Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

123 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.32%—Redislabs Redis1/11/201916/6/2026
Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.
ModificadaMedia (5.5)0.41%—Redislabs Redis1/11/201916/6/2026
Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.
ModificadaCrítica (9.8)3.2%—Redis Wrapper Project Redis Wrapper5/10/201917/6/2026
Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute arbitrary scripts.
ModificadaAlta (7.8)2.1%—Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+515/8/201917/6/2026
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
ModificadaAlta (7.2)24%—Redislabs RedisRedhat OpenstackRedhat Enterprise LinuxRedhat Enterprise Linux EUS+511/7/201917/6/2026
A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRANGE command, an attacker could cause Redis to perform controlled increments of up to 12 bytes past the end of a…
ModificadaAlta (7.2)26%—Redislabs RedisRedhat OpenstackRedhat Software CollectionsRedhat Enterprise Linux+611/7/201917/6/2026
A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog using the SETRANGE command, an attacker could trick Redis interpretation of dense HLL encoding to write up to 3 bytes beyond…
ModificadaCrítica (9.8)7.0%—Redislabs RedisDebian LinuxOracle Communications Operations MonitorRedhat Openstack17/6/201817/6/2026
An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading to a failure of bounds checking.
ModificadaCrítica (9.8)59%💥 ExploitRedislabs RedisDebian LinuxOracle Communications Operations MonitorRedhat Openstack17/6/201817/6/2026
Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.
ModificadaAlta (8.4)2.7%💥 ExploitRedislabs Redis17/6/201817/6/2026
Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to higher privileges via a crafted command line. NOTE: It is unclear whether there are any common situations in which redis-cli is used with, for example, a -h (aka hostname) argument…
ModificadaAlta (7.5)24%💥 ExploitRedislabs Redis16/6/201817/6/2026
Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-service via an XGROUP command in which the key is not a stream.
ModificadaAlta (8.1)1.7%—Cloudpub-redis Project Cloudpub-redis4/6/201817/6/2026
cloudpub-redis is a module for CloudPub: Redis Backend cloudpub-redis downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or…
ModificadaAlta (8.1)1.8%—Redis-srvr Project Redis-srvr4/6/201817/6/2026
redis-srvr is a npm wrapper for redis-server. redis-srvr downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in…
ModificadaCrítica (9.8)2.0%—Redis-store17/11/201717/6/2026
Redis-store <=v1.3.0 allows unsafe objects to be loaded from redis
ModificadaAlta (7.4)2.1%—Redislabs Redis24/10/201717/6/2026
networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).
ModificadaCrítica (9.8)1.8%—Redislabs Redis6/10/201717/6/2026
The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and application crash) or possibly have unspecified other impact by leveraging "limited access to the machine."
ModificadaCrítica (9.8)15%—Redislabs Redis28/10/201617/6/2026
A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent. An out of bounds write vulnerability exists in the handling of the client-output-buffer-limit option during the CONFIG SET command for the Redis data structure store. A crafted CONFIG SET command can lead to…
ModificadaBaja (3.3)0.48%—Redislabs RedisDebian Linux10/8/201617/6/2026
linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .rediscli_history, which allows local users to obtain sensitive information by reading the file.
ModificadaAlta (7.5)4.6%—Redislabs RedisDebian LinuxOpensuse LeapOpensuse+113/4/201617/6/2026
Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a…
ModificadaAlta (10)9.5%—Redislabs RedisDebian Linux9/6/201517/6/2026
Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.
ModificadaAlta (10)6.6%—Symantec Veritas Dynamic Multi-pathingSymantec Veritas Storage FoundationSymantec Veritas Storage Foundation Cluster File System FOR Oracle RACSymantec Netbackup Puredisk19/8/201116/6/2026
Multiple integer overflows in vxsvc.exe in the Veritas Enterprise Administrator service in Symantec Veritas Storage Foundation 5.1 and earlier, Veritas Storage Foundation Cluster File System (SFCFS) 5.1 and earlier, Veritas Storage Foundation Cluster File System Enterprise for Oracle RAC (SFCFSORAC) 5.1 and earlier,…
ModificadaAlta (7.5)14%💥 ExploitAcutecp.rediscussed Acutecp6/4/200916/6/2026
SQL injection vulnerability in login.php in Acute Control Panel 1.0.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.
ModificadaAlta (9)2.9%—Symantec Veritas Netbackup Puredisk Remote Office Edition18/8/200616/6/2026
Symantec Veritas NetBackup PureDisk Remote Office Edition 6.0 before MP1 20060816 allows remote attackers to bypass authentication and gain privileges via unknown attack vectors in the management interface.
ModificadaAlta (7.5)2.4%—Picturedis PhotoalbumPicturedis Professional19/6/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in PictureDis Professional 1.33 Build 234 and earlier and PictureDis Photoalbum 4.82 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to files in photoalbum/ including (1) thumstbl.php, (2) wpfiles.php, and (3)…
Orbitaley — Vulnerabilidades