Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
332 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.2) | 0.99% | — | Redhat Openshift Container Platform | 22/4/2020 | 17/6/2026 | A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator allowing an attacker able to gain access to those logs, to read and write to the storage backing the internal image registry. The highest threat from this vulnerability is… | |
| Modificada | Alta (8.8) | 62% | — | HaproxyDebian LinuxRedhat Openshift Container PlatformFedoraproject Fedora+2 | 2/4/2020 | 17/6/2026 | In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution. | |
| Modificada | Alta (8.8) | 2.7% | — | Buildah Project BuildahRedhat Openshift Container PlatformRedhat Enterprise Linux | 31/3/2020 | 17/6/2026 | A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions. | |
| Modificada | Alta (7.8) | 0.46% | — | Systemd Project SystemdRedhat Ceph StorageRedhat DiscoveryRedhat Migration Toolkit+3 | 31/3/2020 | 17/6/2026 | A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially… | |
| Modificada | Alta (7) | 0.24% | — | Redhat Openshift Container Platform | 9/3/2020 | 17/6/2026 | It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to… | |
| Modificada | Crítica (9.8) | 5.6% | — | Fasterxml Jackson-databindRedhat Decision ManagerRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+4 | 2/3/2020 | 17/6/2026 | A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code. | |
| Modificada | Alta (7.5) | 5.1% | — | Gpgme Project GpgmeRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM ZRedhat Openshift Container Platform FOR Linuxone+5 | 12/2/2020 | 17/6/2026 | The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification. | |
| Modificada | Alta (7) | 0.43% | — | Linuxfoundation RuncDebian LinuxOpensuse LeapCanonical Ubuntu Linux+1 | 12/2/2020 | 17/6/2026 | runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due… | |
| Modificada | Media (5.9) | 1.8% | — | Libpod Project LibpodRedhat Openshift Container PlatformRedhat Enterprise Linux | 11/2/2020 | 17/6/2026 | A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to… | |
| Modificada | Alta (7) | 0.28% | — | Redhat Openshift Container Platform | 7/2/2020 | 17/6/2026 | It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify… | |
| Modificada | Alta (8.8) | 1.1% | — | Redhat Openshift Container Platform | 7/1/2020 | 17/6/2026 | A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged… | |
| Modificada | Media (6.5) | 0.80% | — | Redhat Openshift Container Platform | 7/1/2020 | 17/6/2026 | OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user. | |
| Modificada | Alta (8.8) | 3.9% | — | Google ChromeFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux+11 | 10/12/2019 | 17/6/2026 | Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 2.0% | — | Kubernetes External-provisionerKubernetes External-resizerKubernetes External-snapshotterRedhat Openshift Container Platform | 5/12/2019 | 17/6/2026 | Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot,… | |
| Modificada | Media (6.5) | 0.99% | — | Redhat Openshift Container Platform | 25/11/2019 | 17/6/2026 | OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user. | |
| Modificada | Media (5) | 0.80% | — | Kubernetes Cri-oFedoraproject FedoraRedhat Openshift Container Platform | 25/11/2019 | 17/6/2026 | A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for the cgroup. An attacker could abuse this flaw to get host network… | |
| Modificada | Media (5.9) | 1.6% | — | Buildah Project BuildahLibpod Project LibpodRedhat Openshift Container PlatformSkopeo Project Skopeo+2 | 25/11/2019 | 17/6/2026 | The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and… | |
| Modificada | Media (6.5) | 0.92% | — | Intel Core I3-10110u FirmwareIntel Core I3-10110y FirmwareIntel Core I3-1005g1 FirmwareIntel Core I3-9300t Firmware+774 | 14/11/2019 | 17/6/2026 | Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access. | |
| Modificada | Media (6.5) | 1.8% | — | Kubernetes Kube-state-metricsRedhat Openshift Container Platform | 5/11/2019 | 17/6/2026 | A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that enabled annotations to be exposed as metrics. By default, the kube-state-metrics metrics only expose metadata about Secrets. However, a combination of the default `kubectl`… | |
| Modificada | Alta (8.8) | 64% | 💥 Exploit | Sudo Project SudoFedoraproject FedoraDebian LinuxOpensuse Leap+11 | 17/10/2019 | 17/6/2026 | In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u… | |
| Analizada | Alta (7.5) | 26% | 💥 Exploit | KubernetesRedhat Openshift Container Platform | 17/10/2019 | 17/6/2026 | Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to… | |
| Modificada | Alta (7.5) | 5.3% | — | Golang GODebian LinuxOpensuse LeapFedoraproject Fedora+5 | 30/9/2019 | 17/6/2026 | Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling. | |
| Modificada | Alta (7.5) | 4.4% | — | Linuxfoundation RuncDockerFedoraproject FedoraOpensuse Leap+6 | 25/9/2019 | 17/6/2026 | runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory. | |
| Modificada | Alta (7.8) | 0.62% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+30 | 17/9/2019 | 17/6/2026 | A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could… | |
| Modificada | Crítica (9.8) | 11% | — | Artifex GhostscriptRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+8 | 6/9/2019 | 17/6/2026 | A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute… |