Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

276 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.1%—Kubernetes3/7/202317/6/2026
Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers.
ModificadaMedia (5.5)0.26%—KubernetesFedoraproject Fedora16/6/202317/6/2026
A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in unconfined (seccomp disabled) mode. This…
ModificadaMedia (5.5)0.37%—Kubernetes Secrets-store-csi-driver7/6/202317/6/2026
Kubernetes secrets-store-csi-driver in versions before 1.3.3 discloses service account tokens in logs.
ModificadaAlta (7.8)0.20%—Redhat Advanced Cluster Management FOR Kubernetes5/6/202317/6/2026
The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained values (instead of the policy apply a static manifest on a managed cluster) of taking advantage of cluster scoped access in a created policy. This feature does not restrict…
ModificadaAlta (7.2)1.5%—Apache-airflow-providers-cncf-kubernetes30/5/20232/7/2026
Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection. In order to exploit this weakness, a user would already need elevated permissions (Op or Admin) to change the connection object in this manner. Operators…
ModificadaAlta (7.8)0.21%—Kubernetes Minikube24/5/202317/6/2026
This vulnerability enables ssh access to minikube container using a default password.
ModificadaCrítica (9.8)0.76%—Kubernetes Minikube24/5/202317/6/2026
This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected remote access to the minikube container.
ModificadaAlta (7.8)0.21%—Kubernetes24/5/202317/6/2026
Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true.
ModificadaMedia (6.5)0.69%—Kubernetes Ingress-nginx24/5/202317/6/2026
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` field of an Ingress object (in the `networking.k8s.io` or `extensions` API group) to obtain the credentials of the…
ModificadaMedia (5.3)0.56%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+163/5/202317/6/2026
When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaAlta (7.5)0.49%—Jenkins Kubernetes12/4/202317/6/2026
Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
ModificadaAlta (8.8)1.6%💥 PoCKubernetes1/3/202317/6/2026
Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node objects and send proxy requests to them. Kubernetes supports node proxying, which allows clients of kube-apiserver to access endpoints of a Kubelet to establish connections…
ModificadaMedia (6.5)1.2%—Kubernetes1/3/202317/6/2026
Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API group without authorization. Clusters are impacted by this vulnerability if all of the following are true: 1. There are 2+ CustomResourceDefinitions sharing the same API…
ModificadaMedia (5.3)0.62%—Snyk Kubernetes Monitor28/2/202317/6/2026
This vulnerability in the Snyk Kubernetes Monitor can result in irrelevant data being posted to a Snyk Organization, which could in turn obfuscate other, relevant, security issues. It does not expose the user of the integration to any direct security risk and no user data can be leaked. To exploit the vulnerability…
ModificadaMedia (6.5)0.82%—Jenkins Kubernetes Credentials Provider26/1/202317/6/2026
Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Kubernetes credentials they are not entitled to.
ModificadaAlta (7.8)0.23%—Redhat Advanced Cluster Management FOR Kubernetes13/1/202317/6/2026
RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Red Hat Advanced Cluster Management for Kubernetes (RHACM). An attacker could take advantage of this as the console API endpoint is missing an authentication check,…
ModificadaCrítica (10)2.6%—Microsoft Azure Arc-enabled KubernetesMicrosoft Azure Stack Edge11/10/202217/6/2026
Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allow an unauthenticated user to elevate their privileges and potentially gain administrative control over the Kubernetes cluster. Additionally, because Azure Stack Edge…
ModificadaAlta (7.1)0.39%—Kubernetes Cri-o19/9/202217/6/2026
Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that…
ModificadaMedia (6.5)0.92%—Redhat Advanced Cluster Management FOR Kubernetes1/9/202217/6/2026
A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by the backend. This flaw allows an attacker to craft specific strings containing special characters that lead to crashing the pod and affects system availability…
ModificadaMedia (6.7)0.33%💥 PoCRedhat Fabric8-kubernetesRedhat A-mq StreamsRedhat Build OF QuarkusRedhat Descision Manager+524/8/202217/6/2026
A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.
ModificadaAlta (8.8)1.1%—Kubernetes Aws-iam-authenticator12/7/202217/6/2026
A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.
ModificadaAlta (7.5)3.2%—Kubernetes Cri-oFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux7/6/202217/6/2026
A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. This output is then read by CRI-O after command execution, and it is read in a manner where the entire…
ModificadaAlta (7.1)1.4%—Kubernetes Ingress-nginx6/5/202217/6/2026
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has…
ModificadaAlta (8.1)1.2%—Kubernetes Ingress-nginx6/5/202217/6/2026
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that…
ModificadaCrítica (9.1)1.0%—Ovn-kubernetes20/4/202217/6/2026
A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress network policy that bypasses existing ingress policies of other pods in a cluster, allowing network traffic to access pods that should not be reachable. This issue results in information disclosure…
Orbitaley — Vulnerabilidades