Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
155 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.49% | — | Apache Flink Kubernetes Operator | 26/5/2026 | 24/7/2026 | Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI is currently not validated so that it points to user-owned files or addresses. This lets a user with CR create permissions read files from the operator… | |
| Aplazada | Media (4.9) | 0.26% | — | External-secrets External Secrets OperatorAI | 11/5/2026 | 17/6/2026 | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Prior to 2.4.1, a user who only has permission to create ExternalSecret resources can cause the operator to create a Secret that Kubernetes will automatically populate with a long-lived… | |
| Aplazada | Media (5.3) | 0.37% | — | External-secrets External Secrets OperatorAI | 11/5/2026 | 17/6/2026 | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Prior to 2.4.0, Namespaced SecretStore resources that used CAProvider with type ConfigMap could resolve CA material from another namespace when caProvider.namespace was set. This bypassed… | |
| Aplazada | Media (5.5) | 0.59% | — | Browseroperator Browser-operator-coreAI | 28/4/2026 | 17/6/2026 | A weakness has been identified in BrowserOperator browser-operator-core up to 0.6.0. Affected is the function startsWith of the file scripts/component_server/server.js. Executing a manipulation of the argument request.url can lead to path traversal. The attack can be launched remotely. The exploit has been made… | |
| Analizada | Alta (7.1) | 0.45% | — | External-secrets External Secrets Operator | 14/4/2026 | 17/6/2026 | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Versions 2.2.0 and below contain a vulnerability in runtime/template/v2/template.go where the v2 template engine removes env and expandenv from Sprig's TxtFuncMap() but leaves the… | |
| Analizada | Media (4.9) | 0.48% | — | Aiven Operator | 9/4/2026 | 17/6/2026 | Aiven Operator allows you to provision and manage Aiven Services from your Kubernetes cluster. From 0.31.0 to before 0.37.0, a developer with create permission on ClickhouseUser CRDs in their own namespace can exfiltrate secrets from any other namespace — production database credentials, API keys, service tokens —… | |
| Aplazada | Media (6.4) | 0.24% | — | Tour Activity Operator Plugin FOR TourcmsAI | 21/3/2026 | 17/6/2026 | The Tour & Activity Operator Plugin for TourCMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' parameter of the tourcms_doc_link shortcode in all versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Analizada | Media (4.9) | 0.35% | — | Suse Rancher Backup AND Restore Operator | 4/3/2026 | 17/6/2026 | A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs. | |
| Modificada | Media (5.9) | 0.19% | — | IBM APP Connect Enterprise Certified Containers OperandsIBM APP Connect Operator | 3/3/2026 | 17/6/2026 | IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.20, and IBM App Connect Enterprise Certified Containers Operands versions CD 12.0.11.2‑r1 through 12.0.12.5‑r1 and 13.0.1.0‑r1 through 13.0.6.1‑r1, and LTS versions 12.0.12‑r1 through 12.0.12‑r20,… | |
| Modificada | Alta (8.1) | 0.42% | — | Linuxfoundation Strimzi Kafka Operator | 21/2/2026 | 15/7/2026 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In versions 0.49.0 through 0.50.0, when using a custom Cluster or Clients CA with a multistage CA chain consisting of multiple CAs, Strimzi incorrectly configures the trusted certificates for mTLS… | |
| Aplazada | Media (4) | 0.11% | — | IBM MQ OperatorAIIBM MQ AdvancedAI | 17/2/2026 | 17/6/2026 | IBM MQ Operator (SC2 v3.2.0–3.8.1, LTS v2.0.0–2.0.29) and IBM‑supplied MQ Advanced container images (across affected SC2, CD, and LTS 9.3.x–9.4.x releases) contain a vulnerability where log messages are not properly neutralized before being written to log files. This flaw could allow an unauthorized user to inject… | |
| Analizada | Media (5.3) | 0.35% | — | Control-plane Flux Operator | 21/1/2026 | 17/6/2026 | The Flux Operator is a Kubernetes CRD controller that manages the lifecycle of CNCF Flux CD and the ControlPlane enterprise distribution. Starting in version 0.36.0 and prior to version 0.40.0, a privilege escalation vulnerability exists in the Flux Operator Web UI authentication code that allows an attacker to bypass… | |
| Modificada | Crítica (9.3) | 0.19% | — | External-secrets External Secrets Operator | 21/1/2026 | 15/7/2026 | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.20.2 and prior to version 1.2.0, the `getSecretKey` template function, while introduced for senhasegura Devops Secrets Management (DSM) provider, has the ability to… | |
| Aplazada | Alta (8.4) | 0.14% | — | IBM Licensing OperatorAI | 20/1/2026 | 17/6/2026 | IBM Licensing Operator incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the IBM Licensing Operator image. | |
| Aplazada | Media (6.5) | 0.18% | — | MariadbAIOpenai OperatorAI | 16/12/2025 | 17/6/2026 | Incorrect configuration of replication security in the MariaDB component of the infra-operator in YAOOK Operator allows an on-path attacker to read database contents, potentially including credentials | |
| Aplazada | Alta (8.7) | 0.20% | — | Redhat Runtimes-inventory-rhel8-operatorAI | 15/12/2025 | 22/8/2026 | A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials to any command it receives, instead of only the specific reports it is supposed to handle. This allows a standard user… | |
| Aplazada | Alta (8.8) | 0.33% | — | Observability OperatorAI | 12/11/2025 | 21/9/2026 | A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Custom Resource MonitorStack. This issue allows an adversarial Kubernetes Account with only namespaced-level roles, for example, a tenant controlling a namespace, to create… | |
| Aplazada | Alta (8.7) | 0.30% | — | Beyondtrust ProviderAIExternal-secrets External Secrets OperatorAI | 10/10/2025 | 17/6/2026 | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. A vulnerability was discovered in the BeyondTrust provider implementation for External Secrets Operator versions 0.10.1 through 0.19.2. The provider previously retrieved Kubernetes secrets… | |
| Analizada | Media (5.5) | 0.11% | — | IBM APP Connect Enterprise Certified Containers OperandsIBM APP Connect Operator | 1/9/2025 | 17/6/2026 | IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potentially sensitive information in log files during installation that could be read by a local user on the container. | |
| Aplazada | Alta (7.1) | 0.36% | — | External-secrets External Secrets OperatorAI | 13/8/2025 | 17/6/2026 | External Secrets Operator is a Kubernetes operator that integrates external secret management systems. From version 0.15.0 to before 0.19.2, a vulnerability was discovered where the List() calls for Kubernetes Secret and SecretStore resources performed by the PushSecret controller did not apply a namespace selector.… | |
| Aplazada | Media (6.4) | 0.22% | — | Operator-sdkAI | 7/8/2025 | 21/9/2026 | Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/passwd file to 664 during build time. Developers who used Operator-SDK before… | |
| Analizada | Media (6.5) | 0.17% | — | IBM MQ OperatorIBM Supplied MQ Advanced Container Images | 24/7/2025 | 17/6/2026 | IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.13 Internet Pass-Thru could allow a malicious user to obtain sensitive information from another TLS session connection by the proxy to the same… | |
| Analizada | Media (5.5) | 0.13% | — | IBM MQ OperatorIBM Supplied MQ Advanced Container Images | 24/7/2025 | 17/6/2026 | IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.13 Container could disclose sensitive information to a local user due to improper clearing of heap memory before release. | |
| Analizada | Media (6.9) | 0.34% | — | Openai Operator | 10/7/2025 | 17/6/2026 | Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on Web allows a remote attacker to capture sensitive user input (e.g., login credentials, email addresses) via displaying a deceptive fullscreen interface with overlaid fake browser controls and a… | |
| Analizada | Crítica (9.8) | 0.36% | — | IBM MQ OperatorIBM Supplied MQ Advanced Container Images | 15/6/2025 | 17/6/2026 | IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ Operator SC2 3.2.0 through 3.2.12 Native HA CRR could be configured with a private key and chain other than the intended key which could disclose sensitive information or… |