Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9) | 1.3% | — | Microsoft Azure Kubernetes Service | 13/2/2024 | 10/8/2026 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | |
| Modificada | Crítica (9) | 1.2% | — | Microsoft Azure Kubernetes Service | 13/2/2024 | 10/8/2026 | Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability | |
| Modificada | Media (6.5) | 0.39% | — | Apache AirflowApache-airflow-providers-cncf-kubernetes | 24/1/2024 | 2/7/2026 | Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metadata without any encryption. Additionally, if used with an Airflow version… | |
| Modificada | Alta (7.5) | 1.4% | — | F5 Big-ip NextF5 Big-ip Next Service Proxy FOR KubernetesF5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Local Traffic Manager+2 | 21/11/2023 | 17/6/2026 | The BGP daemon (bgpd) in IP Infusion ZebOS through 7.10.6 allow remote attackers to cause a denial of service by sending crafted BGP update messages containing a malformed attribute. | |
| Analizada | Alta (8.8) | 4.3% | — | KubernetesFedoraproject Fedora | 14/11/2023 | 17/6/2026 | A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they are using an in-tree storage plugin for Windows nodes. | |
| Modificada | Alta (7.5) | 0.60% | — | Mongodb Atlas Kubernetes Operator | 7/11/2023 | 17/6/2026 | The affected versions of MongoDB Atlas Kubernetes Operator may print sensitive information like GCP service account keys and API integration secrets while DEBUG mode logging is enabled. This issue affects MongoDB Atlas Kubernetes Operator versions: 1.5.0, 1.6.0, 1.6.1, 1.7.0. Please note that this is reported on an… | |
| Modificada | Alta (8.2) | 2.5% | 💥 PoC | Kubernetes Apiserver | 3/11/2023 | 17/6/2026 | A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties. | |
| Analizada | Alta (8.8) | 2.5% | — | Kubernetes CSI Proxy | 3/11/2023 | 17/6/2026 | A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running kubernetes-csi-proxy. | |
| Modificada | Alta (8.8) | 4.0% | — | Kubernetes | 31/10/2023 | 17/6/2026 | A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. | |
| Modificada | Alta (8.8) | 13% | — | Kubernetes | 31/10/2023 | 17/6/2026 | A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. | |
| Modificada | Media (6.3) | 0.92% | — | Kubernetes | 30/10/2023 | 17/6/2026 | Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*].port”) as a LoadBalancer Service when the LoadBalancer controller does not set the “status.loadBalancer.ingress[].ip” field. Clusters where the LoadBalancer controller sets the… | |
| Modificada | Media (5.3) | 0.42% | — | Elastic Cloud ON Kubernetes | 26/10/2023 | 17/6/2026 | Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment. | |
| Modificada | Alta (8.8) | 57% | 💥 PoC | Kubernetes Ingress-nginx | 25/10/2023 | 17/6/2026 | Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation. | |
| Modificada | Alta (8.8) | 2.2% | 💥 PoC | Kubernetes Ingress-nginx | 25/10/2023 | 17/6/2026 | Ingress nginx annotation injection causes arbitrary command execution. | |
| Modificada | Media (6.5) | 1.6% | — | Kubernetes Ingress-nginx | 25/10/2023 | 17/6/2026 | Ingress-nginx `path` sanitization can be bypassed with `log_format` directive. | |
| Modificada | Alta (8.8) | 0.58% | — | Kubernetes Operations | 12/10/2023 | 17/6/2026 | Privilege Escalation in kOps using GCE/GCP Provider in Gossip Mode. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (7.4) | 0.38% | — | F5 Big-ip Next Service Proxy FOR Kubernetes | 10/10/2023 | 17/6/2026 | The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacker with the ability to intercept traffic to impersonate the SPK Secure Shell (SSH) server on those containers. This is only exposed when ssh debug is enabled. Note:… | |
| Modificada | Alta (7.5) | 0.54% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+16 | 10/10/2023 | 17/6/2026 | When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, and an iRule using the HTTP_REQUEST event or Local Traffic Policy are associated with the virtual server, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical… | |
| Modificada | Alta (7.5) | 0.48% | — | Redhat Advanced Cluster Management FOR KubernetesRedhat Openshift Container Platform | 5/10/2023 | 17/6/2026 | A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the boundaries, as permissions will not be applied. | |
| Modificada | Alta (7.8) | 0.29% | — | Kubernetes Cri-oRedhat Openshift Container Platform FOR Arm64Redhat Openshift Container Platform FOR LinuxoneRedhat Openshift Container Platform FOR Power+3 | 25/9/2023 | 17/6/2026 | A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable. | |
| Modificada | Alta (8) | 1.6% | — | Kubernetes Kube-apiserverRedhat Openshift Container Platform | 24/9/2023 | 17/6/2026 | An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already… | |
| Modificada | Media (5.3) | 0.21% | — | Kubernetes Cri-oRedhat Openshift Container Platform | 15/9/2023 | 17/6/2026 | The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing the fix for CVE-2022-27652, which was previously fixed in OCP 4.9.41 and 4.10.12 via RHBA-2022:5433… | |
| Modificada | Crítica (9.8) | 2.7% | — | Microsoft Azure Kubernetes Service | 12/9/2023 | 17/6/2026 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | |
| Modificada | Media (6.5) | 2.2% | 💥 PoC | Kubernetes | 3/7/2023 | 17/6/2026 | Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are… |