Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

155 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.9)0.57%—Metal3 Baremetal OperatorAI3/9/202417/6/2026
The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. The `BareMetalHost` (BMH) CRD allows the `userData`, `metaData`, and `networkData` for the provisioned host to be specified as links to Kubernetes Secrets. There are fields for both the `Name` and `Namespace` of the…
AplazadaAlta (8.8)1.4%—Redhat Fence Agents Remediation OperatorAI12/8/202417/6/2026
A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) primitive by supplying an arbitrary command to execute in the --ssh-path/--telnet-path arguments. A low-privilege user, for example, a user with developer access, can create a specially crafted…
AnalizadaCrítica (9.8)0.42%—External-secrets External Secrets Operator24/7/202417/6/2026
Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
ModificadaAlta (8.8)0.41%—Kube-logging Logging-operator24/7/202417/6/2026
Insecure permissions in logging-operator v4.6.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
ModificadaAlta (7.5)0.59%—IBM MQ Operator8/7/202417/6/2026
IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 IBM MQ Container Developer Edition is vulnerable to denial of service caused by incorrect memory de-allocation. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 297172.
ModificadaCrítica (9.8)0.76%—IBM MQ Operator8/7/202417/6/2026
IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string comparison vulnerability. IBM X-Force ID: 297169.
AplazadaAlta (7.5)0.60%—Linbit Piraeus OperatorAI3/5/202417/6/2026
There is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allows an attacker to impersonate the service account bound to this ClusterRole and use its high-risk privileges to list confidential information across the cluster.
AplazadaMedia (6.8)0.69%—Openshift Image Registry OperatorAI1/5/202417/6/2026
An information disclosure flaw was found in OpenShift's internal image registry operator. The AZURE_CLIENT_SECRET can be exposed through an environment variable defined in the pod definition, but is limited to Azure environments. An attacker controlling an account that has high enough permissions to obtain pod…
AnalizadaMedia (6.5)0.84%—Apache Solr Operator12/4/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator. This issue affects all versions of the Apache Solr Operator from 0.3.0 through 0.8.0. When asked to bootstrap Solr security, the operator will enable basic authentication and create several accounts for accessing Solr:…
AnalizadaMedia (6.2)0.89%—Azure ARC Extension Microsoft.azstackhci.operatorAzure ARC Extension Microsoft.azure.hybridnetworkAzure ARC Extension Microsoft.azurekeyvaultsecretsproviderAzure ARC Extension Microsoft.iotoperations.mq+39/4/202417/6/2026
Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability
AnalizadaAlta (7.5)0.26%—IBM MQ Operator3/3/202417/6/2026
IBM MQ Operator 2.0.0 LTS, 2.0.18 LTS, 3.0.0 CD, 3.0.1 CD, 2.4.0 through 2.4.7, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2, and 2.3.0 through 2.3.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 283905.
AnalizadaMedia (5.5)0.12%—IBM MQ Operator3/3/202417/6/2026
IBM MQ Operator 2.0.0 LTS, 2.0.18 LTS, 3.0.0 CD, 3.0.1 CD, 2.4.0 through 2.4.7, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2, and 2.3.0 through 2.3.3 stores or transmits user credentials in plain clear text which can be read by a local user using a trace command. IBM X-Force ID: 272638.
ModificadaMedia (5.9)94%—Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+6418/12/202317/6/2026
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some…
ModificadaAlta (7.1)0.22%—Aveva Batch ManagementAveva Communication DriversAveva EdgeAveva Enterprise Licensing+915/11/202317/6/2026
This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.
ModificadaAlta (7.8)0.24%—Aveva Batch ManagementAveva Communication DriversAveva EdgeAveva Enterprise Licensing+915/11/202317/6/2026
This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine.
ModificadaAlta (7.5)0.60%—Mongodb Atlas Kubernetes Operator7/11/202317/6/2026
The affected versions of MongoDB Atlas Kubernetes Operator may print sensitive information like GCP service account keys and API integration secrets while DEBUG mode logging is enabled. This issue affects MongoDB Atlas Kubernetes Operator versions: 1.5.0, 1.6.0, 1.6.1, 1.7.0. Please note that this is reported on an…
AnalizadaAlta (7.5)100%⚠ Explotación activaSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaAlta (7.8)0.60%—Schneider-electric Ecostruxure Operator Terminal ExpertSchneider-electric Pro-face Blue14/6/202317/6/2026
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI.
ModificadaMedia (5.5)0.19%—Linuxfoundation Baremetal Operator26/4/202317/6/2026
Baremetal Operator (BMO) is a bare metal host provisioning integration for Kubernetes. Prior to version 0.3.0, ironic and ironic-inspector deployed within Baremetal Operator using the included `deploy.sh` store their `.htpasswd` files as ConfigMaps instead of Secrets. This causes the plain-text username and hashed…
ModificadaCrítica (9.8)67%—Fit2cloud Kubeoperator14/1/202317/6/2026
KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In KubeOperator versions 3.16.3 and below, API interfaces with unauthorized entities and can leak sensitive information. This vulnerability could be used to take over the…
ModificadaCrítica (9.8)1.1%—Festo BUS Module Cpx-e-ep FirmwareFesto BUS Node Cpx-fb32 FirmwareFesto BUS Node Cpx-fb33 FirmwareFesto BUS Node Cpx-fb36 Firmware+951/12/202217/6/2026
In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability.
ModificadaAlta (7.8)0.26%—Schneider-electric Ecostruxure Operator Terminal ExpertSchneider-electric Pro-face Blue4/11/202217/6/2026
A CWE-89: Improper Neutralization of Special Elements used in SQL Command (‘SQL Injection’) vulnerability exists that allows adversaries with local user privileges to craft a malicious SQL query and execute as part of project migration which could result in execution of malicious code. Affected Products: EcoStruxure…
ModificadaAlta (7.8)0.20%—Schneider-electric Ecostruxure Operator Terminal ExpertSchneider-electric Pro-face Blue4/11/202217/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load malicious DLL which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal…
ModificadaAlta (7.8)0.11%—Schneider-electric Ecostruxure Operator Terminal ExpertSchneider-electric Pro-face Blue4/11/202217/6/2026
A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load a malicious DLL which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior),…
ModificadaAlta (7.8)0.21%—Schneider-electric Ecostruxure Operator Terminal ExpertSchneider-electric Pro-face Blue4/11/202217/6/2026
A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local user privileges to load a project file from an adversary-controlled network share which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face…