Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
86 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 4.1% | — | Redhat Openshift OriginRedhat Openshift | 8/6/2016 | 17/6/2026 | Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allow remote authenticated users to execute commands with root privileges by changing the root password in an sti builder image. | |
| Modificada | Media (4) | 2.0% | — | Redhat Openshift Origin | 8/9/2015 | 17/6/2026 | The API server in OpenShift Origin 1.0.5 allows remote attackers to cause a denial of service (master process crash) via crafted JSON data. | |
| Modificada | Media (4) | 1.8% | — | Refinedwiki Original Theme | 6/11/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in RefinedWiki Original Theme 3.x before 3.5.13 and 4.x before 4.0.12 for Confluence allows remote authenticated users with permissions to create or edit content to inject arbitrary web script or HTML via the versionComment parameter to pages/doeditpage.action. | |
| Modificada | Alta (10) | 5.2% | — | Redhat OpenshiftRedhat Openshift Origin | 20/6/2014 | 17/6/2026 | cartridge_repository.rb in OpenShift Origin and Enterprise 1.2.8 through 2.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a Source-Url ending with a (1) .tar.gz, (2) .zip, (3) .tgz, or (4) .tar file extension in a cartridge manifest file. | |
| Modificada | Alta (9) | 4.2% | — | Cisco Wide Area Application ServicesCisco Application AND Content Networking System SoftwareCisco Enterprise Content Delivery Network SoftwareCisco Internet Streamer Content Delivery System+4 | 1/8/2013 | 16/6/2026 | The web framework in Cisco WAAS Software before 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1; Cisco ACNS Software 4.x and 5.x before 5.5.29.2; Cisco ECDS Software 2.x before 2.5.6; Cisco CDS-IS Software 2.x before 2.6.3.b50 and 3.1.x before 3.1.2b54; Cisco VDS-IS Software 3.2.x before… | |
| Modificada | Baja (3.6) | 0.36% | — | Redhat OpenshiftRedhat Openshift Origin | 24/2/2013 | 16/6/2026 | The lockwrap function in port-proxy/bin/openshift-port-proxy-cfg in Red Hat OpenShift Origin before 1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp. | |
| Modificada | Baja (2.1) | 0.36% | — | Redhat OpenshiftRedhat Openshift Origin | 24/2/2013 | 16/6/2026 | rhc-chk.rb in Red Hat OpenShift Origin before 1.1, when -d (debug mode) is used, outputs the password and other sensitive information in cleartext, which allows context-dependent attackers to obtain sensitive information, as demonstrated by including log files or Bugzilla reports in support channels. | |
| Modificada | Media (5.8) | 1.5% | — | Redhat OpenshiftRedhat Openshift Origin | 24/2/2013 | 16/6/2026 | Open redirect vulnerability in node-util/www/html/restorer.php in Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the PATH_INFO. | |
| Modificada | Alta (7.5) | 2.2% | — | Redhat OpenshiftRedhat Openshift Origin | 24/2/2013 | 16/6/2026 | node-util/www/html/restorer.php in the Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to execute arbitrary commands via a crafted uuid in the PATH_INFO. | |
| Modificada | Media (6.8) | 1.6% | — | Jimmac Original Photo Gallery | 5/10/2007 | 16/6/2026 | inc/exif.inc.php in Original Photo Gallery 0.11.2 and earlier allows remote attackers to execute arbitrary programs via the exif_prog parameter, which is specified in an exec function call. | |
| Modificada | Alta (7.5) | 3.3% | — | Jakub Steiner Original | 11/5/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in inc/config.inc.php in Jakub Steiner (aka jimmac) original 0.11 allows remote attackers to execute arbitrary PHP code via a URL in the x[1] parameter. |