Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.79% | — | Acryl DatahubAI | 17/8/2026 | 9/9/2026 | A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, and it fails to return the content or any errors directly. | |
| Pendiente de análisis | Alta (8.8) | 0.60% | — | Opendatahub ODH DashboardAI | 10/8/2026 | 14/8/2026 | A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges to cluster-administrator level, gain access to sensitive data like… | |
| Analizada | Alta (7.1) | 0.22% | — | Datahub | 14/5/2026 | 17/6/2026 | DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java objects from the REDIRECT_URL HTTP cookie during the OIDC callback flow, with no integrity protection (no HMAC, no encryption). This is a Deserialization of Untrusted Data… | |
| Analizada | Alta (7.5) | 0.40% | — | Datahub | 6/2/2026 | 17/6/2026 | DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable to MITM attack through TLS downgrade. This issue has been patched in version 1.3.1.8. | |
| Aplazada | Alta (8.8) | 0.60% | — | OS Datahub MapsAI | 3/2/2026 | 17/6/2026 | The OS DataHub Maps plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'OS_DataHub_Maps_Admin::add_file_and_ext' function in all versions up to, and including, 1.8.3. This makes it possible for authenticated attackers, with Author-level access and above, to upload… | |
| Analizada | Crítica (9.1) | 0.60% | — | Datahub-helm | 20/3/2024 | 17/6/2026 | datahub-helm provides the Kubernetes Helm charts for deploying Datahub and its dependencies on a Kubernetes cluster. Starting in version 0.1.143 and prior to version 0.2.182, due to configuration issues in the helm chart, if there was a successful initial deployment during a limited window of time, personal access… | |
| Modificada | Alta (8.8) | 0.65% | — | Datahub Project Datahub | 16/1/2024 | 17/6/2026 | DataHub is an open-source metadata platform. In affected versions a low privileged user could remove a user, edit group members, or edit another user's profile information. The default privileges gave too many broad permissions to low privileged users. These have been constrained in PR #9067 to prevent abuse. This… | |
| Modificada | Alta (8.8) | 0.36% | — | Datahub Project Datahub | 14/11/2023 | 17/6/2026 | DataHub is an open-source metadata platform. The HMAC signature for DataHub Frontend sessions was being signed using a SHA-1 HMAC with the frontend secret key. SHA1 with a 10 byte key can be brute forced using sufficient resources (i.e. state level actors with large computational capabilities). DataHub Frontend was… | |
| Modificada | Alta (8) | 0.47% | — | Datahub Project Datahub | 14/11/2023 | 17/6/2026 | DataHub is an open-source metadata platform. In affected versions sign-up through an invite link does not properly restrict users from signing up as privileged accounts. If a user is given an email sign-up link they can potentially create an admin account given certain preconditions. If the default datahub user has… | |
| Modificada | Media (4.8) | 0.38% | — | Datahub Project Datahub | 14/11/2023 | 17/6/2026 | DataHub is an open-source metadata platform. DataHub Frontend's sessions are configured using Play Framework's default settings for stateless session which do not set an expiration time for a cookie. Due to this, if a session cookie were ever leaked, it would be valid forever. DataHub uses a stateless session cookie… | |
| Modificada | Alta (7.5) | 0.47% | — | Opendatahub Open Data HUB DashboardRedhat Openshift Data Science | 4/10/2023 | 17/6/2026 | A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the generated output instead of an ID for a Kubernetes secret. | |
| Modificada | Crítica (9.8) | 0.37% | — | Datahub | 11/2/2023 | 17/6/2026 | DataHub is an open-source metadata platform. In versions of DataHub prior to 0.8.45 Session cookies are only cleared on new sign-in events and not on logout events. Any authentication checks using the `AuthUtils.hasValidSessionCookie()` method could be bypassed by using a cookie from a logged out session, as a result… | |
| Modificada | Crítica (9.8) | 0.39% | — | Datahub | 11/2/2023 | 17/6/2026 | DataHub is an open-source metadata platform. In the event a system is using Java Authentication and Authorization Service (JAAS) authentication and that system is given a configuration which contains an error, the authentication for the system will fail open and allow an attacker to login using any username and… | |
| Modificada | Crítica (9.8) | 0.63% | — | Datahub | 11/2/2023 | 17/6/2026 | DataHub is an open-source metadata platform. The AuthServiceClient which is responsible for creation of new accounts, verifying credentials, resetting them or requesting access tokens, crafts multiple JSON strings using format strings with user-controlled data. This means that an attacker may be able to augment these… | |
| Modificada | Alta (8.1) | 0.52% | — | Datahub | 11/2/2023 | 17/6/2026 | DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is the default configuration, the Metadata service (GMS) will use the X-DataHub-Actor HTTP header to infer the user the frontend is sending the request on behalf of. When the backends retrieves the header, its… | |
| Modificada | Alta (8.8) | 1.0% | — | Datahub Project Datahub | 11/2/2023 | 17/6/2026 | DataHub is an open-source metadata platform. When the DataHub frontend is configured to authenticate via SSO, it will leverage the pac4j library. The processing of the `id_token` is done in an unsafe manner which is not properly accounted for by the DataHub frontend. Specifically, if any of the id_token claims value… | |
| Modificada | Crítica (9.1) | 0.68% | — | Datahub | 11/2/2023 | 17/6/2026 | DataHub is an open-source metadata platform. The DataHub frontend acts as a proxy able to forward any REST or GraphQL requests to the backend. The goal of this proxy is to perform authentication if needed and forward HTTP requests to the DataHub Metadata Store (GMS). It has been discovered that the proxy does not… | |
| Modificada | Crítica (9.8) | 0.93% | — | Datahub | 28/10/2022 | 17/6/2026 | DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadata service (GMS) does not verify the signature of JWT tokens. This allows an attacker to connect to DataHub instances as any user if Metadata Service authentication is enabled. This vulnerability… | |
| Modificada | Alta (7.8) | 1.3% | — | Cogentdatahub Cogent Datahub | 29/3/2016 | 17/6/2026 | Cogent DataHub before 7.3.10 allows local users to gain privileges by leveraging the user or guest role to modify a file. | |
| Modificada | Media (5) | 0.69% | — | Cogentdatahub Cogent Datahub | 30/5/2014 | 17/6/2026 | Cogent DataHub before 7.3.5 does not use a salt during password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack. | |
| Modificada | Media (4.3) | 2.5% | — | Cogentdatahub Cogent Datahub | 30/5/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.4) | 2.3% | — | Cogentdatahub Cogent Datahub | 30/5/2014 | 17/6/2026 | The directory specifier can include designators that can be used to traverse the directory path. Exploiting this vulnerability may enable an attacker to access a limited number of hardcoded file types. Further exploitation of this vulnerability may allow an attacker to cause the web server component to enter a… | |
| Modificada | Alta (7.5) | 63% | — | Cogentdatahub Cogent Datahub | 22/5/2014 | 17/6/2026 | GetPermissions.asp in Cogent Real-Time Systems Cogent DataHub before 7.3.5 allows remote attackers to execute arbitrary commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 4.0% | — | Cogentdatahub Cogent Datahub | 22/5/2014 | 17/6/2026 | Heap-based buffer overflow in the Web Server in Cogent Real-Time Systems Cogent DataHub before 7.3.5 allows remote attackers to execute arbitrary code via a negative value in the Content-Length field in a request. | |
| Modificada | Alta (7.1) | 0.99% | — | Cogentdatahub Cogent DatahubCogentdatahub OPC DatahubCogentdatahub Cascade DatahubCogentdatahub Datahub Quicktrend | 5/4/2013 | 16/6/2026 | The DataSim and DataPid demonstration clients in Cogent Real-Time Systems Cogent DataHub before 7.3.0, OPC DataHub before 6.4.22, Cascade DataHub before 6.4.22 on Windows, and DataHub QuickTrend before 7.3.0 allow remote servers to cause a denial of service (incorrect pointer access and client crash) via malformed… |