Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
123 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.32% | — | Redislabs Redis | 1/11/2019 | 16/6/2026 | Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds. | |
| Modificada | Media (5.5) | 0.41% | — | Redislabs Redis | 1/11/2019 | 16/6/2026 | Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm. | |
| Modificada | Crítica (9.8) | 3.2% | — | Redis Wrapper Project Redis Wrapper | 5/10/2019 | 17/6/2026 | Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute arbitrary scripts. | |
| Modificada | Alta (7.8) | 2.1% | — | Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+51 | 5/8/2019 | 17/6/2026 | CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials. | |
| Modificada | Alta (7.2) | 24% | — | Redislabs RedisRedhat OpenstackRedhat Enterprise LinuxRedhat Enterprise Linux EUS+5 | 11/7/2019 | 17/6/2026 | A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRANGE command, an attacker could cause Redis to perform controlled increments of up to 12 bytes past the end of a… | |
| Modificada | Alta (7.2) | 26% | — | Redislabs RedisRedhat OpenstackRedhat Software CollectionsRedhat Enterprise Linux+6 | 11/7/2019 | 17/6/2026 | A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog using the SETRANGE command, an attacker could trick Redis interpretation of dense HLL encoding to write up to 3 bytes beyond… | |
| Modificada | Crítica (9.8) | 7.0% | — | Redislabs RedisDebian LinuxOracle Communications Operations MonitorRedhat Openstack | 17/6/2018 | 17/6/2026 | An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading to a failure of bounds checking. | |
| Modificada | Crítica (9.8) | 59% | 💥 Exploit | Redislabs RedisDebian LinuxOracle Communications Operations MonitorRedhat Openstack | 17/6/2018 | 17/6/2026 | Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows. | |
| Modificada | Alta (8.4) | 2.7% | 💥 Exploit | Redislabs Redis | 17/6/2018 | 17/6/2026 | Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to higher privileges via a crafted command line. NOTE: It is unclear whether there are any common situations in which redis-cli is used with, for example, a -h (aka hostname) argument… | |
| Modificada | Alta (7.5) | 24% | 💥 Exploit | Redislabs Redis | 16/6/2018 | 17/6/2026 | Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-service via an XGROUP command in which the key is not a stream. | |
| Modificada | Alta (8.1) | 1.7% | — | Cloudpub-redis Project Cloudpub-redis | 4/6/2018 | 17/6/2026 | cloudpub-redis is a module for CloudPub: Redis Backend cloudpub-redis downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or… | |
| Modificada | Alta (8.1) | 1.8% | — | Redis-srvr Project Redis-srvr | 4/6/2018 | 17/6/2026 | redis-srvr is a npm wrapper for redis-server. redis-srvr downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in… | |
| Modificada | Crítica (9.8) | 2.0% | — | Redis-store | 17/11/2017 | 17/6/2026 | Redis-store <=v1.3.0 allows unsafe objects to be loaded from redis | |
| Modificada | Alta (7.4) | 2.1% | — | Redislabs Redis | 24/10/2017 | 17/6/2026 | networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port). | |
| Modificada | Crítica (9.8) | 1.8% | — | Redislabs Redis | 6/10/2017 | 17/6/2026 | The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and application crash) or possibly have unspecified other impact by leveraging "limited access to the machine." | |
| Modificada | Crítica (9.8) | 15% | — | Redislabs Redis | 28/10/2016 | 17/6/2026 | A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent. An out of bounds write vulnerability exists in the handling of the client-output-buffer-limit option during the CONFIG SET command for the Redis data structure store. A crafted CONFIG SET command can lead to… | |
| Modificada | Baja (3.3) | 0.48% | — | Redislabs RedisDebian Linux | 10/8/2016 | 17/6/2026 | linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .rediscli_history, which allows local users to obtain sensitive information by reading the file. | |
| Modificada | Alta (7.5) | 4.6% | — | Redislabs RedisDebian LinuxOpensuse LeapOpensuse+1 | 13/4/2016 | 17/6/2026 | Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a… | |
| Modificada | Alta (10) | 9.5% | — | Redislabs RedisDebian Linux | 9/6/2015 | 17/6/2026 | Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command. | |
| Modificada | Alta (10) | 6.6% | — | Symantec Veritas Dynamic Multi-pathingSymantec Veritas Storage FoundationSymantec Veritas Storage Foundation Cluster File System FOR Oracle RACSymantec Netbackup Puredisk | 19/8/2011 | 16/6/2026 | Multiple integer overflows in vxsvc.exe in the Veritas Enterprise Administrator service in Symantec Veritas Storage Foundation 5.1 and earlier, Veritas Storage Foundation Cluster File System (SFCFS) 5.1 and earlier, Veritas Storage Foundation Cluster File System Enterprise for Oracle RAC (SFCFSORAC) 5.1 and earlier,… | |
| Modificada | Alta (7.5) | 14% | 💥 Exploit | Acutecp.rediscussed Acutecp | 6/4/2009 | 16/6/2026 | SQL injection vulnerability in login.php in Acute Control Panel 1.0.0 allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Alta (9) | 2.9% | — | Symantec Veritas Netbackup Puredisk Remote Office Edition | 18/8/2006 | 16/6/2026 | Symantec Veritas NetBackup PureDisk Remote Office Edition 6.0 before MP1 20060816 allows remote attackers to bypass authentication and gain privileges via unknown attack vectors in the management interface. | |
| Modificada | Alta (7.5) | 2.4% | — | Picturedis PhotoalbumPicturedis Professional | 19/6/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in PictureDis Professional 1.33 Build 234 and earlier and PictureDis Photoalbum 4.82 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to files in photoalbum/ including (1) thumstbl.php, (2) wpfiles.php, and (3)… |