Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
255 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.7) | 0.69% | — | Palantir Foundry FrontendPalantir Foundry Issues | 10/7/2023 | 17/6/2026 | A security defect was identified that enabled a user of Foundry Issues to perform a Denial of Service attack by submitting malformed data in an Issue that caused loss of frontend functionality to all issue participants. This defect was resolved with the release of Foundry Issues 2.510.0 and Foundry Frontend 6.228.0. | |
| Modificada | Media (5.4) | 0.37% | — | Palantir Foundry Workspace-server | 29/6/2023 | 17/6/2026 | A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and view settings related to 'Developer Mode'. This enabled users with insufficient privilege the ability to view and interact with Developer Mode settings in a limited capacity. A fix was deployed with… | |
| Modificada | Media (4.3) | 0.39% | — | Palantir Foundry Issues | 29/6/2023 | 17/6/2026 | A security defect was identified in Foundry Issues. If a user was added to an issue on a resource that they did not have access to and consequently could not see, they could query Foundry's Notification API and receive metadata about the issue including the RID of the issue, severity, internal UUID of the author, and… | |
| Modificada | Media (6.5) | 0.54% | — | Pivotal Cloud Foundry NFS VolumePivotal Cloud Foundry NotificationsPivotal Cloud Foundry SMB Volume | 16/6/2023 | 17/6/2026 | Vulnerability in Cloud Foundry Notifications, Cloud Foundry SMB-volume release, Cloud FOundry cf-nfs-volume release.This issue affects Notifications: All versions prior to 63; SMB-volume release: All versions prior to 3.1.19; cf-nfs-volume release: 5.0.X versions prior to 5.0.27, 7.1.X versions prior to 7.1.19. | |
| Modificada | Media (6.5) | 0.41% | — | Palantir Foundry | 6/6/2023 | 17/6/2026 | Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that allowed authenticated users within a Foundry organization to bypass discretionary or mandatory access controls under certain circumstances. | |
| Modificada | Media (6.5) | 0.54% | — | Palantir Foundry Comments | 6/6/2023 | 17/6/2026 | A security defect in Foundry's Comments functionality resulted in the retrieval of attachments to comments not being gated by additional authorization checks. This could enable an authenticated user to inject a prior discovered attachment UUID into other arbitrary comments to discover it's content. This defect was… | |
| Modificada | Media (5.9) | 0.58% | — | Cloudfoundry Cf-deploymentCloudfoundry Routing Release | 26/5/2023 | 17/6/2026 | In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of service of applications hosted on Cloud Foundry. Under the right circumstances, when client connections are closed prematurely, gorouter marks the currently selected backend as failed and… | |
| Modificada | Alta (8.1) | 0.36% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deploymentCloudfoundry Loggregator-agent | 19/5/2023 | 17/6/2026 | Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credentials if they're aware of the client certificate used for that syslog drain. This applies even if the drain has zero certs. This would allow the user to override the… | |
| Modificada | Media (4.3) | 0.40% | — | Cloudfoundry User Account AND Authentication | 28/3/2023 | 17/6/2026 | This disclosure regards a vulnerability related to UAA refresh tokens and external identity providers.Assuming that an external identity provider is linked to the UAA, a refresh token is issued to a client on behalf of a user from that identity provider, the administrator of the UAA deactivates the identity provider… | |
| Modificada | Media (6.1) | 0.53% | — | Maxfoundry Maxbuttons | 5/3/2023 | 17/6/2026 | A vulnerability was found in MaxButtons Plugin up to 1.26.0 on WordPress and classified as problematic. This issue affects the function maxbuttons_strip_px of the file includes/maxbuttons-button.php. The manipulation of the argument button_id leads to cross site scripting. The attack may be initiated remotely.… | |
| Modificada | Crítica (9.1) | 0.38% | — | Cloudfoundry Cf-deploymentCloudfoundry Diego | 3/2/2023 | 17/6/2026 | Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on diego cells, allowing application ingress without a client certificate. If mTLS route integrity is enabled AND unproxied ports are turned off, then an attacker could… | |
| Modificada | Crítica (9.1) | 1.2% | — | Cloudfoundry Archiver | 27/12/2022 | 17/6/2026 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | |
| Modificada | Alta (8.8) | 0.31% | — | Maxfoundry Media Library Folders | 18/11/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Media Library Folders plugin <= 7.1.1 on WordPress. | |
| Modificada | Alta (7.5) | 0.40% | — | Palantir Foundry Build2 | 15/11/2022 | 17/6/2026 | Information Exposure Through Log Files vulnerability discovered in Foundry when logs were captured using an underlying library known as Build2. This issue was present in versions earlier than 1.785.0. Upgrade to Build2 version 1.785.0 or greater. | |
| Modificada | Alta (7.5) | 0.40% | — | Palantir Foundry Code-workbooks | 14/11/2022 | 17/6/2026 | Information Exposure Through Log Files vulnerability discovered in Foundry Code-Workbooks where the endpoint backing that console was generating service log records of any Python code being run. These service logs included the Foundry token that represents the Code-Workbooks Python console. Upgrade to Code-Workbooks… | |
| Modificada | Crítica (9.8) | 2.6% | 💥 PoC | Vmware Bosh EditorVmware Cloudfoundry Manifest YML SupportVmware Concourse CI Pipeline EditorVmware Spring Boot Tools+1 | 4/11/2022 | 17/6/2026 | Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39.0 and below all use Snakeyaml library for YAML editing support. This library allows for some special syntax in the… | |
| Modificada | Media (5.4) | 0.35% | — | Palantir Foundry Blobster | 4/11/2022 | 17/6/2026 | The Foundry Blobster service was found to have a cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Foundry to launch attacks against other users. This vulnerability is resolved in Blobster 3.228.0. | |
| Modificada | Media (4.8) | 0.51% | — | Maxfoundry Maxbuttons | 23/9/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Foundry Button Plugin MaxButtons plugin <= 9.2 at WordPress | |
| Modificada | Alta (8.8) | 0.40% | — | Maxfoundry Maxbuttons | 22/8/2022 | 17/6/2026 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Max Foundry MaxButtons plugin <= 9.2 at WordPress. | |
| Modificada | Media (4.8) | 0.59% | — | Maxfoundry Wp-paginate | 11/7/2022 | 17/6/2026 | The WP-Paginate WordPress plugin before 2.1.9 does not escape one of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when unfiltered_html is disallowed | |
| Modificada | Media (4.4) | 0.31% | — | Edgexfoundry Edgex Foundry | 14/6/2022 | 17/6/2026 | EdgeX Foundry is an open source project for building a common open framework for Internet of Things edge computing. Prior to version 2.1.1, the /api/v2/config endpoint exposes message bus credentials to local unauthenticated users. In security-enabled mode, message bus credentials are supposed to be kept in the EdgeX… | |
| Modificada | Crítica (9.1) | 0.95% | — | Palantir Foundry Multipass | 14/6/2022 | 17/6/2026 | The Multipass service was found to have code paths that could be abused to cause a denial of service for authentication or authorization operations. A malicious attacker could perform an application-level denial of service attack, potentially causing authentication and/or authorization operations to fail for the… | |
| Modificada | Media (5.5) | 0.23% | — | Palantir Foundry Issues | 26/4/2022 | 17/6/2026 | Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive information (session tokens). This issue was fixed in 2.249.1. | |
| Modificada | Media (5.3) | 0.92% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deployment | 25/3/2022 | 17/6/2026 | In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally or maliciously) causes CC instances to timeout and fail is possible. An attacker can leverage this vulnerability to cause an inability for anyone to push or manage apps. | |
| Modificada | Media (4.8) | 0.56% | — | Maxfoundry Maxgalleria | 18/3/2022 | 17/6/2026 | Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in MaxGalleria WordPress plugin (versions 6.2.5). |