Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 10.0% | 💥 PoC | Golang GOFedoraproject FedoraNetapp Kubernetes Monitoring Operator | 20/4/2022 | 17/6/2026 | encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data. | |
| Modificada | Media (5.3) | 0.24% | — | Kubernetes Cri-oFedoraproject FedoraMobyproject MobyRedhat Openshift Container Platform | 18/4/2022 | 17/6/2026 | A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable… | |
| Modificada | Alta (7.5) | 3.9% | — | Golang SSHFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Advanced Cluster Management FOR Kubernetes | 18/3/2022 | 17/6/2026 | The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey. | |
| Modificada | Alta (8.8) | 19% | 💥 PoC | Kubernetes Cri-o | 16/3/2022 | 17/6/2026 | A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed. | |
| Modificada | Media (6.5) | 0.92% | — | Jenkins Kubernetes Continuous Deploy | 15/3/2022 | 17/6/2026 | A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Media (6.5) | 0.73% | — | Jenkins Kubernetes Continuous Deploy | 15/3/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Media (6.5) | 0.92% | — | Jenkins Kubernetes Continuous Deploy | 15/3/2022 | 17/6/2026 | A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Media (6.5) | 1.8% | — | Jenkins Kubernetes Continuous Deploy | 15/3/2022 | 17/6/2026 | Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows users with Credentials/Create permission to read arbitrary files on the Jenkins controller. | |
| Modificada | Crítica (9.1) | 3.1% | — | Golang GONetapp Beegfs CSI DriverNetapp Cloud Insights Telegraf AgentNetapp Kubernetes Monitoring Operator+2 | 11/2/2022 | 17/6/2026 | Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element. | |
| Modificada | Alta (7.5) | 2.7% | 💥 PoC | Golang GONetapp Beegfs CSI DriverNetapp Cloud Insights Telegraf AgentNetapp Kubernetes Monitoring Operator+1 | 11/2/2022 | 17/6/2026 | cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags. | |
| Modificada | Alta (7.5) | 2.8% | — | Golang GONetapp Beegfs CSI DriverNetapp Cloud Insights Telegraf AgentNetapp Kubernetes Monitoring Operator+2 | 11/2/2022 | 17/6/2026 | Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption. | |
| Modificada | Media (4.2) | 0.77% | — | Kubernetes Cri-oRedhat Openshift Container Platform | 9/2/2022 | 17/6/2026 | An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace. | |
| Modificada | Baja (3.1) | 1.1% | — | Kubernetes | 1/2/2022 | 17/6/2026 | As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Services, Pods, Nodes, or StorageClass service providers. As part of this mitigation Kubernetes does a DNS name resolution… | |
| Analizada | Baja (3) | 0.78% | — | Kubernetes | 7/1/2022 | 17/6/2026 | kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events. | |
| Modificada | Alta (7.1) | 2.1% | — | Kubernetes Ingress-nginxNetapp Trident | 29/10/2021 | 17/6/2026 | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster. | |
| Modificada | Media (6.7) | 0.47% | — | Kubernetes Java | 11/10/2021 | 17/6/2026 | Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. | |
| Modificada | Alta (8.1) | 8.0% | 💥 PoC | Kubernetes | 20/9/2021 | 17/6/2026 | A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem. | |
| Modificada | Baja (3.1) | 2.0% | — | Kubernetes | 20/9/2021 | 17/6/2026 | A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack. | |
| Modificada | Media (4.1) | 2.1% | — | Kubernetes | 20/9/2021 | 17/6/2026 | A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10,… | |
| Modificada | Media (4.8) | 1.3% | — | Kubernetes | 6/9/2021 | 17/6/2026 | A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not performed on EndpointSlice IPs. | |
| Modificada | Media (6.5) | 5.5% | 💥 PoC | Kubernetes | 6/9/2021 | 17/6/2026 | A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating… | |
| Modificada | Media (4.3) | 1.6% | — | Jenkins Kubernetes | 10/6/2021 | 17/6/2026 | Jenkins Kubernetes CLI Plugin 1.10.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Alta (7.8) | 2.0% | — | Microsoft Kubernetes Tools | 8/6/2021 | 17/6/2026 | Microsoft VsCode Kubernetes Tools Extension Elevation of Privilege Vulnerability | |
| Modificada | Alta (7) | 0.26% | — | Kubernetes-nmstateRedhat Openshift Virtualization | 7/6/2021 | 17/6/2026 | An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before kubernetes-nmstate-handler-container-v2.3.0-30 are affected. | |
| Modificada | Media (5.6) | 0.80% | — | Ovn-kubernetes | 2/6/2021 | 17/6/2026 | A vulnerability was found in OVN Kubernetes in versions up to and including 0.3.0 where the Egress Firewall does not reliably apply firewall rules when there is multiple DNS rules. It could lead to potentially lose of confidentiality, integrity or availability of a service. |