Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

566 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.42%—TaskclusterAI30/9/202630/9/2026
Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes. Prior to version 100.3.0, Taskcluster is vulnerable to unauthenticated RCE on Taskcluster deployments with an anonymous role that exposes the GraphQL endpoint and parses filter arguments using the sift…
Pendiente de análisisAlta (7.5)0.37%—Socket.io Cluster-engineAI29/9/202630/9/2026
Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 0.1.1, @socket.io/cluster-engine uses inherited object properties when looking up attacker-controlled session IDs in clustered deployments. Special property names such as __proto__ or constructor can resolve through the object…
Pendiente de análisisMedia (5.4)0.44%—Open Cluster Management Multicluster Observability AddonAIOpen Cluster Management Addon FrameworkAI18/9/202621/9/2026
A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details,…
Pendiente de análisisAlta (7.7)0.47%—Redhat Multicluster Observability AddonAIRedhat Opentelemetry CollectorAIRedhat Cluster LOG ForwarderAI11/9/202621/9/2026
A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on…
Pendiente de análisisMedia (6.5)0.14%—Clusterlabs PCSAI10/9/202614/9/2026
A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided the files are shorter than 256 bytes. The file contents are read with root privileges by…
Pendiente de análisisAlta (7.7)0.63%—Redhat Multicluster EngineAIRedhat Clusterclaims ControllerAI21/8/202629/9/2026
A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the `spec.namespace` field. This allows the tenant to specify and delete any ManagedCluster, including the hub's…
Pendiente de análisisAlta (7.7)0.53%—Redhat Advanced Cluster ManagementAIRedhat Multicloud Operators SubscriptionAI20/8/202628/8/2026
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This allows the `GetSecret()` function in the HelmRelease controller to fetch…
Pendiente de análisisMedia (5.4)0.35%—Redhat Advanced Cluster Management FOR KubernetesAI20/8/20263/9/2026
A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating EndpointSlices with attacker-controlled IP…
AnalizadaMedia (6.5)0.31%—IBM Reliable Scalable Cluster Technology19/8/20264/9/2026
IBM Reliable Scalable Cluster Technology (RSCT) 3.0 could allow a remote attacker to cause a denial of service by sending a specially crafted request due improper input validation.
Pendiente de análisisCrítica (9.3)0.62%—Redhat Multicluster Engine FOR KubernetesAI19/8/202629/9/2026
A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the attacker can proxy requests to arbitrary…
Pendiente de análisisMedia (4.3)1.0%—Jboss MOD ClusterAI19/8/202620/8/2026
A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single crafted UDP multicast datagram with a valid HTTP status line and a "Server:" header but without the "Date:", "Digest:", and "Sequence:" headers triggers a NullPointerException in verifyDigest() that is not caught by…
AnalizadaAlta (7.5)0.33%—Oracle Mysql Cluster18/8/20264/9/2026
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 8.0.0-8.0.48, 8.4.0-8.4.11 and 9.7.0-9.7.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Cluster. Successful attacks…
AnalizadaAlta (8.2)0.38%—Oracle Mysql Cluster18/8/20262/9/2026
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that are affected are 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster.…
Pendiente de análisisMedia (4.4)0.35%—Submariner-operatorAIRedhat Advanced Cluster Management FOR KubernetesAI18/8/20263/9/2026
A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker…
Pendiente de análisisMedia (5.5)0.19%—Redhat Advanced Cluster Management FOR KubernetesAI18/8/20265/9/2026
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exposes proxy basic-auth credentials in the must-gather archive, potentially…
Pendiente de análisisMedia (5.5)0.11%—Redhat Advanced Cluster Management FOR KubernetesAI18/8/20265/9/2026
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in cleartext in the resulting archive,…
Pendiente de análisisAlta (8.8)0.81%—Redhat Advanced Cluster Management FOR KubernetesAIRedhat Governance Policy Addon ControllerAI18/8/202627/8/2026
A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with…
Pendiente de análisisCrítica (9.9)0.49%—Open Cluster Management Managedcluster Import ControllerAI17/8/202629/9/2026
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to…
Pendiente de análisisAlta (7.1)0.35%—Redhat Multicluster EngineAIRedhat Clusterclaims ControllerAI13/8/202629/9/2026
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable…
ModificadaMedia (6.5)0.16%—Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client12/8/20265/9/2026
A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive privilege means that a compromise of the insights-client pod or ServiceAccount…
Pendiente de análisisCrítica (9.9)0.81%—Redhat Advanced Cluster ManagementAI12/8/202627/8/2026
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly privileged ServiceAccount (SA). This enables…
Pendiente de análisisMedia (5.8)0.40%—Redhat Multicluster EngineAI12/8/202629/9/2026
A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vulnerability. By manipulating `copiedFrom` labels, the attacker could intercept…
Pendiente de análisisCrítica (9.9)0.56%—Cluster-curator-controllerAI12/8/202629/9/2026
A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control.…
Pendiente de análisisCrítica (9.9)0.88%—Redhat Multicluster EngineAIRedhat Cluster Curator ControllerAI12/8/202629/9/2026
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the…
Pendiente de análisisAlta (7.7)0.48%—Redhat Advanced Cluster ManagementAIRedhat Multicloud Operators ChannelAI12/8/202627/8/2026
A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets and ConfigMaps within any Channel…