Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
6110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.5) | 0.19% | — | Redhat Advanced Cluster Management FOR KubernetesAI | 18/8/2026 | 5/9/2026 | A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exposes proxy basic-auth credentials in the must-gather archive, potentially… | |
| Pendiente de análisis | Media (5.5) | 0.11% | — | Redhat Advanced Cluster Management FOR KubernetesAI | 18/8/2026 | 5/9/2026 | A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in cleartext in the resulting archive,… | |
| Pendiente de análisis | Alta (7.7) | 0.49% | — | Redhat AWXAI | 18/8/2026 | 25/8/2026 | A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing GitHub pull request webhooks, AWX extracts the status callback URL (pull_request.statuses_url) from the incoming webhook payload without validating the target host against the expected Git provider.… | |
| Pendiente de análisis | Alta (8.8) | 0.81% | — | Redhat Advanced Cluster Management FOR KubernetesAIRedhat Governance Policy Addon ControllerAI | 18/8/2026 | 27/8/2026 | A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with… | |
| Pendiente de análisis | Crítica (9.6) | 0.35% | — | Redhat Ansible Automation PlatformAIHashicorp VaultAI | 18/8/2026 | 24/9/2026 | A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role… | |
| Pendiente de análisis | Crítica (9.1) | 0.91% | — | Redhat Acm-search-v2-rhel9AI | 17/8/2026 | 27/8/2026 | A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or SQL statements. This occurs because the WORK_MEM string provided in the Search CR is not properly validated before… | |
| Pendiente de análisis | Alta (7.9) | 0.70% | — | Redhat Openshift AIAIRedhat OpenshiftAI | 17/8/2026 | 5/10/2026 | A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts are granted cluster-wide permissions that exceed their operational requirements. An attacker who compromises the identity of these ServiceAccounts, either through a remote code execution… | |
| Analizada | Alta (7.1) | 0.24% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing the Quay builder to make requests to internal network addresses. Such an… | |
| Analizada | Alta (7.5) | 0.42% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without proper authorization. While file IDs are complex, they can be intercepted from plaintext email or webhook callbacks. This vulnerability leads to information disclosure,… | |
| Analizada | Alta (7.5) | 0.23% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stripe-Signature header. Successful exploitation can lead to the unauthorized… | |
| Analizada | Alta (8.2) | 0.46% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to the security scanner notification endpoint. This allows the attacker to flood the notification queue and inject path traversal characters into Clair API URL paths.… | |
| Analizada | Media (4.4) | 0.33% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can read the notification configuration, including sensitive details like webhook URLs, Slack tokens, and email addresses. This vulnerability also allows them to… | |
| Analizada | Media (6.5) | 0.31% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the system does not properly escape the username input. This allows an attacker to inject LDAP filter metacharacters, enabling user-existence oracle… | |
| Analizada | Media (5.4) | 0.29% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. These flaws could allow an attacker with a validly-signed token from… | |
| Analizada | Media (4.4) | 0.15% | — | Redhat Openshift Container PlatformRedhat Enterprise Linux | 14/8/2026 | 31/8/2026 | A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution for its clients. | |
| Pendiente de análisis | Media (5.3) | 0.39% | — | Redhat UndertowAI | 14/8/2026 | 14/8/2026 | A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method performs a silent narrowing cast from 16-bit Unicode characters to 8-bit bytes when writing HTTP response header values. A remote attacker can exploit this by supplying specific Unicode characters in… | |
| Analizada | Media (6.5) | 0.33% | — | SambaRedhat Enterprise Linux | 14/8/2026 | 23/9/2026 | A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets containing invalid field lengths, improperly terminated strings, or inconsistent packet sizes to be processed without adequate bounds checking. A… | |
| Modificada | Media (5.5) | 0.16% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 14/8/2026 | 2/10/2026 | A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This… | |
| Pendiente de análisis | Alta (7.1) | 0.35% | — | Redhat Multicluster EngineAIRedhat Clusterclaims ControllerAI | 13/8/2026 | 29/9/2026 | A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable… | |
| Analizada | Media (6.3) | 0.14% | — | Redhat Enterprise Linux | 13/8/2026 | 25/8/2026 | A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an attacker can redirect privileged writes to an arbitrary file during script execution in a… | |
| Analizada | Media (6.3) | 0.13% | — | Redhat Enterprise Linux | 13/8/2026 | 25/8/2026 | A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to an arbitrary file. This can lead to… | |
| Analizada | Media (6.6) | 0.13% | — | Redhat Enterprise Linux | 13/8/2026 | 25/8/2026 | A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially crafted message, the attacker can cause out-of-bounds memory access, leading to the… | |
| Analizada | Media (6.5) | 0.19% | — | Redhat Enterprise Linux | 13/8/2026 | 25/8/2026 | A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local network segment to cause a denial of service. By sending a specially crafted IPv4/UDP DHCP reply, the… | |
| Modificada | Media (6.5) | 0.16% | — | Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client | 12/8/2026 | 5/9/2026 | A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive privilege means that a compromise of the insights-client pod or ServiceAccount… | |
| Pendiente de análisis | Crítica (9) | 1.2% | — | Redhat ACM Search V2 Rhel9AI | 12/8/2026 | 27/8/2026 | A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This allows the attacker to deploy an arbitrary container image across all… |