Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

276 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)10.0%💥 PoCGolang GOFedoraproject FedoraNetapp Kubernetes Monitoring Operator20/4/202217/6/2026
encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.
ModificadaMedia (5.3)0.24%—Kubernetes Cri-oFedoraproject FedoraMobyproject MobyRedhat Openshift Container Platform18/4/202217/6/2026
A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable…
ModificadaAlta (7.5)3.9%—Golang SSHFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Advanced Cluster Management FOR Kubernetes18/3/202217/6/2026
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.
ModificadaAlta (8.8)19%💥 PoCKubernetes Cri-o16/3/202217/6/2026
A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.
ModificadaMedia (6.5)0.92%—Jenkins Kubernetes Continuous Deploy15/3/202217/6/2026
A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
ModificadaMedia (6.5)0.73%—Jenkins Kubernetes Continuous Deploy15/3/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
ModificadaMedia (6.5)0.92%—Jenkins Kubernetes Continuous Deploy15/3/202217/6/2026
A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
ModificadaMedia (6.5)1.8%—Jenkins Kubernetes Continuous Deploy15/3/202217/6/2026
Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows users with Credentials/Create permission to read arbitrary files on the Jenkins controller.
ModificadaCrítica (9.1)3.1%—Golang GONetapp Beegfs CSI DriverNetapp Cloud Insights Telegraf AgentNetapp Kubernetes Monitoring Operator+211/2/202217/6/2026
Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.
ModificadaAlta (7.5)2.7%💥 PoCGolang GONetapp Beegfs CSI DriverNetapp Cloud Insights Telegraf AgentNetapp Kubernetes Monitoring Operator+111/2/202217/6/2026
cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.
ModificadaAlta (7.5)2.8%—Golang GONetapp Beegfs CSI DriverNetapp Cloud Insights Telegraf AgentNetapp Kubernetes Monitoring Operator+211/2/202217/6/2026
Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.
ModificadaMedia (4.2)0.77%—Kubernetes Cri-oRedhat Openshift Container Platform9/2/202217/6/2026
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.
ModificadaBaja (3.1)1.1%—Kubernetes1/2/202217/6/2026
As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Services, Pods, Nodes, or StorageClass service providers. As part of this mitigation Kubernetes does a DNS name resolution…
AnalizadaBaja (3)0.78%—Kubernetes7/1/202217/6/2026
kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.
ModificadaAlta (7.1)2.1%—Kubernetes Ingress-nginxNetapp Trident29/10/202117/6/2026
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.
ModificadaMedia (6.7)0.47%—Kubernetes Java11/10/202117/6/2026
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution.
ModificadaAlta (8.1)8.0%💥 PoCKubernetes20/9/202117/6/2026
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.
ModificadaBaja (3.1)2.0%—Kubernetes20/9/202117/6/2026
A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.
ModificadaMedia (4.1)2.1%—Kubernetes20/9/202117/6/2026
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10,…
ModificadaMedia (4.8)1.3%—Kubernetes6/9/202117/6/2026
A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not performed on EndpointSlice IPs.
ModificadaMedia (6.5)5.5%💥 PoCKubernetes6/9/202117/6/2026
A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating…
ModificadaMedia (4.3)1.6%—Jenkins Kubernetes10/6/202117/6/2026
Jenkins Kubernetes CLI Plugin 1.10.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
ModificadaAlta (7.8)2.0%—Microsoft Kubernetes Tools8/6/202117/6/2026
Microsoft VsCode Kubernetes Tools Extension Elevation of Privilege Vulnerability
ModificadaAlta (7)0.26%—Kubernetes-nmstateRedhat Openshift Virtualization7/6/202117/6/2026
An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before kubernetes-nmstate-handler-container-v2.3.0-30 are affected.
ModificadaMedia (5.6)0.80%—Ovn-kubernetes2/6/202117/6/2026
A vulnerability was found in OVN Kubernetes in versions up to and including 0.3.0 where the Egress Firewall does not reliably apply firewall rules when there is multiple DNS rules. It could lead to potentially lose of confidentiality, integrity or availability of a service.
Orbitaley — Vulnerabilidades