Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2700▼ 69 respecto a la semana anterior
Críticas / altas1449▲ 307 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 1.3% | — | LibsnowflakeclientAISnowflake PHP PDO DriverAISnowflake Odbc DriverAI | 24/7/2026 | 30/7/2026 | Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could exploit this by uploading a file with a… | |
| Analizada | Alta (7.5) | 0.27% | — | CMU Cveclient | 2/4/2026 | 24/7/2026 | The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of the encryption credentials. | |
| Analizada | Media (6.1) | 0.25% | — | CMU Cveclient | 2/4/2026 | 24/7/2026 | XSS vulnerability in cveInterface.js allows for inject HTML to be passed to display, as cveInterface trusts input from CVE API services | |
| Modificada | Alta (8.1) | 0.94% | — | Redhat Kubeclient | 25/3/2022 | 17/6/2026 | A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeconfig files. When the kubeconfig file does not configure custom CA to verify certs, kubeclient ends up accepting any certificate (it wrongly returns VERIFY_NONE). Ruby… | |
| Modificada | Crítica (9.8) | 2.0% | — | Openstack Python-keystoneclientRedhat OpenstackDebian Linux | 10/12/2019 | 16/6/2026 | python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass | |
| Modificada | Crítica (9.8) | 2.1% | — | Openstack Python-keystoneclientRedhat OpenstackFedoraproject FedoraDebian Linux | 10/12/2019 | 16/6/2026 | python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass | |
| Modificada | Media (4.3) | 2.6% | — | Openstack KeystonemiddlewareOpenstack Python-keystoneclientCanonical Ubuntu Linux | 17/4/2015 | 17/6/2026 | The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a… | |
| Modificada | Media (4.3) | 2.0% | — | Openstack KeystonemiddlewareOpenstack Python-keystoneclient | 2/10/2014 | 17/6/2026 | OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted… | |
| Modificada | Media (6) | 1.1% | — | Openstack Python-keystoneclient | 15/4/2014 | 17/6/2026 | The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an… | |
| Modificada | Media (5.5) | 2.1% | — | Openstack Python-keystoneclient | 21/1/2014 | 16/6/2026 | python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires. | |
| Modificada | Baja (2.1) | 0.37% | — | Openstack Python-keystoneclient | 1/10/2013 | 16/6/2026 | The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process. | |
| Modificada | Media (5.8) | 0.99% | — | Openstack Python GlanceclientOpensuse | 28/8/2013 | 16/6/2026 | The Python client library for Glance (python-glanceclient) before 0.10.0 does not properly check the preverify_ok value, which prevents the server hostname from being verified with a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate and allows man-in-the-middle attackers to… | |
| Modificada | Alta (7.5) | 1.1% | — | Infor EclientInfor Enspire Distribution Management Solution | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in eClient 7.3.2.3 in Enspire Distribution Management Solution 7.3.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.8) | 0.34% | — | Checkpoint Vpn-1 Secureclient | 8/2/2008 | 16/6/2026 | The Auto Local Logon feature in Check Point VPN-1 SecuRemote/SecureClient NGX R60 and R56 for Windows caches credentials under the Checkpoint\SecuRemote registry key, which has Everyone/Full Control permissions, which allows local users to gain privileges by reading and reusing the credentials. | |
| Modificada | Media (6.5) | 3.1% | — | Checkpoint Secureclient NGCheckpoint Vpn-1 Secureclient | 8/12/2005 | 16/6/2026 | Check Point VPN-1 SecureClient NG with Application Intelligence R56, NG FP1, 4.0, and 4.1 allows remote attackers to bypass security policies by modifying the local copy of the local.scv policy file after it has been downloaded from the VPN Endpoint. |