Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2700▼ 69 respecto a la semana anterior
Críticas / altas1449▲ 307 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.8)1.3%—LibsnowflakeclientAISnowflake PHP PDO DriverAISnowflake Odbc DriverAI24/7/202630/7/2026
Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could exploit this by uploading a file with a…
AnalizadaAlta (7.5)0.27%—CMU Cveclient2/4/202624/7/2026
The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of the encryption credentials.
AnalizadaMedia (6.1)0.25%—CMU Cveclient2/4/202624/7/2026
XSS vulnerability in cveInterface.js allows for inject HTML to be passed to display, as cveInterface trusts input from CVE API services
ModificadaAlta (8.1)0.94%—Redhat Kubeclient25/3/202217/6/2026
A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeconfig files. When the kubeconfig file does not configure custom CA to verify certs, kubeclient ends up accepting any certificate (it wrongly returns VERIFY_NONE). Ruby…
ModificadaCrítica (9.8)2.0%—Openstack Python-keystoneclientRedhat OpenstackDebian Linux10/12/201916/6/2026
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
ModificadaCrítica (9.8)2.1%—Openstack Python-keystoneclientRedhat OpenstackFedoraproject FedoraDebian Linux10/12/201916/6/2026
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
ModificadaMedia (4.3)2.6%—Openstack KeystonemiddlewareOpenstack Python-keystoneclientCanonical Ubuntu Linux17/4/201517/6/2026
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a…
ModificadaMedia (4.3)2.0%—Openstack KeystonemiddlewareOpenstack Python-keystoneclient2/10/201417/6/2026
OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted…
ModificadaMedia (6)1.1%—Openstack Python-keystoneclient15/4/201417/6/2026
The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an…
ModificadaMedia (5.5)2.1%—Openstack Python-keystoneclient21/1/201416/6/2026
python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.
ModificadaBaja (2.1)0.37%—Openstack Python-keystoneclient1/10/201316/6/2026
The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.
ModificadaMedia (5.8)0.99%—Openstack Python GlanceclientOpensuse28/8/201316/6/2026
The Python client library for Glance (python-glanceclient) before 0.10.0 does not properly check the preverify_ok value, which prevents the server hostname from being verified with a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate and allows man-in-the-middle attackers to…
ModificadaAlta (7.5)1.1%—Infor EclientInfor Enspire Distribution Management Solution1/11/201116/6/2026
SQL injection vulnerability in eClient 7.3.2.3 in Enspire Distribution Management Solution 7.3.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.8)0.34%—Checkpoint Vpn-1 Secureclient8/2/200816/6/2026
The Auto Local Logon feature in Check Point VPN-1 SecuRemote/SecureClient NGX R60 and R56 for Windows caches credentials under the Checkpoint\SecuRemote registry key, which has Everyone/Full Control permissions, which allows local users to gain privileges by reading and reusing the credentials.
ModificadaMedia (6.5)3.1%—Checkpoint Secureclient NGCheckpoint Vpn-1 Secureclient8/12/200516/6/2026
Check Point VPN-1 SecureClient NG with Application Intelligence R56, NG FP1, 4.0, and 4.1 allows remote attackers to bypass security policies by modifying the local copy of the local.scv policy file after it has been downloaded from the VPN Endpoint.