Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
566 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.7) | 0.18% | — | Oracle Mysql Cluster | 15/7/2025 | 17/6/2026 | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and 9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Cluster executes to compromise… | |
| Analizada | Media (5.5) | 0.14% | — | Redhat Advanced Cluster Management FOR Kubernetes | 2/7/2025 | 17/6/2026 | A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials through the UI. This information should only be accessible to authorized users and… | |
| Aplazada | Media (6) | 0.22% | — | Akka-cluster-metricsAI | 28/6/2025 | 17/6/2026 | In Akka through 2.10.6, akka-cluster-metrics uses Java serialization for cluster metrics. | |
| Modificada | Media (5.4) | 0.28% | — | Redhat Advanced Cluster SecurityStackrox | 27/5/2025 | 17/6/2026 | A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of table cells. The only known potential exploit is if the script is included in the name of a Kubernetes “Role” object* that is applied to a secured cluster. This object can be used by a… | |
| Aplazada | Media (5.4) | 0.33% | — | Apache MOD Proxy ClusterAI | 23/4/2025 | 6/10/2026 | A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive should be replaced by the <Location> directive as the former does not restrict IP/host access as `Require ip IP_ADDRESS` would suggest. This means that anyone with access to the host might send MCMP requests that may result in… | |
| Aplazada | Crítica (9.8) | 0.42% | — | HPE Performance Cluster ManagerAI | 22/4/2025 | 17/6/2026 | A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the server host. | |
| Analizada | Alta (8.1) | 0.41% | — | HPE Performance Cluster Manager | 21/4/2025 | 17/6/2026 | A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication. | |
| Modificada | Media (6.8) | 0.50% | — | Oracle Mysql ClusterOracle Mysql ClientNetapp Active IQ Unified ManagerNetapp Snapcenter | 15/4/2025 | 17/6/2026 | Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client.… | |
| Analizada | Media (4.9) | 0.62% | — | Oracle Mysql Cluster | 15/4/2025 | 17/6/2026 | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDBCluster Plugin). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL… | |
| Modificada | Media (5.5) | 0.97% | — | Oracle Mysql ClusterOracle Mysql Server | 15/4/2025 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks… | |
| Modificada | Baja (2.7) | 0.75% | — | Oracle Mysql ClusterOracle Mysql Server | 15/4/2025 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.… | |
| Modificada | Media (6.5) | 0.91% | — | Oracle Mysql ClusterOracle Mysql Server | 15/4/2025 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful… | |
| Modificada | Media (6.5) | 1.1% | 💥 PoC | Oracle Mysql ClusterOracle Mysql Server | 15/4/2025 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful… | |
| Analizada | Media (5.5) | 1.4% | — | Microsoft Azure Local Cluster | 8/4/2025 | 17/6/2026 | Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally. | |
| Analizada | Media (5.7) | 1.1% | — | Microsoft Azure Local Cluster | 8/4/2025 | 17/6/2026 | Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network. | |
| Aplazada | Crítica (9.8) | 0.49% | — | HPE Insight Cluster Management UtilityAI | 30/3/2025 | 17/6/2026 | Unauthenticated RCE in HPE Insight Cluster Management Utility | |
| Aplazada | Alta (8.2) | 0.49% | — | Redhat Multicluster EngineAIRedhat Advanced Cluster ManagementAIRedhat HiveAI | 17/3/2025 | 21/8/2026 | A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials… | |
| Aplazada | Alta (8.9) | 0.33% | — | Redhat Advanced Cluster SecurityAI | 27/1/2025 | 17/6/2026 | A flaw was found in the Red Hat Advanced Cluster Security (RHACS) portal. When rendering a table view in the portal, for example, on any of the /main/configmanagement/* endpoints, the front-end generates a DOM table-element (id="pdf-table"). This information is then populated with unsanitized data using innerHTML. An… | |
| Modificada | Media (4.9) | 0.87% | — | Oracle Mysql ClusterOracle Mysql Server | 21/1/2025 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL… | |
| Modificada | Media (4.9) | 1.0% | — | Oracle Mysql ClusterOracle Mysql Server | 21/1/2025 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.… | |
| Modificada | Baja (1.8) | 0.30% | — | Oracle Mysql ClusterOracle Mysql Server | 21/1/2025 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to… | |
| Modificada | Media (6.5) | 1.1% | — | Oracle Mysql ClusterOracle Mysql Server | 21/1/2025 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL… | |
| Analizada | Alta (8.4) | 0.35% | 💥 PoC | Inspur Clusterengine | 6/1/2025 | 17/6/2026 | An issue was discovered in Inspur ClusterEngine v4.0 that allows attackers to gain escalated Local privileges and execute arbitrary commands via /opt/tsce4/torque6/bin/getJobsByShell. | |
| Aplazada | Alta (7.5) | 0.44% | — | Linuxfoundation Open Cluster ManagementAI | 17/12/2024 | 17/6/2026 | A flaw was found in Open Cluster Management (OCM) when a user has access to the worker nodes which contain the cluster-manager or klusterlet deployments. The cluster-manager deployment uses a service account with the same name "cluster-manager" which is bound to a ClusterRole also named "cluster-manager", which… | |
| Aplazada | Media (4.4) | 0.13% | — | Nvidia Base Command ManagerAIBright Computing Bright Cluster ManagerAI | 6/12/2024 | 17/6/2026 | NVIDIA Base Command Manager and Bright Cluster Manager for Linux contain an insecure temporary file vulnerability. A successful exploit of this vulnerability might lead to denial of service. |