Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

1570 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RechazadaSin puntuar——Hawtio-operatorAI8/9/202621/9/2026
Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.
AplazadaMedia (5.5)0.53%—Code-projects Student Crud OperationAI8/9/202611/9/2026
A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handler. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has been made public and could be used.
AplazadaBaja (2.1)0.33%—Code-projects Student Crud OperationAI8/9/202628/9/2026
A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edit.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Pendiente de análisisAlta (7.7)0.31%—IBM Observability With Instana AgentAIIBM Instana Agent OperatorAI4/9/202610/9/2026
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an…
Pendiente de análisisCrítica (9.6)0.21%—IBM Observability With Instana AgentAIIBM Instana Agent OperatorAI4/9/20268/9/2026
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace…
Pendiente de análisisCrítica (9.8)0.43%—IBM Operational Decision ManagerAI4/9/202610/9/2026
IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution.
AplazadaCrítica (9.3)3.3%—Qvidium Opera11AI31/8/20261/9/2026
A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be…
Pendiente de análisisAlta (7.7)0.53%—Redhat Advanced Cluster ManagementAIRedhat Multicloud Operators SubscriptionAI20/8/202628/8/2026
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This allows the `GetSecret()` function in the HelmRelease controller to fetch…
Pendiente de análisisCrítica (9.9)0.62%—Multicloud-operators SubscriptionAI20/8/202628/8/2026
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates using its own elevated ServiceAccount…
Pendiente de análisisAlta (8)0.72%—Acm-operator-bundleAI19/8/20268/9/2026
A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote…
Pendiente de análisisAlta (7.7)0.60%—Mce-operator-bundleAI19/8/202629/9/2026
A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to inject and execute arbitrary code during…
Pendiente de análisisCrítica (9.9)0.55%—Search-v2-operatorAI19/8/202627/8/2026
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Requests (CSRs), and manage ManifestWork. This grants excessive…
Pendiente de análisisCrítica (9.1)0.71%—Search-v2-operatorAI19/8/202627/8/2026
A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specifically a Custom Resource (CR) editor, to manipulate Search CR fields such as imageOverride, arguments, and environment variables without proper validation. By exploiting this, an attacker can mount arbitrary secrets into a…
AnalizadaAlta (8.8)0.42%—Oracle Hospitality Opera 5 Property Services18/8/20264/9/2026
Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.28.0-5.6.28.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…
AnalizadaAlta (7.5)0.33%—Oracle Operations Intelligence18/8/202628/8/2026
Vulnerability in the Oracle Operations Intelligence product of Oracle E-Business Suite (component: Daily Business Intelligence). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Operations…
Pendiente de análisisMedia (4.4)0.35%—Submariner-operatorAIRedhat Advanced Cluster Management FOR KubernetesAI18/8/20263/9/2026
A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker…
Pendiente de análisisMedia (5.4)0.39%—Submariner OperatorAI18/8/20263/9/2026
A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectivity, stores the IPsec pre-shared key (PSK) in an unencrypted format. This key, which is critical for securing communication between Kubernetes clusters, can be accessed by unauthorized parties. Such…
Pendiente de análisisMedia (6.5)0.58%—Submariner-operatorAI18/8/202628/9/2026
A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters' endpoint information. Consequently, an…
Pendiente de análisisAlta (8.8)0.16%—Search-v2-operatorAI17/8/202627/8/2026
A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If an attacker gains access to any of the pods running under this service account, they could exploit this to achieve `system:masters`…
Pendiente de análisisCrítica (9.9)0.69%—Multicloud-operators SubscriptionAI17/8/202629/9/2026
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the…
Pendiente de análisisCrítica (9.6)0.47%—Hashicorp Vault Secrets OperatorAI13/8/202628/8/2026
Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a…
Pendiente de análisisAlta (7.7)0.48%—Redhat Advanced Cluster ManagementAIRedhat Multicloud Operators ChannelAI12/8/202627/8/2026
A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets and ConfigMaps within any Channel…
Pendiente de análisisAlta (7.7)0.48%—Multicloud-operators SubscriptionAI12/8/202627/8/2026
A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Namespace field, the user can cause the system to copy sensitive Secret…
Pendiente de análisisMedia (6.4)0.33%—Multicloud-operators ChannelAI12/8/20265/9/2026
A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the system handles sensitive information, known as Secrets, across different parts of the system (namespaces). By exploiting this, an attacker can modify these Secrets in…
Pendiente de análisisMedia (5.5)0.39%—Feast OperatorAI10/8/202619/8/2026
A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by an automated process with elevated privileges, allowing the tenant to steal sensitive credentials. This could lead to a direct escalation of privileges, granting the…