Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
255 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.81% | — | Maxfoundry Wp-paginate | 28/2/2022 | 17/6/2026 | The WP-Paginate WordPress plugin before 2.1.4 does not sanitise and escape its preset settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed | |
| Modificada | Media (5.7) | 0.32% | 💥 PoC | Edgexfoundry APP Service ConfigurableEdgexfoundry Application Functions Software Development KITEdgexfoundry Edgex Foundry | 19/11/2021 | 17/6/2026 | Functions SDK for EdgeX is meant to provide all the plumbing necessary for developers to get started in processing/transforming/exporting data out of the EdgeX IoT platform. In affected versions broken encryption in app-functions-sdk “AES” transform in EdgeX Foundry releases prior to Jakarta allows attackers to… | |
| Modificada | Alta (7.5) | 1.0% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deployment | 27/10/2021 | 17/6/2026 | Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthenticated attackers to cause denial of service by using REST HTTP requests with label_selectors on multiple V3 endpoints by generating an enormous SQL query. | |
| Modificada | Media (6.1) | 0.71% | — | Cloudfoundry Cf-deploymentCloudfoundry User Account AND Authentication | 11/8/2021 | 17/6/2026 | UAA server versions prior to 75.4.0 are vulnerable to an open redirect vulnerability. A malicious user can exploit the open redirect vulnerability by social engineering leading to take over of victims’ accounts in certain cases along with redirection of UAA users to a malicious sites. | |
| Modificada | Alta (7.5) | 0.99% | — | Cloudfoundry Cf-deploymentCloudfoundry User Account AND Authentication | 22/7/2021 | 17/6/2026 | In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an identity provider( IdP) of type “oauth 1.0” was sent to UAA server. | |
| Modificada | Media (6.5) | 0.80% | — | Edgexfoundry Edgex Foundry | 9/7/2021 | 17/6/2026 | EdgeX Foundry is an open source project for building a common open framework for internet-of-things edge computing. A vulnerability exists in the Edinburgh, Fuji, Geneva, and Hanoi versions of the software. When the EdgeX API gateway is configured for OAuth2 authentication and a proxy user is created, the client_id… | |
| Modificada | Media (6.5) | 0.84% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deployment | 8/4/2021 | 17/6/2026 | Cloud Controller API versions prior to 1.106.0 logs service broker credentials if the default value of db logging config field is changed. CAPI database logs service broker password in plain text whenever a job to clean up orphaned items is run by Cloud Controller. | |
| Modificada | Alta (7.5) | 1.1% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deployment | 2/12/2020 | 17/6/2026 | CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicious attacker can send specially-crafted YAML files to certain endpoints, causing the YAML parser to consume excessive CPU and RAM. | |
| Modificada | Media (6.5) | 0.92% | — | Cloud Foundry Bosh System Metrics Server | 2/10/2020 | 17/6/2026 | BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details). | |
| Modificada | Alta (7.7) | 1.2% | — | Cloudfoundry Cf-deploymentCloudfoundry Gorouter | 3/9/2020 | 17/6/2026 | Cloud Foundry Routing (Gorouter) versions prior to 0.206.0 allow a malicious developer with "cf push" access to cause denial-of-service to the CF cluster by pushing an app that returns specially crafted HTTP responses that crash the Gorouters. | |
| Modificada | Media (4.3) | 0.57% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deployment | 3/9/2020 | 17/6/2026 | Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controller.read" scope, but no roles in any spaces, to list all droplets in all spaces (whereas they should see none). | |
| Modificada | Alta (8.8) | 0.99% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deployment | 21/8/2020 | 17/6/2026 | Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where an app domain is also the system domain (which is true in the default CF Deployment manifest), were vulnerable to developers maliciously or accidentally claiming certain sensitive routes, potentially resulting in the… | |
| Modificada | Media (6.5) | 1.2% | — | Cloudfoundry Cf-deploymentCloudfoundry Routing-release | 21/8/2020 | 17/6/2026 | Cloud Foundry Routing (Gorouter), versions prior to 0.204.0, when used in a deployment with NGINX reverse proxies in front of the Gorouters, is potentially vulnerable to denial-of-service attacks in which an unauthenticated malicious attacker can send specially-crafted HTTP requests that may cause the Gorouters to be… | |
| Modificada | Media (5.9) | 2.9% | — | Golang GOCloudfoundry Cf-deploymentCloudfoundry Routing-releaseDebian Linux+2 | 17/7/2020 | 17/6/2026 | Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.ReverseProxy Handler, because it reads a request body and writes a response at the same time. | |
| Modificada | Alta (8.8) | 0.49% | — | Cloudfoundry Cf-deploymentCloudfoundry User Account AND Authentication | 27/2/2020 | 17/6/2026 | In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers. | |
| Modificada | Media (5.3) | 1.0% | — | Cloudfoundry Routing Release | 27/2/2020 | 17/6/2026 | Cloud Foundry Routing Release, versions prior to 0.197.0, contains GoRouter, which allows malicious clients to send invalid headers, causing caching layers to reject subsequent legitimate clients trying to access the app. | |
| Modificada | Media (6.5) | 0.75% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deployment | 27/2/2020 | 17/6/2026 | Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive information such as credentials if provided to the job. A malicious user with access to those logs may gain unauthorized access to resources protected by such credentials. | |
| Modificada | Alta (7.4) | 0.53% | — | Cloudfoundry CredhubPivotal Software Cloud Foundry Cf-deployment | 12/2/2020 | 17/6/2026 | Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with access to the network between CredHub and its MySQL database may eavesdrop on database connections and thereby gain unauthorized access to CredHub and other components. | |
| Modificada | Media (4.3) | 0.78% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deployment | 19/12/2019 | 17/6/2026 | Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins. | |
| Modificada | Media (6.5) | 1.3% | — | Cloudfoundry Cf-deploymentCloudfoundry User Account AND Authentication | 6/12/2019 | 17/6/2026 | Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter. A remote authenticated malicious user could gain access to user credentials via the uaa.log file if authentication is provided via query parameters. | |
| Modificada | Alta (7.5) | 1.3% | — | Cloudfoundry Cf-deploymentCloudfoundry User Account AND Authentication | 26/11/2019 | 17/6/2026 | Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well. | |
| Modificada | Alta (8.6) | 1.5% | — | Cloudfoundry Cf-deploymentCloudfoundry Routing-release | 19/11/2019 | 17/6/2026 | Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HTTP route service request using an invalid nonce that will cause the Gorouter to crash. | |
| Modificada | Alta (8.8) | 1.5% | — | Cloudfoundry Cf-deploymentPivotal Software Cloud Foundry SMB Volume | 23/10/2019 | 17/6/2026 | Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for volumes that have been recently created, allowing the user to take control of the SMB Volume. | |
| Modificada | Media (4.3) | 1.1% | — | Cloudfoundry Cf-deploymentPivotal Software Cloud Foundry UAA | 23/10/2019 | 17/6/2026 | Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote authenticated malicious user with scim.invite scope can craft a request with malicious content which can leak information about users of the UAA. | |
| Modificada | Alta (8.8) | 1.3% | — | Cloudfoundry UAA Release | 26/9/2019 | 17/6/2026 | CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their own privileges to any scope, allowing them to take control of UAA and the resources it controls. |