Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

174 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.0%—Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA24/10/201717/6/2026
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact via vectors involving emails with password recovery links, aka "Cross Domain Referer Leakage."
ModificadaCrítica (9.8)1.2%—Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA24/10/201717/6/2026
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire password reset links.
ModificadaCrítica (9.8)1.2%—Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA24/10/201717/6/2026
The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire existing sessions.
ModificadaAlta (8.8)0.76%—Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA24/10/201717/6/2026
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks on PWS and log a user into an arbitrary account by leveraging lack of CSRF checks.
ModificadaAlta (7.8)1.2%—Cloudfoundry Cf-releasePivotal Capi-release4/10/201717/6/2026
In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-8033 introduces an API regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially crafted application.…
ModificadaMedia (6.1)0.78%—Cloudfoundry Cf-releasePivotal Routing-release4/10/201717/6/2026
In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to append a combination of characters to the URL that will allow for an open redirect. An attacker could exploit this as a phishing attack to gain access to user…
ModificadaMedia (6.1)0.88%—Vmware Single Sign-on FOR Pivotal Cloud Foundry9/9/201717/6/2026
In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, a user can execute a XSS attack on certain Single Sign-On service UI pages by inputting code in the text field for an organization name.
ModificadaMedia (6.5)1.1%—Vmware Single Sign-on FOR Pivotal Cloud Foundry9/9/201717/6/2026
In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, an XXE (XML External Entity) attack was discovered in the Single Sign-On service dashboard. Privileged users can in some cases upload malformed XML leading to exposure of data on the Single Sign-On…
ModificadaAlta (8.8)1.2%—Cloudfoundry Cf-releaseCloudfoundry User Account AND AuthenticationCloudfoundry Uaa-releasePivotal Elastic Runtime7/9/201717/6/2026
The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations…
ModificadaMedia (6.6)0.88%—Pivotal Software Cloud Foundry UAACloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry CF10/7/201717/6/2026
In Cloud Foundry cf-release versions prior to v264; UAA release all versions of UAA v2.x.x, 3.6.x versions prior to v3.6.13, 3.9.x versions prior to v3.9.15, 3.20.x versions prior to v3.20.0, and other versions prior to v4.4.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.17, 24.x versions prior to…
ModificadaAlta (7.5)1.1%—Cloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry CFPivotal Software Cloud Foundry UAA13/6/201717/6/2026
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v263; UAA release 2.x versions prior to v2.7.4.18, 3.6.x versions prior to v3.6.12, 3.9.x versions prior to v3.9.14, and other versions prior to v4.3.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.16, 24.x versions prior…
ModificadaCrítica (9.8)1.2%—Cloudfoundry Cf-releaseCloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry UAA13/6/201717/6/2026
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v261; UAA release 2.x versions prior to v2.7.4.17, 3.6.x versions prior to v3.6.11, 3.9.x versions prior to v3.9.13, and other versions prior to v4.2.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.15, 24.x versions prior…
ModificadaAlta (7.2)0.94%—Cloudfoundry Cf-releaseCloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry UAA13/6/201717/6/2026
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v260; UAA release 2.x versions prior to v2.7.4.16, 3.6.x versions prior to v3.6.10, 3.9.x versions prior to v3.9.12, and other versions prior to v3.17.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.14, 24.x versions…
ModificadaAlta (7.5)0.82%—Pivotal PCF Tile Generator13/6/201717/6/2026
An issue was discovered in Pivotal PCF Tile Generator versions prior to 6.0.0. Tiles created by the PCF Tile Generator create a running open security group that overrides security groups set by the operator.
ModificadaMedia (6.5)0.97%—Cloudfoundry Cf-releaseCloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry UAA13/6/201717/6/2026
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v258; UAA release 2.x versions prior to v2.7.4.15, 3.6.x versions prior to v3.6.9, 3.9.x versions prior to v3.9.11, and other versions prior to v3.16.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.13, 24.x versions prior…
ModificadaAlta (8.8)1.1%—Cloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry CFPivotal Software Cloud Foundry UAA13/6/201717/6/2026
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x versions prior to v3.6.8, 3.9.x versions prior to v3.9.10, and other versions prior to v3.15.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.12, 24.x versions prior…
ModificadaAlta (7.5)1.1%—Cloudfoundry Cf-releaseCloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry UAA13/6/201717/6/2026
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x versions prior to v3.6.8, 3.9.x versions prior to v3.9.10, and other versions prior to v3.15.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.12, 24.x versions prior…
ModificadaMedia (6.1)1.9%—Broadcom Rabbitmq ServerPivotal Software RabbitmqDebian Linux13/6/201717/6/2026
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable…
ModificadaAlta (7.8)0.37%—Broadcom Rabbitmq ServerPivotal Software RabbitmqDebian Linux13/6/201717/6/2026
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. RabbitMQ management UI stores signed-in user credentials in…
ModificadaMedia (6.1)3.3%—Broadcom Rabbitmq ServerPivotal Software RabbitmqDebian Linux13/6/201717/6/2026
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable…
ModificadaAlta (8.1)0.90%—Pivotal Software Cloud Foundry Cf-releasePivotal Software Cloud Foundry UAAPivotal Software Cloud Foundry Uaa-release13/6/201717/6/2026
An issue was discovered in Cloud Foundry Foundation Cloud Foundry release v252 and earlier versions, UAA stand-alone release v2.0.0 - v2.7.4.12 & v3.0.0 - v3.11.0, and UAA bosh release v26 & earlier versions. UAA is vulnerable to session fixation when configured to authenticate against external SAML or OpenID Connect…
ModificadaAlta (8.8)1.3%—Pivotal Software Cloud Foundry Elastic Runtime13/6/201717/6/2026
An issue was discovered in Pivotal PCF Elastic Runtime 1.8.x versions prior to 1.8.29 and 1.9.x versions prior to 1.9.7. Pivotal Cloud Foundry deployments using the Pivotal Account application are vulnerable to a flaw which allows an authorized user to take over the account of another user, causing account lockout and…
ModificadaCrítica (9.8)1.4%—Pivotal Software Cloud Foundry Elastic Runtime13/6/201717/6/2026
An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.65, 1.7.x versions prior to 1.7.48, 1.8.x versions prior to 1.8.28, and 1.9.x versions prior to 1.9.5. Several credentials were present in the logs for the Notifications errand in the PCF Elastic Runtime tile.
ModificadaCrítica (9.8)2.1%—Pivotal Software Cloud Foundry Elastic Runtime13/6/201717/6/2026
An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.60, 1.7.x versions prior to 1.7.41, 1.8.x versions prior to 1.8.23, and 1.9.x versions prior to 1.9.1. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other users in multiple…
ModificadaAlta (7.5)2.9%—Pivotal Software Spring FrameworkVmware Spring FrameworkVmware Spring Security25/5/201717/6/2026
Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for mapping requests to controllers respectively. Differences in the strictness of the pattern matching mechanisms, for example with regards to space trimming in path…
Orbitaley — Vulnerabilidades