Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2561▼ 311 respecto a la semana anterior
Críticas / altas1347▲ 84 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.56% | — | NodemailerRedhat Advanced Cluster Management FOR KubernetesRedhat Ceph StorageRedhat Developer HUB | 18/12/2025 | 30/9/2026 | A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser. | |
| Modificada | Alta (7.7) | 0.32% | — | Redhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little EndianRedhat Codeready Linux Builder FOR X86 64+25 | 26/11/2025 | 31/8/2026 | A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow,… | |
| Modificada | Media (5.9) | 94% | — | Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+64 | 18/12/2023 | 17/6/2026 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (6.5) | 1.8% | — | HaproxyRedhat Ceph StorageRedhat Software CollectionsRedhat Openshift Container Platform+5 | 23/3/2023 | 17/6/2026 | An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability. | |
| Modificada | Media (6.5) | 0.57% | — | Redhat Ceph Storage | 6/3/2023 | 17/6/2026 | A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW, causing a denial of service. | |
| Modificada | Media (6.5) | 0.56% | — | Redhat Ceph StorageRedhat Openshift Container StorageRedhat Openshift Data FoundationRedhat Openstack Platform+3 | 25/8/2022 | 17/6/2026 | A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks. | |
| Modificada | Crítica (9.1) | 1.2% | — | Linuxfoundation CephRedhat Ceph StorageFedoraproject Fedora | 25/7/2022 | 17/6/2026 | A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed… | |
| Modificada | Crítica (9.8) | 53% | — | GrafanaRedhat Ceph StorageRedhat Storage | 21/3/2022 | 17/6/2026 | An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to… | |
| Modificada | Crítica (9.1) | 2.8% | — | Lapack Project LapackOpenblas Project OpenblasJulialang JuliaRedhat Ceph Storage+4 | 8/12/2021 | 17/6/2026 | An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory. | |
| Modificada | Crítica (9.8) | 1.6% | — | ZeromqRedhat Ceph StorageRedhat Enterprise LinuxFedoraproject Fedora | 28/5/2021 | 17/6/2026 | A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by sending crafted topic subscription requests and then unsubscribing. The highest threat from this vulnerability is to confidentiality, integrity, as well as system… | |
| Modificada | Media (6.1) | 1.7% | — | Redhat Ceph Storage | 27/5/2021 | 17/6/2026 | A flaw was found in Red Hat Ceph Storage 4, in the Dashboard component. In response to CVE-2020-27839, the JWT token was moved from localStorage to an httpOnly cookie. However, token cookies are used in the body of the HTTP response for the documentation, which again makes it available to XSS.The greatest threat to… | |
| Modificada | Media (5.3) | 2.4% | — | Redhat CephRedhat Ceph StorageFedoraproject Fedora | 18/5/2021 | 17/6/2026 | A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL that ends with two slashes it can cause the rgw to crash, resulting in a denial of service. The greatest threat to the system is of availability. | |
| Modificada | Media (6.5) | 1.6% | — | Redhat CephRedhat Ceph StorageFedoraproject FedoraDebian Linux | 17/5/2021 | 17/6/2026 | A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response… | |
| Modificada | Alta (7.2) | 2.1% | — | Linuxfoundation CephRedhat Ceph StorageFedoraproject FedoraDebian Linux | 15/4/2021 | 17/6/2026 | An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_id can exploit the ability of any user to request a global_id previously associated with another… | |
| Modificada | Media (4.4) | 0.27% | — | Redhat CephRedhat Ceph StorageFedoraproject Fedora | 8/1/2021 | 17/6/2026 | A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible. | |
| Modificada | Alta (7.1) | 0.31% | — | Redhat CephRedhat Ceph StorageRedhat Openshift Container PlatformRedhat Openstack Platform+1 | 18/12/2020 | 17/6/2026 | User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all… | |
| Modificada | Media (5.5) | 0.21% | — | Ceph-ansibleRedhat Ceph Storage | 8/12/2020 | 17/6/2026 | A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality. | |
| Modificada | Alta (8.8) | 1.0% | — | Redhat CephRedhat Ceph StorageRedhat Openshift Container PlatformFedoraproject Fedora | 23/11/2020 | 17/6/2026 | A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with access to the Ceph cluster network to authenticate with the Ceph service via a… | |
| Modificada | Media (6.1) | 1.3% | — | Encode Django Rest FrameworkRedhat Ceph StorageDebian Linux | 30/9/2020 | 17/6/2026 | A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who can control those strings to inject malicious <script> tags, leading to a… | |
| Modificada | Alta (7.1) | 0.23% | — | Redhat Ansible EngineRedhat Ansible TowerRedhat Ceph StorageRedhat Openstack Platform+1 | 23/9/2020 | 17/6/2026 | A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious… | |
| Modificada | Media (6.5) | 1.6% | — | Redhat Ceph StorageRedhat OpenstackFedoraproject FedoraOpensuse Leap+2 | 26/6/2020 | 17/6/2026 | A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made.… | |
| Modificada | Media (5.5) | 0.36% | — | Redhat Ansible EngineRedhat Ansible TowerRedhat Ceph StorageRedhat Openstack+2 | 11/5/2020 | 17/6/2026 | A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when using modules which decrypts vault files such as assemble, script, unarchive, win_copy, aws_s3 or… | |
| Modificada | Media (5.5) | 0.47% | — | GrafanaRedhat Ceph StorageRedhat Enterprise LinuxFedoraproject Fedora | 29/4/2020 | 17/6/2026 | An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords). | |
| Modificada | Media (6.1) | 1.6% | — | Linuxfoundation CephRedhat Ceph StorageRedhat Openshift Container PlatformFedoraproject Fedora+2 | 23/4/2020 | 17/6/2026 | A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input. |