Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

380 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.5)0.09%—Hashicorp Vault1/5/202317/6/2026
HashiCorp Vault Enterprise 1.13.0 up to 1.13.1 is vulnerable to a padding oracle attack when using an HSM in conjunction with the CKM_AES_CBC_PAD or CKM_AES_CBC encryption mechanisms. An attacker with privileges to modify storage and restart Vault may be able to intercept or modify cipher text in order to derive…
ModificadaAlta (7.5)0.40%—Jenkins Thycotic Devops Secrets Vault12/4/202317/6/2026
Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
ModificadaAlta (7.5)0.48%—Jenkins Azure KEY Vault12/4/202317/6/2026
Jenkins Azure Key Vault Plugin 187.va_cd5fecd198a_ and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
ModificadaMedia (4.7)0.21%—Hashicorp Vault30/3/202317/6/2026
HashiCorp Vault's implementation of Shamir's secret sharing used precomputed table lookups, and was vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to…
ModificadaMedia (6.5)0.33%—Hashicorp Vault30/3/202317/6/2026
HashiCorp Vault's PKI mount issuer endpoints did not correctly authorize access to remove an issuer or modify issuer metadata, potentially resulting in denial of service of the PKI mount. This bug did not affect public or private key material, trust chains or certificate issuance. Fixed in Vault 1.13.1, 1.12.5, and…
ModificadaMedia (6.7)0.38%—Hashicorp Vault30/3/202317/6/2026
HashiCorp Vault and Vault Enterprise versions 0.8.0 through 1.13.1 are vulnerable to an SQL injection attack when configuring the Microsoft SQL (MSSQL) Database Storage Backend. When configuring the MSSQL plugin through the local, certain parameters are not sanitized when passed to the user-provided MSSQL database. An…
ModificadaMedia (5.5)0.22%—Vmware Spring Cloud ConfigVmware Spring Cloud VaultVmware Spring Vault23/3/202317/6/2026
In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.
ModificadaMedia (4.8)0.39%—IP Vault - WP Firewall Project IP Vault - WP Firewall14/3/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul C. Schroeder IP Vault – WP Firewall plugin <= 1.1 versions.
ModificadaAlta (8.1)0.60%—Hashicorp Vault11/3/202317/6/2026
HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the secret ID of any other role by providing the secret ID accessor. This vulnerability is fixed in Vault 1.13.0, 1.12.4, 1.11.8, 1.10.11 and above.
ModificadaAlta (8.8)0.38%—Dell Powervault Me5012 FirmwareDell Powervault Me5024 FirmwareDell Powervault Me5084 Firmware20/1/202317/6/2026
Dell EMC PV ME5, versions ME5.1.0.0.0 and ME5.1.0.1.0, contains a Client-side desync Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability to force a victim's browser to desynchronize its connection with the website, typically leading to XSS and DoS.
ModificadaAlta (7.5)0.63%—Isode M-vault21/12/202217/6/2026
Isode M-Vault 16.0v0 through 17.x before 17.0v24 can crash upon an LDAP v1 bind request.
ModificadaMedia (5.3)0.43%—Hashicorp Vault12/10/202217/6/2026
HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.
ModificadaCrítica (9.1)1.00%—Hashicorp Vault22/9/202217/6/2026
An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias…
ModificadaAlta (7.5)0.78%—Hcltech Versionvault Express30/8/202217/6/2026
An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service.
ModificadaMedia (6.5)0.46%—Hcltech Versionvault Express30/8/202217/6/2026
HCL VersionVault Express exposes administrator credentials.
ModificadaMedia (6.5)0.70%—Jenkins Hashicorp Vault27/7/202217/6/2026
A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48 and earlier allows attackers with Overall/Read permission to obtain credentials stored in Vault with attacker-specified path and keys.
ModificadaCrítica (9.1)1.6%—Hashicorp Vault26/7/202217/6/2026
HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cluster, introducing potential for future data loss or catastrophic failure. Fixed in Vault…
ModificadaAlta (7.5)1.1%—Automattic Vaultpress23/6/202217/6/2026
A vulnerability, which was classified as critical, was found in VaultPress Plugin 1.8.4. This affects an unknown part. The manipulation leads to code injection. It is possible to initiate the attack remotely.
ModificadaCrítica (9.1)0.59%—Hcltech Versionvault Express25/5/202217/6/2026
VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.
ModificadaMedia (5.3)1.2%—Hashicorp Vault17/5/202217/6/2026
HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly configure and enforce MFA on login after server restarts. This affects the Login MFA feature introduced in Vault and Vault Enterprise 1.10.0 and does not affect the separate Enterprise MFA feature set. Fixed in 1.10.3.
ModificadaMedia (6.5)0.95%—Hashicorp Vault10/3/202217/6/2026
Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoint to authorized operators with `read` permissions on this endpoint. Fixed in Vault Enterprise 1.9.4, 1.8.9 and 1.7.10.
ModificadaMedia (6.5)0.57%—Hashicorp Vault10/3/202217/6/2026
"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_subdomains is set to false. Fixed in Vault Enterprise 1.8.9 and 1.9.4.
ModificadaMedia (6.5)0.81%—Jenkins Hashicorp Vault15/2/202217/6/2026
Jenkins HashiCorp Vault Plugin 336.v182c0fbaaeb7 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenkins controller file system.
ModificadaMedia (6.5)0.81%—Jenkins Hashicorp Vault15/2/202217/6/2026
Jenkins HashiCorp Vault Plugin 3.8.0 and earlier implements functionality that allows agent processes to retrieve any Vault secrets for use on the agent, allowing attackers able to control agent processes to obtain Vault secrets for an attacker-specified path and key.
ModificadaAlta (8.8)4.2%—Commvault Commcell13/1/202217/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the AppStudioUploadHandler class. The…
Orbitaley — Vulnerabilidades