Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
601 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.57% | — | Linuxfoundation Yocto | 9/3/2026 | 17/6/2026 | In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.. | |
| Modificada | Crítica (9.8) | 0.95% | — | Linuxfoundation Backstage Plugin-techdocs-node | 7/3/2026 | 15/7/2026 | Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arbitrary code execution. The @backstage/plugin-techdocs-node package uses an allowlist to filter dangerous MkDocs configuration keys during the documentation build process.… | |
| Analizada | Baja (2.7) | 0.40% | — | Linuxfoundation Backstage/integration | 7/3/2026 | 17/6/2026 | Backstage is an open framework for building developer portals. Prior to version 1.20.1, a vulnerability in the SCM URL parsing used by Backstage integrations allowed path traversal sequences in encoded form to be included in file paths. When these URLs were processed by integration functions that construct API URLs,… | |
| Analizada | Media (6.5) | 0.30% | — | Linuxfoundation Backstage/plugin-scaffolder-backend | 7/3/2026 | 17/6/2026 | Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run through task event logs. This issue has been patched in version 3.1.4. | |
| Analizada | Media (4.6) | 0.12% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt+1 | 2/3/2026 | 17/6/2026 | In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10607099; Issue ID:… | |
| Analizada | Crítica (9.3) | 0.60% | — | Linuxfoundation Vitess | 26/2/2026 | 17/6/2026 | Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that files in the manifest — which may be files that they have also added to the manifest… | |
| Analizada | Alta (8.4) | 0.69% | — | Linuxfoundation Vitess | 26/2/2026 | 17/6/2026 | Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that arbitrary code is later executed when that backup is restored. This can be used to… | |
| Analizada | Alta (7.5) | 0.73% | — | Linuxfoundation Nats-server | 24/2/2026 | 17/6/2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling of NATS messages handles compressed messages via the WebSockets negotiated compression. Prior to versions 2.11.2 and 2.12.3, the implementation bound the memory size of a NATS message but did not… | |
| Modificada | Alta (8.1) | 0.42% | — | Linuxfoundation Strimzi Kafka Operator | 21/2/2026 | 15/7/2026 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In versions 0.49.0 through 0.50.0, when using a custom Cluster or Clients CA with a multistage CA chain consisting of multiple CAs, Strimzi incorrectly configures the trusted certificates for mTLS… | |
| Analizada | Media (5.9) | 0.23% | — | Linuxfoundation Strimzi | 20/2/2026 | 17/6/2026 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 to before 0.50.1, when a chain consisting of multiple CA (Certificate Authority) certificates is used in the trusted certificates configuration of a Kafka Connect operand or of the target… | |
| Analizada | Media (6.9) | 0.73% | — | Linuxfoundation Inspektor Gadget | 12/2/2026 | 17/6/2026 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. String fields from eBPF events in columns output mode are rendered to the terminal without any sanitization of control characters or ANSI escape sequences. Therefore, a… | |
| Analizada | Alta (8) | 0.65% | — | Linuxfoundation Antrea | 6/2/2026 | 17/6/2026 | Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's network policy priority assignment system has a uint16 arithmetic overflow bug that causes incorrect OpenFlow priority calculations when handling a large numbers of policies with various priority… | |
| Modificada | Alta (8.8) | 0.61% | — | Linuxfoundation Backstage | 30/1/2026 | 15/7/2026 | Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In versions of @backstage/plugin-techdocs-node prior to 1.13.11 and 1.14.1, when TechDocs is configured with `runIn: local`, a malicious actor who can submit or… | |
| Analizada | Media (6.5) | 0.44% | — | Linuxfoundation Backstage | 30/1/2026 | 17/6/2026 | Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In versions of @backstage/plugin-techdocs-node prior to 1.13.11 and 1.14.1, a path traversal vulnerability in the TechDocs local generator allows attackers to read… | |
| Modificada | Media (6.6) | 1.4% | — | Linuxfoundation Inspektor Gadget | 29/1/2026 | 17/6/2026 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. The `ig` binary provides a subcommand for image building, used to generate custom gadget OCI images. A part of this functionality is implemented in the file… | |
| Analizada | Alta (8.8) | 0.31% | — | Linuxfoundation Podman Desktop | 28/1/2026 | 17/6/2026 | Podman Desktop is a graphical tool for developing on containers and Kubernetes. A critical authentication bypass vulnerability in Podman Desktop prior to version 1.25.1 allows any extension to completely circumvent permission checks and gain unauthorized access to all authentication sessions. The `isAccessAllowed()`… | |
| Modificada | Alta (8.8) | 0.81% | — | Linuxfoundation Pytorch | 27/1/2026 | 15/7/2026 | PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with `torch.load(..., weights_only=True)`, can corrupt memory and potentially lead to arbitrary… | |
| Analizada | Media (5) | 0.18% | — | Linuxfoundation Sigstore-python | 26/1/2026 | 17/6/2026 | sigstore-python is a Python tool for generating and verifying Sigstore signatures. Prior to version 4.2.0, the sigstore-python OAuth authentication flow is susceptible to Cross-Site Request Forgery. `_OAuthSession` creates a unique "state" and sends it as a parameter in the authentication request but the "state" in… | |
| Analizada | Media (5.3) | 0.28% | — | Linuxfoundation Everest | 26/1/2026 | 17/6/2026 | EVerest is an EV charging software stack. In versions up to and including 2025.12.1, it is possible to bypass the sequence state verification including authentication, and send requests that transition to forbidden states relative to the current one, thereby updating the current context with illegitimate data.cThanks… | |
| Analizada | Alta (8.9) | 0.79% | — | Linuxfoundation Dragonfly | 22/1/2026 | 17/6/2026 | Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/v1/jobs) lack JWT authentication middleware and RBAC authorization checks in the routing configuration. This allows any unauthenticated user with access to the Manager… | |
| Analizada | Media (5.3) | 0.37% | — | Linuxfoundation Rekor | 22/1/2026 | 17/6/2026 | Rekor is a software supply chain transparency log. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary internal services because /api/v1/index/retrieve supports retrieving a public key via user-provided URL. Since the SSRF only can trigger GET requests, the request cannot mutate state. The response… | |
| Analizada | Media (5.3) | 0.43% | — | Linuxfoundation Rekor | 22/1/2026 | 17/6/2026 | Rekor is a software supply chain transparency log. In versions 1.4.3 and below, the entry implementation can panic on attacker-controlled input when canonicalizing a proposed entry with an empty spec.message, causing nil Pointer Dereference. Function validate() returns nil (success) when message is empty, leaving… | |
| Analizada | Baja (3.7) | 0.23% | — | Linuxfoundation Backstage/backend Defaults | 21/1/2026 | 17/6/2026 | Backstage is an open framework for building developer portals, and @backstage/backend-defaults provides the default implementations and setup for a standard Backstage backend app. Prior to versions 0.12.2, 0.13.2, 0.14.1, and 0.15.0, the `FetchUrlReader` component, used by the catalog and other plugins to fetch… | |
| Analizada | Media (4.2) | 0.19% | — | Linuxfoundation Everest | 21/1/2026 | 17/6/2026 | EVerest is an EV charging software stack. Prior to version 2025.9.0, in several places, integer values are concatenated to literal strings when throwing errors. This results in pointers arithmetic instead of printing the integer value as expected, like most of interpreted languages. This can be used by malicious… | |
| Analizada | Alta (7.4) | 0.27% | — | Linuxfoundation Everest | 21/1/2026 | 17/6/2026 | EVerest is an EV charging software stack. Prior to version 2025.10.0, during the deserialization of a `DC_ChargeLoopRes` message that includes Receipt as well as TaxCosts, the vector `<DetailedTax>tax_costs` in the target `Receipt` structure is accessed out of bounds. This occurs in the method `template <> void… |