Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
6126 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.7) | 0.47% | — | Redhat Multicluster Observability AddonAIRedhat Opentelemetry CollectorAIRedhat Cluster LOG ForwarderAI | 11/9/2026 | 21/9/2026 | A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on… | |
| Pendiente de análisis | Media (5.9) | 0.41% | — | Redhat Service InterconnectAIRedhat Skupper RouterAI | 10/9/2026 | 14/9/2026 | A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processes a specially crafted network message using its AMQP field parser. Due to a lack of bounds on recursion during parsing,… | |
| Aplazada | Alta (7.7) | 0.21% | — | Redhat OpenshiftAIOpenai OperatorAI | 9/9/2026 | 9/9/2026 | A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under specific conditions during the initial provisioning of a Portworx storage cluster, a user holding only limited, namespace-scoped permissions could cause the operator to grant broader access than intended,… | |
| Pendiente de análisis | Media (4.9) | 0.48% | — | Redhat Build OF KeycloakAIRedhat KeycloakAI | 9/9/2026 | 16/9/2026 | A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm administrator to still submit arbitrary filesystem paths as keystore parameters. This… | |
| Pendiente de análisis | Crítica (9.9) | 0.39% | — | Hawtio-operatorAIRedhat OpenshiftAI | 8/9/2026 | 8/9/2026 | A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource. Because the operator ships a ClusterRole… | |
| Pendiente de análisis | Media (6.5) | 0.35% | — | Redhat Openshift AIAIRedhat Odh-dashboardAI | 7/9/2026 | 8/9/2026 | A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data, without an authorization check. Any authenticated dashboard user can retrieve the… | |
| Analizada | Media (4.7) | 0.14% | — | Redhat Enterprise Linux | 3/9/2026 | 22/9/2026 | A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untrusted inode height value from on-disk metadata without bounds validation, causing stack exhaustion and a denial of service when processing crafted GFS2 filesystem images. | |
| Analizada | Media (6.3) | 0.14% | — | Redhat Enterprise Linux | 3/9/2026 | 22/9/2026 | A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap buffer over-read that may disclose sensitive memory contents or cause a crash when processing crafted GFS2 filesystem images. | |
| Analizada | Alta (7) | 0.17% | — | Redhat Enterprise Linux | 3/9/2026 | 22/9/2026 | A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images. | |
| Analizada | Alta (7) | 0.17% | — | Redhat Enterprise Linux | 3/9/2026 | 22/9/2026 | A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images. | |
| Analizada | Media (4.7) | 0.14% | — | Redhat Enterprise Linux | 3/9/2026 | 22/9/2026 | A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di_depth field without bounds validation. A crafted GFS2 filesystem image with a large di_depth value causes stack exhaustion and a denial of… | |
| Aplazada | Crítica (9.8) | 0.30% | — | Redhat Developer ToolsAI | 2/9/2026 | 3/9/2026 | The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component | |
| Pendiente de análisis | Media (6.4) | 0.30% | — | Redhat Ansible Automation PlatformAIAnsible AWXAI | 1/9/2026 | 24/9/2026 | A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whereas the standard single-job launch path requires use-level permission on the same field. A… | |
| Pendiente de análisis | Media (6.5) | 0.32% | — | Apache HttpdAIDogtag Certificate AuthorityAIRedhat Identity ManagementAI | 1/9/2026 | 1/9/2026 | An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same unauthenticated error path emits large multi-line stack traces into the CA debug log, creating a log-amplification resource exhaustion… | |
| Pendiente de análisis | Alta (7.5) | 0.36% | — | Redhat ResteasyAI | 31/8/2026 | 2/10/2026 | A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or… | |
| Pendiente de análisis | Alta (8.8) | 0.37% | — | Redhat QuteAIRedhat QuarkusAI | 31/8/2026 | 11/9/2026 | A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails. The issue exists in the component responsible for looking up data values (ReflectionValueResolver), which fails to properly block access to sensitive Java internal functions when processing… | |
| Pendiente de análisis | Alta (7.5) | 0.58% | — | Redhat Jboss EAPAIRedhat WildflyAIRedhat UndertowAI | 31/8/2026 | 10/9/2026 | Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot be adjusted and default to being unlimited. This allows a remote attacker to send… | |
| Analizada | Media (6.1) | 0.26% | — | GimpRedhat Enterprise Linux | 28/8/2026 | 1/9/2026 | A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not properly validate the channel-count parameter. This incorrect validation leads to improper memory bounds checking, resulting in both a heap out-of-bounds read and a stack out-of-bounds access. This… | |
| Analizada | Media (6.1) | 0.26% | — | GimpRedhat Enterprise Linux | 28/8/2026 | 31/8/2026 | A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service… | |
| Analizada | Media (6.1) | 0.26% | — | GimpRedhat Enterprise Linux | 28/8/2026 | 31/8/2026 | A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap out-of-bounds read. This issue can result in an… | |
| Pendiente de análisis | Media (5.5) | 0.16% | — | Fedora DNFAISuse ZypperAIRedhat YUMAIOpensuse LibsolvAI | 28/8/2026 | 28/8/2026 | A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id values from the file's compressed filelist data without validating that they fall within the… | |
| Analizada | Media (6.1) | 0.27% | — | GimpRedhat Enterprise Linux | 28/8/2026 | 31/8/2026 | A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate the HAM row size and improperly handles cases where the number of color planes (nPlanes) is zero. This causes a row size mismatch that bypasses memory bounds… | |
| Pendiente de análisis | Alta (7.5) | 1.1% | — | Redhat UndertowAI | 27/8/2026 | 22/9/2026 | A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a… | |
| Modificada | Media (4.4) | 0.23% | — | GimpRedhat Enterprise Linux | 25/8/2026 | 2/9/2026 | A flaw was found in the file-xwd plugin in GIMP. When processing a specially crafted XWD image file, the plugin validates the image width and bytes-per-line parameters independently rather than ensuring their combined values are consistent with the allocated buffer size. This incorrect validation leads to improper… | |
| Pendiente de análisis | Media (5.9) | 0.34% | — | Redhat KeycloakAI | 25/8/2026 | 28/9/2026 | A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various OAuth2 and OpenID Connect grant types used for issuing access tokens. The issue occurs because the JWT Bearer grant fails to check if a client… |