Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

276 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9)1.3%—Microsoft Azure Kubernetes Service13/2/202410/8/2026
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
ModificadaCrítica (9)1.2%—Microsoft Azure Kubernetes Service13/2/202410/8/2026
Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability
ModificadaMedia (6.5)0.39%—Apache AirflowApache-airflow-providers-cncf-kubernetes24/1/20242/7/2026
Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metadata without any encryption. Additionally, if used with an Airflow version…
ModificadaAlta (7.5)1.4%—F5 Big-ip NextF5 Big-ip Next Service Proxy FOR KubernetesF5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Local Traffic Manager+221/11/202317/6/2026
The BGP daemon (bgpd) in IP Infusion ZebOS through 7.10.6 allow remote attackers to cause a denial of service by sending crafted BGP update messages containing a malformed attribute.
AnalizadaAlta (8.8)4.3%—KubernetesFedoraproject Fedora14/11/202317/6/2026
A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they are using an in-tree storage plugin for Windows nodes.
ModificadaAlta (7.5)0.60%—Mongodb Atlas Kubernetes Operator7/11/202317/6/2026
The affected versions of MongoDB Atlas Kubernetes Operator may print sensitive information like GCP service account keys and API integration secrets while DEBUG mode logging is enabled. This issue affects MongoDB Atlas Kubernetes Operator versions: 1.5.0, 1.6.0, 1.6.1, 1.7.0. Please note that this is reported on an…
ModificadaAlta (8.2)2.5%💥 PoCKubernetes Apiserver3/11/202317/6/2026
A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.
AnalizadaAlta (8.8)2.5%—Kubernetes CSI Proxy3/11/202317/6/2026
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running kubernetes-csi-proxy.
ModificadaAlta (8.8)4.0%—Kubernetes31/10/202317/6/2026
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.
ModificadaAlta (8.8)13%—Kubernetes31/10/202317/6/2026
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.
ModificadaMedia (6.3)0.92%—Kubernetes30/10/202317/6/2026
Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*].port”) as a LoadBalancer Service when the LoadBalancer controller does not set the “status.loadBalancer.ingress[].ip” field. Clusters where the LoadBalancer controller sets the…
ModificadaMedia (5.3)0.42%—Elastic Cloud ON Kubernetes26/10/202317/6/2026
Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment.
ModificadaAlta (8.8)57%💥 PoCKubernetes Ingress-nginx25/10/202317/6/2026
Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.
ModificadaAlta (8.8)2.2%💥 PoCKubernetes Ingress-nginx25/10/202317/6/2026
Ingress nginx annotation injection causes arbitrary command execution.
ModificadaMedia (6.5)1.6%—Kubernetes Ingress-nginx25/10/202317/6/2026
Ingress-nginx `path` sanitization can be bypassed with `log_format` directive.
ModificadaAlta (8.8)0.58%—Kubernetes Operations12/10/202317/6/2026
Privilege Escalation in kOps using GCE/GCP Provider in Gossip Mode.
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaAlta (7.4)0.38%—F5 Big-ip Next Service Proxy FOR Kubernetes10/10/202317/6/2026
The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacker with the ability to intercept traffic to impersonate the SPK Secure Shell (SSH) server on those containers. This is only exposed when ssh debug is enabled. Note:…
ModificadaAlta (7.5)0.54%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1610/10/202317/6/2026
When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, and an iRule using the HTTP_REQUEST event or Local Traffic Policy are associated with the virtual server, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical…
ModificadaAlta (7.5)0.48%—Redhat Advanced Cluster Management FOR KubernetesRedhat Openshift Container Platform5/10/202317/6/2026
A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the boundaries, as permissions will not be applied.
ModificadaAlta (7.8)0.29%—Kubernetes Cri-oRedhat Openshift Container Platform FOR Arm64Redhat Openshift Container Platform FOR LinuxoneRedhat Openshift Container Platform FOR Power+325/9/202317/6/2026
A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
ModificadaAlta (8)1.6%—Kubernetes Kube-apiserverRedhat Openshift Container Platform24/9/202317/6/2026
An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already…
ModificadaMedia (5.3)0.21%—Kubernetes Cri-oRedhat Openshift Container Platform15/9/202317/6/2026
The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing the fix for CVE-2022-27652, which was previously fixed in OCP 4.9.41 and 4.10.12 via RHBA-2022:5433…
ModificadaCrítica (9.8)2.7%—Microsoft Azure Kubernetes Service12/9/202317/6/2026
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
ModificadaMedia (6.5)2.2%💥 PoCKubernetes3/7/202317/6/2026
Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are…
Orbitaley — Vulnerabilidades