing and managing Kubernetes applications.`getHostByName` is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP address the function performs a DNS lookup. The DNS lookup happens when…
ModificadaAlta (7.2)0.82%—Helmet Store Showroom Site Project Helmet Store Showroom Site13/1/202317/6/2026
Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_helmet.
ModificadaAlta (7.2)0.82%—Helmet Store Showroom Site Project Helmet Store Showroom Site13/1/202317/6/2026
Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category.
ModificadaAlta (7.2)0.82%—Helmet Store Showroom Site Project Helmet Store Showroom Site13/1/202317/6/2026
Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_brand.
ModificadaAlta (7.2)0.73%—Helmet Store Showroom Site Project Helmet Store Showroom Site12/1/202317/6/2026
Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /hss/classes/Users.php?f=delete.
ModificadaAlta (7.5)0.86%—Helm15/12/202217/6/2026
Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the_chartutil_ package that can cause a segmentation violation. The _chartutil_ package contains a parser that loads a JSON Schema validation file. For example, the Helm client…
ModificadaAlta (7.5)0.86%—Helm15/12/202217/6/2026
Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the _repo_package. The _repo_ package contains a handler that processes the index file of a repository. For example, the Helm client adds references to chart repositories where…
ModificadaAlta (7.5)0.78%—Helm15/12/202217/6/2026
Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption, resulting in Denial of Service. Input to functions in the _strvals_ package can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that…
ModificadaCrítica (9.8)1.1%—Helmet Store Showroom Project Helmet Store Showroom14/12/202217/6/2026
Helmet Store Showroom v1.0 vulnerable to unauthenticated SQL Injection.
ModificadaCrítica (9.8)4.4%—Helmet Store Showroom Site Project Helmet Store Showroom Site14/12/202217/6/2026
There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access.
ModificadaAlta (7.2)0.81%—Helmet Store Showroom Site Project Helmet Store Showroom Site14/12/202217/6/2026
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/classes/Master.php?f=delete_product.
ModificadaAlta (7.2)0.81%—Helmet Store Showroom Site Project Helmet Store Showroom Site14/12/202217/6/2026
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/brands/manage_brand.php?id=.
ModificadaAlta (7.2)0.81%—Helmet Store Showroom Site Project Helmet Store Showroom Site14/12/202217/6/2026
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=client/manage_client&id=.
ModificadaAlta (7.2)0.73%—Helmet Store Showroom Site Project Helmet Store Showroom Site14/12/202217/6/2026
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=user/manage_user&id=.
ModificadaAlta (7.2)0.73%—Helmet Store Showroom Site Project Helmet Store Showroom Site14/12/202217/6/2026
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/categories/manage_category.php?id=.
ModificadaAlta (7.2)0.73%—Helmet Store Showroom Site Project Helmet Store Showroom Site14/12/202217/6/2026
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/categories/view_category.php?id=.
ModificadaAlta (7.2)0.73%—Helmet Store Showroom Site Project Helmet Store Showroom Site14/12/202217/6/2026
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=products/manage_product&id=.
ModificadaAlta (7.2)0.73%—Helmet Store Showroom Site Project Helmet Store Showroom Site14/12/202217/6/2026
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=products/view_product&id=.
ModificadaAlta (7.2)0.73%—Helmet Store Showroom Site Project Helmet Store Showroom Site14/12/202217/6/2026
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=categories&c=.