Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
–

36 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.4)0.47%—ChaosproAI18/2/202617/6/2026
ChaosPro 2.0 contains a buffer overflow vulnerability in the configuration file path handling that allows attackers to execute arbitrary code by overwriting the Structured Exception Handler. Attackers can craft a malicious configuration file with carefully constructed payload to overwrite memory and gain remote code…
AnalizadaCrítica (9.8)3.3%—Chaos-mesh Chaos Mesh15/9/202517/6/2026
The cleanIptables mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.
AnalizadaCrítica (9.8)2.8%—Chaos-mesh Chaos Mesh15/9/202517/6/2026
The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.
AnalizadaCrítica (9.8)2.9%—Chaos-mesh Chaos Mesh15/9/202517/6/2026
The cleanTcs mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.
AnalizadaAlta (7.5)0.78%—Chaos-mesh Chaos Mesh15/9/202517/6/2026
The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kubernetes cluster, which provides an API to kill arbitrary processes in any Kubernetes pod, leading to cluster-wide denial of service.
AnalizadaBaja (2.1)0.52%—Litmuschaos Litmus10/8/202517/6/2026
A vulnerability was found in LitmusChaos Litmus up to 3.19.0 and classified as critical. This issue affects some unknown processing of the component LocalStorage Handler. The manipulation leads to permission issues. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The…
AnalizadaBaja (2.1)0.38%—Litmuschaos Litmus10/8/202517/6/2026
A vulnerability has been found in LitmusChaos Litmus up to 3.19.0 and classified as problematic. This vulnerability affects unknown code of the file /auth/delete_project/ of the component Delete Request Handler. The manipulation of the argument projectID leads to missing authorization. The attack can be initiated…
AnalizadaBaja (2.1)0.42%—Litmuschaos Litmus10/8/202517/6/2026
A vulnerability, which was classified as critical, was found in LitmusChaos Litmus up to 3.19.0. This affects an unknown part of the file /auth/login. The manipulation of the argument projectID leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
AnalizadaBaja (1.9)0.24%—Litmuschaos Litmus10/8/202517/6/2026
A vulnerability, which was classified as problematic, has been found in LitmusChaos Litmus up to 3.19.0. Affected by this issue is some unknown functionality of the component LocalStorage Handler. The manipulation of the argument projectID leads to authorization bypass. Local access is required to approach this…
AnalizadaBaja (2.1)0.43%—Litmuschaos Litmus10/8/202517/6/2026
A vulnerability classified as problematic was found in LitmusChaos Litmus up to 3.19.0. Affected by this vulnerability is an unknown functionality. The manipulation of the argument projectID leads to improper control of resource identifiers. The attack can be launched remotely. The exploit has been disclosed to the…
AnalizadaBaja (2.1)1.0%—Litmuschaos Litmus10/8/202517/6/2026
A vulnerability classified as problematic has been found in LitmusChaos Litmus up to 3.19.0. Affected is an unknown function. The manipulation leads to client-side enforcement of server-side security. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor…
AnalizadaBaja (2.1)0.34%—Litmuschaos Litmus10/8/202517/6/2026
A vulnerability was found in LitmusChaos Litmus up to 3.19.0. It has been rated as critical. This issue affects some unknown processing of the file /auth/list_projects. The manipulation of the argument role leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the…
AplazadaMedia (5.4)0.27%—Tiagorlampert ChaosAI25/11/202417/6/2026
A cross-site scripting (XSS) vulnerability in the /scroll.php endpoint of LafeLabs Chaos v0.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
AplazadaAlta (8.6)1.7%—ChaosbladeAI18/9/202417/6/2026
exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd parameter without authentication.
AnalizadaAlta (8.8)0.57%—Chaos-mesh Chaos Mesh24/7/202417/6/2026
Insecure permissions in chaos-mesh v2.6.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
AplazadaMedia (6.5)0.25%—Automattic ChaostheoryAI3/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic ChaosTheory allows Stored XSS.This issue affects ChaosTheory: from n/a through 1.3.
AplazadaCrítica (9.8)1.4%—Tiagorlampert ChaosAI7/5/202417/6/2026
An issue in tiagorlampert CHAOS v5.0.1 before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae669c481ed5e allows a remote attacker to execute arbitrary code via the unsafe concatenation of the `filename` argument into the `buildStr` string without any sanitization or filtering.
AnalizadaMedia (4.8)8.0%—Tiagorlampert Chaos12/4/202417/6/2026
Cross Site Scripting vulnerability in tiagorlampert CHAOS v.5.0.1 allows a remote attacker to escalate privileges via the sendCommandHandler function in the handler.go component.
ModificadaMedia (5.3)0.83%—Netflix Chaos Monkey3/12/202017/6/2026
Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers with Overall/Read permission to access the Chaos Monkey page and to see the history of actions.
ModificadaAlta (7.5)1.3%—Netflix Chaos Monkey3/12/202017/6/2026
Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to generate load and to generate memory leaks.
ModificadaAlta (7.5)1.1%—Chaos Tool Suite Project Ctools7/8/201717/6/2026
ctools 6.x-1.x before 6.x-1.14 and 7.x-1.x before 7.x-1.8 in Drupal does not verify the "edit" permission for the "content type" plugins that are used on Panels and similar systems to place content and functionality on a page.
ModificadaMedia (4.3)2.7%—Fedoraproject FedoraDrupalChaos Tool Suite Project Ctools24/8/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag.
ModificadaMedia (5.8)1.3%—Chaos Tool Suite Project Ctools16/6/201517/6/2026
Open redirect vulnerability in the Chaos tool suite (ctools) module before 6.x-1.12 and 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors involving processing confirmation delete pages.
ModificadaMedia (4.3)1.2%—Chaos Tool Suite Project Ctools15/6/201517/6/2026
The Chaos tool suite (ctools) module 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to obtain sensitive node titles via (1) an autocomplete search on custom entities without an access query tag or (2) leveraging knowledge of the ID of an entity.
ModificadaBaja (3.5)1.8%—Chaos Tool Suite Project Ctools16/7/201316/6/2026
The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict node access, which allows remote authenticated users with the "access content" permission to read restricted node titles via an autocomplete list.