Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1570 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.7) | 0.83% | — | FeastAIFeast-operatorAI | 10/8/2026 | 14/8/2026 | A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is "no_auth," meaning no security manager is installed. This default allows unauthenticated and unauthorized access to feature-server, registry-server, and offline-server endpoints. A remote attacker,… | |
| Pendiente de análisis | Alta (8.8) | 0.73% | — | Data Science Pipelines OperatorAI | 10/8/2026 | 21/9/2026 | A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Source Name (DSN) string. By manipulating these parameters, an attacker can enable… | |
| Pendiente de análisis | Alta (7.5) | 0.61% | — | MinioAIRedhat Data Science Pipelines OperatorAI | 10/8/2026 | 21/9/2026 | A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords and MinIO access/secret keys, if they can access the MinIO Route or MariaDB Service. The flaw occurs because the operator uses a… | |
| Pendiente de análisis | Alta (8.7) | 0.70% | — | Kubeflow Data Science Pipelines OperatorAI | 10/8/2026 | 21/9/2026 | A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to execute commands within pods and manage cluster-wide roles, could be… | |
| Pendiente de análisis | Alta (8.1) | 0.60% | — | Trustyai-service-operatorAI | 10/8/2026 | 21/9/2026 | A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote code, leading to arbitrary code… | |
| Analizada | Crítica (9.8) | 0.34% | — | IBM Application Gateway Operator | 5/8/2026 | 10/8/2026 | IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources. | |
| Aplazada | Media (5.5) | 2.7% | — | Sangfor Operation AND Maintenance Security Management SystemAI | 3/8/2026 | 12/8/2026 | A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the function com.sbr.fort.foreignDP.DpLoginController of the file /fort/portal_login of the component Login Endpoint. This manipulation causes os command injection. The attack… | |
| Analizada | Media (6.3) | 0.26% | — | IBM Operations Analytics - LOG Analysis | 30/7/2026 | 1/10/2026 | IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 does not invalidate session after a password chance which could allow an authenticated user to impersonate another user on the system. | |
| Analizada | Media (6.8) | 0.46% | — | Redhat Cost Management Metrics Operator | 30/7/2026 | 12/8/2026 | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token endpoint. When authentication.type is set to service-account, the operator sends the tenant's Red Hat SSO client_id and client_secret to this… | |
| Analizada | Alta (7.6) | 0.32% | — | Redhat Cost Management Metrics Operator | 30/7/2026 | 12/8/2026 | A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL,… | |
| Analizada | Media (6.8) | 0.39% | — | Redhat Cost Management Metrics Operator | 30/7/2026 | 17/8/2026 | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer token is attached to HTTP requests sent… | |
| Aplazada | Crítica (9.9) | 0.78% | — | Banzai Cloud Logging OperatorAI | 29/7/2026 | 10/9/2026 | Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such as Flow record_transformer.records values directly into fluent.conf without escaping, allowing a… | |
| Pendiente de análisis | Alta (7.1) | 0.23% | — | Kong Kubernetes Ingress ControllerAIKong OperatorAIKong GatewayAI | 29/7/2026 | 30/7/2026 | Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. The embedded KIC collects CA-certificate Secrets across all watched namespaces using a label selector alone, without… | |
| Pendiente de análisis | Media (6.5) | 0.35% | — | Tempo OperatorAI | 13/7/2026 | 13/7/2026 | The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces. | |
| Aplazada | Baja (2) | 0.33% | — | Amtt Hotel Broadband Operation SystemAI | 12/7/2026 | 13/7/2026 | A flaw has been found in AMTT Hotel Broadband Operation System 1.0. Impacted is an unknown function of the file manager/network/switch_status.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The… | |
| Pendiente de análisis | Media (6.3) | 0.28% | — | Trustyai-service-operatorAITrustyai GorchAI | 8/7/2026 | 31/8/2026 | A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication is enabled, the gorch service exposes unproxied orchestrator and detector metrics ports. This allows any pod on the cluster network to directly access these ports, bypassing the kube-rbac-proxy and… | |
| Pendiente de análisis | Media (6.3) | 0.27% | — | Trustyai Service OperatorAIGorchAINemoguardrailsAI | 8/7/2026 | 31/8/2026 | A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enabled, these services can expose their communication channels without requiring users to prove their identity. This allows any other program within the cluster to access the… | |
| Analizada | Alta (8.8) | 0.42% | — | Dell Data Domain Operating System | 8/7/2026 | 9/7/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Incorrect Authorization vulnerability. A low privileged attacker with remote access could… | |
| Analizada | Alta (7.5) | 0.48% | — | Dell Data Domain Operating System | 8/7/2026 | 9/7/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access… | |
| Analizada | Baja (2.7) | 0.35% | — | Dell Data Domain Operating System | 8/7/2026 | 8/7/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper limitation of a pathname to a restricted directory ('path traversal') vulnerability. A… | |
| Analizada | Alta (7.1) | 0.28% | — | Dell Data Domain Operating System | 8/7/2026 | 8/7/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain a stored cross-site scripting vulnerability. An unauthenticated attacker with remote access could… | |
| Analizada | Alta (7.2) | 2.0% | — | Dell Data Domain Operating System | 7/7/2026 | 8/7/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special elements used in an OS command ('OS command Injection')… | |
| Analizada | Crítica (9.8) | 0.63% | — | Dell Data Domain Operating System | 7/7/2026 | 8/7/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 an improper authentication vulnerability. An unauthenticated attacker with remote access could potentially… | |
| Analizada | Crítica (9.8) | 0.63% | — | Dell Data Domain Operating System | 7/7/2026 | 8/7/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability.… | |
| Analizada | Alta (7.2) | 2.0% | — | Dell Data Domain Operating System | 3/7/2026 | 8/7/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special elements used in an OS command ('OS command Injection')… |