Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
119 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.73% | — | Helmet Store Showroom Site Project Helmet Store Showroom Site | 14/12/2022 | 17/6/2026 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=product_per_brand&bid=. | |
| Modificada | Alta (7.2) | 0.73% | — | Helmet Store Showroom Site Project Helmet Store Showroom Site | 14/12/2022 | 17/6/2026 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=view_product&id=. | |
| Modificada | Alta (8.8) | 0.50% | — | Helmet Store Showroom Project Helmet Store Showroom | 14/12/2022 | 17/6/2026 | Helmet Store Showroom 1.0 is vulnerable to Cross Site Request Forgery (CSRF). An unauthenticated user can add an admin account due to missing CSRF protection. | |
| Modificada | Media (6.1) | 1.3% | 💥 Exploit | Helmet Store Showroom Project Helmet Store Showroom | 14/12/2022 | 17/6/2026 | Helmet Store Showroom 1.0 is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Media (4.3) | 0.68% | — | Fluxcd Flux2Fluxcd Helm-controllerFluxcd Image-automation-controllerFluxcd Image-reflector-controller+3 | 22/10/2022 | 17/6/2026 | Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a Denial of Service. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields `.spec.interval` or… | |
| Modificada | Media (5.3) | 1.0% | — | Mbconnectline Mbconnect24Mbconnectline Mymbconnect24Helmholz Myrex24Helmholz Myrex24.virtual | 14/9/2022 | 17/6/2026 | A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. | |
| Modificada | Alta (7.5) | 1.4% | — | HelmFluxcd Flux2Fluxcd Helm-controller | 7/9/2022 | 17/6/2026 | Flux2 is a tool for keeping Kubernetes clusters in sync with sources of configuration, and Flux's helm-controller is a Kubernetes operator that allows one to declaratively manage Helm chart releases. Helm controller is tightly integrated with the Helm SDK. A vulnerability found in the Helm SDK that affects flux2… | |
| Modificada | Media (6.5) | 1.0% | — | Helm | 1/9/2022 | 17/6/2026 | Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. Fuzz testing, provided by the CNCF, identified input to functions in the _strvals_ package that can cause an out of memory panic. The _strvals_ package contains a parser that turns strings in to Go structures. The _strvals_… | |
| Modificada | Crítica (9.3) | 1.5% | — | Helm-flask-celery Project Helm-flask-celery | 11/7/2022 | 17/6/2026 | The olmax99/helm-flask-celery repository before 2022-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Crítica (9.9) | 1.1% | — | Fluxcd Flux2Fluxcd Helm-controllerFluxcd Kustomize-controller | 6/5/2022 | 17/6/2026 | Flux2 is an open and extensible continuous delivery solution for Kubernetes. Flux2 versions between 0.1.0 and 0.29.0, helm-controller 0.1.0 to v0.19.0, and kustomize-controller 0.1.0 to v0.23.0 are vulnerable to Code Injection via malicious Kubeconfig. In multi-tenancy deployments this can also lead to privilege… | |
| Modificada | Media (4.3) | 0.66% | — | Mbconnectline Mbconnect24Mbconnectline Mymbconnect24Helmholz Myrex24Helmholz Myrex24.virtual | 2/8/2021 | 17/6/2026 | In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 an authenticated attacker can change the password of his account into a new password that violates the password policy by intercepting and modifying the request that is send to the server. | |
| Modificada | Alta (8.6) | 1.4% | — | Helm | 16/6/2021 | 17/6/2026 | Helm is a tool for managing Charts (packages of pre-configured Kubernetes resources). In versions of helm prior to 3.6.1, a vulnerability exists where the username and password credentials associated with a Helm repository could be passed on to another domain referenced by that Helm repository. This issue has been… | |
| Modificada | Media (6.5) | 1.0% | — | Mbconnectline Mbconnect24Mbconnectline Mymbconnect24Helmholz Myrex24Helmholz Myrex24.virtual | 2/3/2021 | 17/6/2026 | An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. Improper access validation allows a logged in user to shutdown or reboot devices in his account without having corresponding permissions. | |
| Modificada | Media (5.3) | 1.2% | — | Mbconnectline Mbconnect24Mbconnectline Mymbconnect24Helmholz Myrex24Helmholz Myrex24.virtual | 16/2/2021 | 17/6/2026 | An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. An unauthenticated attacker is able to access files (that should have been restricted) via forceful browsing. | |
| Modificada | Media (4.3) | 0.97% | — | Mbconnectline Mbconnect24Mbconnectline Mymbconnect24Helmholz Myrex24Helmholz Myrex24.virtual | 16/2/2021 | 17/6/2026 | An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An incomplete filter applied to a database response allows an authenticated attacker to gain non-public information about other users and devices in the account. | |
| Modificada | Media (5.3) | 1.2% | — | Mbconnectline Mbconnect24Mbconnectline Mymbconnect24Helmholz Myrex24Helmholz Myrex24.virtual | 16/2/2021 | 17/6/2026 | An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An attacker can read arbitrary JSON files via Local File Inclusion. | |
| Modificada | Media (5.3) | 1.2% | — | Mbconnectline Mbconnect24Mbconnectline Mymbconnect24Helmholz Myrex24Helmholz Myrex24.virtual | 16/2/2021 | 17/6/2026 | An issue was discovered MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. There is an SSRF in the HA module allowing an unauthenticated attacker to scan for open ports. | |
| Modificada | Alta (7.5) | 1.5% | — | Mbconnectline Mbconnect24Mbconnectline Mymbconnect24Helmholz Myrex24Helmholz Myrex24.virtual | 16/2/2021 | 17/6/2026 | An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. There is an SSRF in the in the MySQL access check, allowing an attacker to scan for open ports and gain some information about possible credentials. | |
| Modificada | Media (6.5) | 1.0% | — | Mbconnectline Mbconnect24Mbconnectline Mymbconnect24Helmholz Myrex24Helmholz Myrex24.virtual | 16/2/2021 | 17/6/2026 | An issue in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 allows a logged in user to see devices in the account he should not have access to due to improper use of access validation. | |
| Modificada | Media (6.8) | 1.0% | — | Helm | 5/2/2021 | 17/6/2026 | Helm is open-source software which is essentially "The Kubernetes Package Manager". Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. In Helm from version 3.0 and before version 3.5.2, there a few cases where data loaded from potentially untrusted sources was not properly… | |
| Modificada | Media (4.7) | 1.5% | — | Helm | 17/9/2020 | 17/6/2026 | In Helm before versions 2.16.11 and 3.3.2, a Helm plugin can contain duplicates of the same entry, with the last one always used. If a plugin is compromised, this lowers the level of access that an attacker needs to modify a plugin's install hooks, causing a local execution attack. To perform this attack, an attacker… | |
| Modificada | Baja (2.7) | 0.96% | — | Helm | 17/9/2020 | 17/6/2026 | In Helm before versions 2.16.11 and 3.3.2 plugin names are not sanitized properly. As a result, a malicious plugin author could use characters in a plugin name that would result in unexpected behavior, such as duplicating the name of another plugin or spoofing the output to `helm --help`. This issue has been patched… | |
| Modificada | Baja (2.7) | 0.88% | — | Helm | 17/9/2020 | 17/6/2026 | In Helm before versions 2.16.11 and 3.3.2, a Helm repository can contain duplicates of the same chart, with the last one always used. If a repository is compromised, this lowers the level of access that an attacker needs to inject a bad chart into a repository. To perform this attack, an attacker must have write… | |
| Modificada | Baja (2.7) | 1.0% | — | Helm | 17/9/2020 | 17/6/2026 | In Helm before versions 2.16.11 and 3.3.2 there is a bug in which the `alias` field on a `Chart.yaml` is not properly sanitized. This could lead to the injection of unwanted information into a chart. This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is to manually review the `dependencies`… | |
| Modificada | Crítica (9) | 1.4% | — | Cyberark Conjur OSS Helm Chart | 22/6/2020 | 17/6/2026 | In Conjur OSS Helm Chart before 2.0.0, a recently identified critical vulnerability resulted in the installation of the Conjur Postgres database with an open port. This allows an attacker to gain full read & write access to the Conjur Postgres database, including escalating the attacker's privileges to assume full… |