Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

104 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.53%—Redhat Build OF QuarkusRedhat Data GridRedhat Descision ManagerRedhat Integration Camel K+520/5/202117/6/2026
A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.
ModificadaMedia (6.8)1.4%—Microsoft Azure Container InstancesMicrosoft Azure Container RegistryMicrosoft Azure Kubernetes ServiceMicrosoft Azure Service Fabric+111/3/202119/8/2026
Azure Virtual Machine Information Disclosure Vulnerability
ModificadaCrítica (9.8)2.6%—Docker Registry11/12/202017/6/2026
Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deployed using affected versions of the registry container may allow a remote attacker to achieve root access with a blank password.
ModificadaMedia (6.5)2.7%—Apache Nifi Registry28/4/202017/6/2026
If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Registry invalidates the authentication token on the client side but not on the server side. This permits the user's client-side token to be used for up to 12 hours after logging out to make API requests…
ModificadaAlta (7.2)2.1%—Linuxfoundation HarborPivotal Vmware Harbor Registry20/3/202017/6/2026
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform.
ModificadaMedia (4.9)1.4%—Linuxfoundation HarborPivotal Vmware Harbor Registry20/3/202017/6/2026
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.
ModificadaAlta (8.8)1.0%—Linuxfoundation HarborPivotal Vmware Harbor Registry20/3/202017/6/2026
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform.
ModificadaAlta (8.8)1.6%—Linuxfoundation HarborPivotal Vmware Harbor Registry20/3/202017/6/2026
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry for the Pivotal Platform.
ModificadaMedia (5.3)1.1%—IBM Websphere Service Registry AND Repository26/2/202017/6/2026
IBM WebSphere Service Registry and Repository 8.5 could allow a user to obtain sensitive version information that could be used in further attacks against the system. IBM X-Force ID: 165593.
ModificadaAlta (7.5)1.7%—Linuxfoundation HarborVmware Cloud FoundationVmware Harbor Container Registry18/10/201917/6/2026
Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or pull access permissions to a project they don't have access or control for. The Harbor API did not enforce the proper project permissions…
ModificadaCrítica (9.8)1.4%—Silverstripe RegistrySilverstripe Restfulserver11/6/201917/6/2026
SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x before 2.1.2 and silverstripe/registry module 2.1.x before 2.1.1 and 2.2.x before 2.2.1 allows attackers to execute arbitrary SQL commands.
ModificadaAlta (7.5)2.0%—Simple-npm-registry Project Simple-npm-registry7/6/201817/6/2026
simple-npm-registry is a local npm package cache. simple-npm-registry is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaMedia (4.8)3.8%💥 ExploitWso2 API ManagerWso2 APP ManagerWso2 Application ServerWso2 Business Process Server+1321/9/201717/6/2026
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
ModificadaAlta (7.5)3.2%—Docker RegistryRedhat Enterprise Linux Server20/7/201717/6/2026
Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.
ModificadaMedia (4.3)1.5%—Openstack Image Registry AND Delivery Service (glance)13/4/201617/6/2026
OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when show_multiple_locations is enabled, allow remote authenticated users to change image status and upload new image data by removing the last location of an image.
ModificadaMedia (6.8)2.4%—Openstack Image Registry AND Delivery Service (glance)26/10/201517/6/2026
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting images that are being uploaded using a token that expires during the process. NOTE: this vulnerability…
ModificadaMedia (5.5)2.1%—Openstack Image Registry AND Delivery Service (glance)26/10/201517/6/2026
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-status header to images/*.
ModificadaMedia (4)2.1%—Openstack Image Registry AND Delivery Service (glance)24/2/201517/6/2026
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them, a different vulnerability than…
ModificadaMedia (4)2.0%—Openstack Image Registry AND Delivery Service (glance)24/2/201517/6/2026
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them before the uploads finish, a…
ModificadaMedia (4)2.9%—Redhat OpenstackOpenstack Image Registry AND Delivery Service (glance)23/1/201517/6/2026
OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.
ModificadaMedia (6.5)2.8%—Openstack Image Registry AND Delivery Service (glance)21/1/201517/6/2026
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.1.4 and 2014.2.x before 2014.2.2 allows remote authenticated users to read or delete arbitrary files via a full pathname in a filesystem: URL in the image location property. NOTE: this vulnerability exists because of an incomplete fix for…
ModificadaMedia (5.5)2.8%—Redhat OpenstackOpenstack Image Registry AND Delivery Service (glance)7/1/201517/6/2026
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image location property.
ModificadaBaja (2.1)0.61%—IBM Websphere Service Registry AND Repository29/12/201417/6/2026
IBM WebSphere Service Registry and Repository (WSRR) 8.5 before 8.5.0.1, when Chrome and WebSEAL are used, does not properly process ServiceRegistryDashboard logout actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.
ModificadaBaja (3.5)1.5%—IBM Websphere Service Registry AND Repository24/12/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x before 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x before 7.5.0.3, and 8.0.x before 8.0.0.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6)0.87%—IBM Websphere Service Registry AND Repository24/12/201417/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x before 6.3.0.5, 7.0.x before 7.0.0.5, 7.5.x before 7.5.0.3, and 8.0.x before 8.0.0.2 allow remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
Orbitaley — Vulnerabilidades