Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
2350 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.1) | 0.35% | — | Redhat Multicluster EngineAIRedhat Clusterclaims ControllerAI | 13/8/2026 | 29/9/2026 | A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable… | |
| Pendiente de análisis | Crítica (9.9) | 0.56% | — | Cluster-curator-controllerAI | 12/8/2026 | 29/9/2026 | A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control.… | |
| Pendiente de análisis | Crítica (9.9) | 0.88% | — | Redhat Multicluster EngineAIRedhat Cluster Curator ControllerAI | 12/8/2026 | 29/9/2026 | A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the… | |
| Analizada | Crítica (9.1) | 0.80% | — | Craftycontrol Crafty Controller | 11/8/2026 | 18/8/2026 | Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution. | |
| Pendiente de análisis | Media (6.5) | 0.42% | — | Redhat Odh-model-controllerAI | 10/8/2026 | 14/8/2026 | A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can exploit a vulnerability in the `loadSecret` function. This function improperly reads the Secret namespace from user-controlled input without validation. This allows an attacker to read sensitive API… | |
| Pendiente de análisis | Media (4.8) | 0.29% | — | Cisco Integrated Management ControllerAI | 5/8/2026 | 6/8/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could… | |
| Aplazada | Alta (7.6) | 0.21% | — | Watchfire Controller SoftwareAI | 30/7/2026 | 8/9/2026 | The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries… | |
| Pendiente de análisis | Alta (8.8) | 0.80% | — | Samba Active Directory Domain ControllerAI | 30/7/2026 | 30/7/2026 | A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied attribute names and executes the resulting internal database search in a trusted… | |
| Aplazada | Alta (7.1) | 0.19% | — | Mitsubishielectric Melsec MX Controller Mx-rAIMitsubishielectric Melsec MX Controller Mx-fAIMitsubishielectric Cc-link IE TSN Interface BoardAIMitsubishielectric Motion ModuleAI+25 | 30/7/2026 | 18/9/2026 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board,… | |
| Pendiente de análisis | Alta (7.1) | 0.23% | — | Kong Kubernetes Ingress ControllerAIKong OperatorAIKong GatewayAI | 29/7/2026 | 30/7/2026 | Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. The embedded KIC collects CA-certificate Secrets across all watched namespaces using a label selector alone, without… | |
| Pendiente de análisis | Alta (7.1) | 0.23% | — | Kong Kubernetes Ingress ControllerAI | 29/7/2026 | 30/7/2026 | Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. KIC collects CA-certificate Secrets across all watched namespaces using a label selector alone, without ingress-class or namespace restrictions. The… | |
| Aplazada | Alta (7.1) | 0.28% | — | Codesys Profinet ControllerAICodesys ControlAI | 29/7/2026 | 30/7/2026 | An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in… | |
| Aplazada | Media (4.8) | 0.43% | — | Ericsson Packet Core ControllerAI | 27/7/2026 | 29/9/2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, denying access to legitimate users. | |
| Aplazada | Media (5.1) | 0.16% | — | Ericsson Packet Core ControllerAI | 27/7/2026 | 29/9/2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information. | |
| Aplazada | Media (4.8) | 0.23% | — | Ericsson Packet Core ControllerAI | 27/7/2026 | 29/9/2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system. | |
| Aplazada | Media (6.8) | 0.23% | — | Ericsson Packet Core ControllerAI | 27/7/2026 | 29/9/2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted commands to reveal system secret through error messages. | |
| Aplazada | Alta (8.5) | 0.28% | — | Ericsson Packet Core ControllerAI | 27/7/2026 | 29/9/2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root. | |
| Analizada | Media (6.4) | 0.31% | — | Oracle Communications Convergent Charging Controller | 21/7/2026 | 17/8/2026 | Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: Prov IF). Supported versions that are affected are 15.0.0.0.0 and 15.2.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (8.7) | 0.52% | — | Progress Sharefile Storage Zones Controller | 21/7/2026 | 3/9/2026 | In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server. | |
| Analizada | Alta (8.8) | 0.53% | — | F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance ManagerF5 Nginx Open Source+2 | 15/7/2026 | 11/8/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process,… | |
| Analizada | Media (6.3) | 0.45% | — | F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx PlusF5 WAF | 15/7/2026 | 10/8/2026 | When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the attacker's control to cause a heap buffer over-read in the NGINX worker process, leading to a restart. Impact: This… | |
| Analizada | Alta (8.3) | 0.42% | — | F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx PlusF5 WAF | 15/7/2026 | 10/8/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control… | |
| Analizada | Alta (8.7) | 0.51% | — | F5 Nginx Ingress Controller | 15/7/2026 | 16/7/2026 | When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An… | |
| Analizada | Alta (7.1) | 0.50% | — | F5 Nginx Ingress Controller | 15/7/2026 | 16/7/2026 | When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate. Impact: The NGINX Ingress Controller control plane process terminates and… | |
| Analizada | Crítica (9.2) | 0.89% | — | F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx PlusF5 WAF | 15/7/2026 | 10/8/2026 | A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression… |