Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 354 respecto a la semana anterior
Críticas / altas1295▼ 24 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.1) | 0.29% | — | Redhat Automation-controllerAIAnsible-coreAI | 23/9/2026 | 24/9/2026 | — | |
| Pendiente de análisis | Baja (3.1) | 0.21% | — | Ansible-coreAI | 23/9/2026 | 24/9/2026 | — | |
| Pendiente de análisis | Alta (7.8) | 0.17% | — | Ansible-coreAI | 21/7/2026 | 4/9/2026 | A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone commands without a '--' (end-of-options) separator before user-supplied URLs when installing collections from git sources. An attacker who provides a crafted collection… | |
| Pendiente de análisis | Alta (7.8) | 0.22% | — | Ansible-coreAI | 5/6/2026 | 15/9/2026 | A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows… | |
| Aplazada | Media (5.5) | 0.50% | — | Ansible-coreAI | 12/11/2024 | 30/6/2026 | A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks. | |
| Aplazada | Media (6.3) | 0.26% | — | Ansible-coreAI | 6/11/2024 | 17/6/2026 | A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against the unprivileged user's home directory. If the unprivileged user has… |