Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.4) | 0.47% | — | ChaosproAI | 18/2/2026 | 17/6/2026 | ChaosPro 2.0 contains a buffer overflow vulnerability in the configuration file path handling that allows attackers to execute arbitrary code by overwriting the Structured Exception Handler. Attackers can craft a malicious configuration file with carefully constructed payload to overwrite memory and gain remote code… | |
| Analizada | Crítica (9.8) | 3.3% | — | Chaos-mesh Chaos Mesh | 15/9/2025 | 17/6/2026 | The cleanIptables mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster. | |
| Analizada | Crítica (9.8) | 2.8% | — | Chaos-mesh Chaos Mesh | 15/9/2025 | 17/6/2026 | The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster. | |
| Analizada | Crítica (9.8) | 2.9% | — | Chaos-mesh Chaos Mesh | 15/9/2025 | 17/6/2026 | The cleanTcs mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster. | |
| Analizada | Alta (7.5) | 0.78% | — | Chaos-mesh Chaos Mesh | 15/9/2025 | 17/6/2026 | The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kubernetes cluster, which provides an API to kill arbitrary processes in any Kubernetes pod, leading to cluster-wide denial of service. | |
| Analizada | Baja (2.1) | 0.52% | — | Litmuschaos Litmus | 10/8/2025 | 17/6/2026 | A vulnerability was found in LitmusChaos Litmus up to 3.19.0 and classified as critical. This issue affects some unknown processing of the component LocalStorage Handler. The manipulation leads to permission issues. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The… | |
| Analizada | Baja (2.1) | 0.38% | — | Litmuschaos Litmus | 10/8/2025 | 17/6/2026 | A vulnerability has been found in LitmusChaos Litmus up to 3.19.0 and classified as problematic. This vulnerability affects unknown code of the file /auth/delete_project/ of the component Delete Request Handler. The manipulation of the argument projectID leads to missing authorization. The attack can be initiated… | |
| Analizada | Baja (2.1) | 0.42% | — | Litmuschaos Litmus | 10/8/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in LitmusChaos Litmus up to 3.19.0. This affects an unknown part of the file /auth/login. The manipulation of the argument projectID leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Baja (1.9) | 0.24% | — | Litmuschaos Litmus | 10/8/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in LitmusChaos Litmus up to 3.19.0. Affected by this issue is some unknown functionality of the component LocalStorage Handler. The manipulation of the argument projectID leads to authorization bypass. Local access is required to approach this… | |
| Analizada | Baja (2.1) | 0.43% | — | Litmuschaos Litmus | 10/8/2025 | 17/6/2026 | A vulnerability classified as problematic was found in LitmusChaos Litmus up to 3.19.0. Affected by this vulnerability is an unknown functionality. The manipulation of the argument projectID leads to improper control of resource identifiers. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Baja (2.1) | 1.0% | — | Litmuschaos Litmus | 10/8/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in LitmusChaos Litmus up to 3.19.0. Affected is an unknown function. The manipulation leads to client-side enforcement of server-side security. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor… | |
| Analizada | Baja (2.1) | 0.34% | — | Litmuschaos Litmus | 10/8/2025 | 17/6/2026 | A vulnerability was found in LitmusChaos Litmus up to 3.19.0. It has been rated as critical. This issue affects some unknown processing of the file /auth/list_projects. The manipulation of the argument role leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (5.4) | 0.27% | — | Tiagorlampert ChaosAI | 25/11/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the /scroll.php endpoint of LafeLabs Chaos v0.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Aplazada | Alta (8.6) | 1.7% | — | ChaosbladeAI | 18/9/2024 | 17/6/2026 | exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd parameter without authentication. | |
| Analizada | Alta (8.8) | 0.57% | — | Chaos-mesh Chaos Mesh | 24/7/2024 | 17/6/2026 | Insecure permissions in chaos-mesh v2.6.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. | |
| Aplazada | Media (6.5) | 0.25% | — | Automattic ChaostheoryAI | 3/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic ChaosTheory allows Stored XSS.This issue affects ChaosTheory: from n/a through 1.3. | |
| Aplazada | Crítica (9.8) | 1.4% | — | Tiagorlampert ChaosAI | 7/5/2024 | 17/6/2026 | An issue in tiagorlampert CHAOS v5.0.1 before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae669c481ed5e allows a remote attacker to execute arbitrary code via the unsafe concatenation of the `filename` argument into the `buildStr` string without any sanitization or filtering. | |
| Analizada | Media (4.8) | 8.0% | — | Tiagorlampert Chaos | 12/4/2024 | 17/6/2026 | Cross Site Scripting vulnerability in tiagorlampert CHAOS v.5.0.1 allows a remote attacker to escalate privileges via the sendCommandHandler function in the handler.go component. | |
| Modificada | Media (5.3) | 0.83% | — | Netflix Chaos Monkey | 3/12/2020 | 17/6/2026 | Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers with Overall/Read permission to access the Chaos Monkey page and to see the history of actions. | |
| Modificada | Alta (7.5) | 1.3% | — | Netflix Chaos Monkey | 3/12/2020 | 17/6/2026 | Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to generate load and to generate memory leaks. | |
| Modificada | Alta (7.5) | 1.1% | — | Chaos Tool Suite Project Ctools | 7/8/2017 | 17/6/2026 | ctools 6.x-1.x before 6.x-1.14 and 7.x-1.x before 7.x-1.8 in Drupal does not verify the "edit" permission for the "content type" plugins that are used on Panels and similar systems to place content and functionality on a page. | |
| Modificada | Media (4.3) | 2.7% | — | Fedoraproject FedoraDrupalChaos Tool Suite Project Ctools | 24/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag. | |
| Modificada | Media (5.8) | 1.3% | — | Chaos Tool Suite Project Ctools | 16/6/2015 | 17/6/2026 | Open redirect vulnerability in the Chaos tool suite (ctools) module before 6.x-1.12 and 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors involving processing confirmation delete pages. | |
| Modificada | Media (4.3) | 1.2% | — | Chaos Tool Suite Project Ctools | 15/6/2015 | 17/6/2026 | The Chaos tool suite (ctools) module 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to obtain sensitive node titles via (1) an autocomplete search on custom entities without an access query tag or (2) leveraging knowledge of the ID of an entity. | |
| Modificada | Baja (3.5) | 1.8% | — | Chaos Tool Suite Project Ctools | 16/7/2013 | 16/6/2026 | The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict node access, which allows remote authenticated users with the "access content" permission to read restricted node titles via an autocomplete list. |