Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
5399 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.7) | 0.10% | — | Cloudfoundry Bosh DirectorAIVmware VcenterAI | 29/8/2026 | 3/9/2026 | Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, leading to complete virtualization infrastructure takeover. An attacker who can intercept traffic… | |
| Pendiente de análisis | Media (6.2) | 0.16% | — | IBM Cloud PAK FOR Data SystemAI | 28/8/2026 | 31/8/2026 | IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 is vulnerable to a denial of service due to improper limitation of resources. | |
| Analizada | Media (5.3) | 0.40% | — | Vmware Spring Cloud Config | 27/8/2026 | 31/8/2026 | The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier | |
| Analizada | Baja (3.8) | 0.23% | — | Vmware Spring Cloud Stream | 27/8/2026 | 4/9/2026 | Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6 | |
| Analizada | Baja (3.8) | 0.21% | — | Vmware Spring Cloud Stream | 27/8/2026 | 4/9/2026 | Partition interceptor may be improperly added while sending message. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6 | |
| Analizada | Baja (3.8) | 0.21% | — | Vmware Spring Cloud Stream | 27/8/2026 | 4/9/2026 | Improper caching of the original content type in Spring Cloud Stream Avro. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6 | |
| Analizada | Baja (3.8) | 0.21% | — | Vmware Spring Cloud Stream | 27/8/2026 | 4/9/2026 | Dynamic destination cache size is not properly bound in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6 | |
| Analizada | Media (4.9) | 0.23% | — | Vmware Spring Cloud Function | 27/8/2026 | 4/9/2026 | Potential for logging sensitive data in Spring Cloud Function Azure. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 | |
| Analizada | Baja (3.5) | 0.21% | — | Vmware Spring Cloud Function | 27/8/2026 | 2/9/2026 | Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier | |
| Analizada | Baja (3.5) | 0.21% | — | Vmware Spring Cloud Function | 27/8/2026 | 2/9/2026 | Composition lookup can potentially poison base function in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier | |
| Analizada | Baja (3.5) | 0.22% | — | Vmware Spring Cloud Function | 27/8/2026 | 2/9/2026 | Potential for improper filtering of HTTP headers in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier | |
| Analizada | Baja (3.5) | 0.13% | — | Vmware Spring Cloud Function | 27/8/2026 | 2/9/2026 | Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual scheme. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 | |
| Analizada | Media (5.5) | 0.24% | — | Vmware Spring Cloud Function | 27/8/2026 | 31/8/2026 | Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 | |
| Analizada | Alta (7.6) | 0.43% | — | Broadcom Spring Cloud Commons | 27/8/2026 | 1/9/2026 | There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled. Spring Cloud Commons 5.0.0 - 5.0.2 Spring Cloud Commons 4.3.0 - 4.3.3 Spring Cloud Commons 4.0.0 - 4.2.6 Spring Cloud Commons 3.1.10 and earlier | |
| Analizada | Media (4.9) | 0.17% | — | Vmware Spring Cloud Function | 27/8/2026 | 23/9/2026 | Potential for logging sensitive data in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6 | |
| Analizada | Alta (7.5) | 0.49% | — | Vmware Spring Cloud Config | 27/8/2026 | 1/9/2026 | Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier | |
| Analizada | Alta (8.7) | 0.33% | — | Vmware Spring Cloud Gateway | 27/8/2026 | 10/9/2026 | Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - 4.3.5 Spring Cloud Gateway 4.0.0 - 4.2.9 Spring Cloud Gateway 3.1.13 and earlier | |
| Aplazada | Media (5.8) | 0.41% | — | Fit2cloud KubepiAI | 26/8/2026 | 9/9/2026 | KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 2.0.0, cluster-scoped APIs do not consistently validate per-cluster access, allowing an authenticated user with cluster management permissions to operate on clusters outside the scope they were granted. Because the affected… | |
| Aplazada | Crítica (10) | 0.64% | — | Fit2cloud KubepiAI | 26/8/2026 | 9/9/2026 | KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endpoints are exposed on the same public routing boundary as the SSO login and callback endpoints, so SSO, OIDC, and SAML management operations can be reached without administrator authorization.… | |
| Aplazada | Media (4.3) | 0.30% | — | Wgstart WgcloudAI | 26/8/2026 | 31/8/2026 | An issue in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the content parameter is directly concatenated to the ProcessBuilder. | |
| Analizada | Media (4.3) | 0.27% | — | Dell Cloud Disaster Recovery | 26/8/2026 | 3/9/2026 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. | |
| Analizada | Alta (7.2) | 1.6% | — | Dell Cloud Disaster Recovery | 26/8/2026 | 3/9/2026 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | |
| Analizada | Crítica (9.1) | 2.0% | — | Dell Cloud Disaster Recovery | 26/8/2026 | 3/9/2026 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |
| Analizada | Crítica (9.8) | 0.55% | — | Vmware Spring Cloud Config | 26/8/2026 | 4/9/2026 | Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This issue affects Spring Cloud Config: from 5.0.0 through 5.0.4, from 4.3.0 through 4.3.4, from 4.0.0 through 4.2.8, and through 3.1.14. | |
| Analizada | Alta (8.1) | 0.22% | — | Vmware Spring Cloud Config | 26/8/2026 | 4/9/2026 | The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14… |