Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 99% | 💥 Exploit | Kubernetes Ingress NginxAI | 25/3/2025 | 17/6/2026 | A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default… | |
| Aplazada | Alta (8.8) | 82% | 💥 Exploit | Kubernetes Ingress-nginxAI | 25/3/2025 | 17/6/2026 | A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mirror-host` Ingress annotations can be used to inject arbitrary configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure… | |
| Aplazada | Alta (8.8) | 33% | 💥 Exploit | Kubernetes Ingress-nginxAI | 25/3/2025 | 17/6/2026 | A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to… | |
| Aplazada | Baja (3.1) | 0.31% | — | KubernetesAI | 20/3/2025 | 17/6/2026 | A security issue was discovered in Kubernetes where a malicious or compromised pod could bypass network restrictions enforced by network policies during namespace deletion. The order in which objects are deleted during namespace termination is not defined, and it is possible for network policies to be deleted before… | |
| Aplazada | Media (6.5) | 0.70% | — | KubernetesAI | 13/3/2025 | 17/6/2026 | This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using this feature remains vulnerable. | |
| Aplazada | Media (6.2) | 0.37% | — | KubernetesAI | 13/2/2025 | 17/6/2026 | A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet read-only HTTP endpoint may cause a Node Denial of Service by filling the Node's disk. | |
| Aplazada | Alta (8.1) | 0.26% | — | Crowdstrike Falcon Sensor FOR LinuxAICrowdstrike Falcon Kubernetes Admission ControllerAICrowdstrike Falcon Container SensorAI | 12/2/2025 | 17/6/2026 | CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the CrowdStrike cloud. CrowdStrike has identified a validation logic error in the Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor where our TLS connection… | |
| Analizada | Alta (8.7) | 0.41% | — | F5 Big-ip Next Service Proxy FOR KubernetesF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+8 | 5/2/2025 | 17/6/2026 | When SIP Session and Router ALG profiles are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Aplazada | Media (6.6) | 0.24% | — | Kubernetes Cri-oAI | 28/1/2025 | 17/6/2026 | A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths, leading to node-level denial of service by unmounting critical system directories. | |
| Aplazada | Media (6.5) | 0.35% | — | Octopus Kubernetes WorkerAIOctopus Kubernetes AgentAI | 16/1/2025 | 17/6/2026 | In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in clear-text. This was identified in Version 2 however it was determined that this could also be achieved in Version 1 and the fix was applied to both versions accordingly. | |
| Aplazada | Alta (7.4) | 0.75% | — | Kubernetes Cri-oAI | 26/11/2024 | 21/8/2026 | A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore it. When it does that restoration, it attempts to restore the mounts from the restore archive instead of the pod request. As a result, the validations run on the pod spec, verifying… | |
| Aplazada | Alta (8.1) | 3.0% | 💥 PoC | Kubernetes KubeletAI | 22/11/2024 | 17/6/2026 | The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11, from 1.29.0 through 1.29.6, from 1.30.0 through 1.30.2. | |
| Aplazada | Alta (7.7) | 0.59% | — | Kubernetes Kube-controller-managerAI | 17/11/2024 | 17/6/2026 | A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp block causes a denial of service due to KCM pods going into restart churn. | |
| Analizada | Alta (8.1) | 1.7% | — | Kubernetes-sigs Image Builder | 15/10/2024 | 17/6/2026 | A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process when using the Nutanix, OVA, QEMU or raw providers. The credentials can be used to gain root access. The credentials are disabled at the conclusion of the image build… | |
| Analizada | Crítica (9.8) | 2.2% | — | Kubernetes-sigs Image Builder | 15/10/2024 | 17/6/2026 | A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and nodes using the resulting images may be accessible via these… | |
| Aplazada | Alta (8.8) | 1.1% | — | KubernetesAI | 20/8/2024 | 17/6/2026 | Prior to 3385, the user-controlled role parameter enters the application in the Kubernetes::RoleVerificationsController. The role parameter flows into the RoleConfigFile initializer and then into the Kubernetes::Util.parse_file method where it is unsafely deserialized using the YAML.load_stream method. This issue may… | |
| Aplazada | Alta (8.8) | 27% | 💥 PoC | Kubernetes Ingress NginxAI | 16/8/2024 | 17/6/2026 | A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `extensions` API group) can bypass annotation validation to inject arbitrary commands and obtain the credentials of the ingress-nginx controller. In the default configuration, that… | |
| Analizada | Alta (8.2) | 0.44% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+19 | 14/8/2024 | 17/6/2026 | When TCP profile with Multipath TCP enabled (MPTCP) is configured on a Virtual Server, undisclosed traffic along with conditions beyond the attackers control can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Aplazada | Media (6.1) | 0.31% | — | KubernetesAI | 18/7/2024 | 17/6/2026 | A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may be able to modify container logs. | |
| Modificada | Alta (8.1) | 1.2% | — | Kubernetes Cri-oRedhat Openshift Container Platform | 12/6/2024 | 21/8/2026 | A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system. | |
| Aplazada | Media (5.1) | 0.21% | — | Fluxcd Source-controllerAIKubernetesAI | 15/5/2024 | 17/6/2026 | The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. The source-controller implements the source.toolkit.fluxcd.io API and is a core component of the GitOps toolkit. Prior to version 1.2.5, when… | |
| Aplazada | Alta (7.2) | 1.4% | — | Kubernetes Cri-oAI | 26/4/2024 | 24/8/2026 | A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system. | |
| Aplazada | Baja (2.7) | 2.2% | 💥 PoC | KubernetesAI | 22/4/2024 | 17/6/2026 | A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a… | |
| Analizada | Crítica (9) | 18% | — | Microsoft Azure Kubernetes Service Confidential Containers | 9/4/2024 | 17/6/2026 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.5) | 0.52% | — | F5 Big-ip Access Policy ManagerF5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+9 | 14/2/2024 | 17/6/2026 | When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated |