Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.1% | — | Kubernetes | 3/7/2023 | 17/6/2026 | Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers. | |
| Modificada | Media (5.5) | 0.26% | — | KubernetesFedoraproject Fedora | 16/6/2023 | 17/6/2026 | A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in unconfined (seccomp disabled) mode. This… | |
| Modificada | Media (5.5) | 0.37% | — | Kubernetes Secrets-store-csi-driver | 7/6/2023 | 17/6/2026 | Kubernetes secrets-store-csi-driver in versions before 1.3.3 discloses service account tokens in logs. | |
| Modificada | Alta (7.8) | 0.20% | — | Redhat Advanced Cluster Management FOR Kubernetes | 5/6/2023 | 17/6/2026 | The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained values (instead of the policy apply a static manifest on a managed cluster) of taking advantage of cluster scoped access in a created policy. This feature does not restrict… | |
| Modificada | Alta (7.2) | 1.5% | — | Apache-airflow-providers-cncf-kubernetes | 30/5/2023 | 2/7/2026 | Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection. In order to exploit this weakness, a user would already need elevated permissions (Op or Admin) to change the connection object in this manner. Operators… | |
| Modificada | Alta (7.8) | 0.21% | — | Kubernetes Minikube | 24/5/2023 | 17/6/2026 | This vulnerability enables ssh access to minikube container using a default password. | |
| Modificada | Crítica (9.8) | 0.76% | — | Kubernetes Minikube | 24/5/2023 | 17/6/2026 | This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected remote access to the minikube container. | |
| Modificada | Alta (7.8) | 0.21% | — | Kubernetes | 24/5/2023 | 17/6/2026 | Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true. | |
| Modificada | Media (6.5) | 0.69% | — | Kubernetes Ingress-nginx | 24/5/2023 | 17/6/2026 | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` field of an Ingress object (in the `networking.k8s.io` or `extensions` API group) to obtain the credentials of the… | |
| Modificada | Media (5.3) | 0.56% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+16 | 3/5/2023 | 17/6/2026 | When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Alta (7.5) | 0.49% | — | Jenkins Kubernetes | 12/4/2023 | 17/6/2026 | Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled. | |
| Modificada | Alta (8.8) | 1.6% | 💥 PoC | Kubernetes | 1/3/2023 | 17/6/2026 | Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node objects and send proxy requests to them. Kubernetes supports node proxying, which allows clients of kube-apiserver to access endpoints of a Kubelet to establish connections… | |
| Modificada | Media (6.5) | 1.2% | — | Kubernetes | 1/3/2023 | 17/6/2026 | Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API group without authorization. Clusters are impacted by this vulnerability if all of the following are true: 1. There are 2+ CustomResourceDefinitions sharing the same API… | |
| Modificada | Media (5.3) | 0.62% | — | Snyk Kubernetes Monitor | 28/2/2023 | 17/6/2026 | This vulnerability in the Snyk Kubernetes Monitor can result in irrelevant data being posted to a Snyk Organization, which could in turn obfuscate other, relevant, security issues. It does not expose the user of the integration to any direct security risk and no user data can be leaked. To exploit the vulnerability… | |
| Modificada | Media (6.5) | 0.82% | — | Jenkins Kubernetes Credentials Provider | 26/1/2023 | 17/6/2026 | Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Kubernetes credentials they are not entitled to. | |
| Modificada | Alta (7.8) | 0.23% | — | Redhat Advanced Cluster Management FOR Kubernetes | 13/1/2023 | 17/6/2026 | RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Red Hat Advanced Cluster Management for Kubernetes (RHACM). An attacker could take advantage of this as the console API endpoint is missing an authentication check,… | |
| Modificada | Crítica (10) | 2.6% | — | Microsoft Azure Arc-enabled KubernetesMicrosoft Azure Stack Edge | 11/10/2022 | 17/6/2026 | Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allow an unauthenticated user to elevate their privileges and potentially gain administrative control over the Kubernetes cluster. Additionally, because Azure Stack Edge… | |
| Modificada | Alta (7.1) | 0.39% | — | Kubernetes Cri-o | 19/9/2022 | 17/6/2026 | Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that… | |
| Modificada | Media (6.5) | 0.92% | — | Redhat Advanced Cluster Management FOR Kubernetes | 1/9/2022 | 17/6/2026 | A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by the backend. This flaw allows an attacker to craft specific strings containing special characters that lead to crashing the pod and affects system availability… | |
| Modificada | Media (6.7) | 0.33% | 💥 PoC | Redhat Fabric8-kubernetesRedhat A-mq StreamsRedhat Build OF QuarkusRedhat Descision Manager+5 | 24/8/2022 | 17/6/2026 | A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML. | |
| Modificada | Alta (8.8) | 1.1% | — | Kubernetes Aws-iam-authenticator | 12/7/2022 | 17/6/2026 | A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges. | |
| Modificada | Alta (7.5) | 3.2% | — | Kubernetes Cri-oFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux | 7/6/2022 | 17/6/2026 | A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. This output is then read by CRI-O after command execution, and it is read in a manner where the entire… | |
| Modificada | Alta (7.1) | 1.4% | — | Kubernetes Ingress-nginx | 6/5/2022 | 17/6/2026 | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has… | |
| Modificada | Alta (8.1) | 1.2% | — | Kubernetes Ingress-nginx | 6/5/2022 | 17/6/2026 | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that… | |
| Modificada | Crítica (9.1) | 1.0% | — | Ovn-kubernetes | 20/4/2022 | 17/6/2026 | A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress network policy that bypasses existing ingress policies of other pods in a cluster, allowing network traffic to access pods that should not be reachable. This issue results in information disclosure… |