Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.9) | 0.65% | — | ProwlerAIKubernetesAIGoogle Cloud Platform GCPAI | 12/8/2026 | 9/9/2026 | Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args because kubeconfig_contains_exec_auth in api/src/backend/api/v1/serializers.py checked only exec blocks, and POST… | |
| Modificada | Media (5.5) | 0.35% | — | Oracle VirtualizationRedhat AnsibleRedhat Ansible TowerRedhat Cisco Nx-os Collection+4 | 26/5/2021 | 17/6/2026 | A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality.… | |
| Modificada | Media (4.9) | 0.34% | — | Silver-peak Unity Edgeconnect FOR Amazon WEB ServicesSilver-peak Unity Edgeconnect FOR AzureSilver-peak Unity Edgeconnect FOR Google Cloud PlatformSilver-peak Unity Orchestrator+20 | 5/5/2020 | 17/6/2026 | The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted portal. | |
| Modificada | Media (4.9) | 0.34% | — | Silver-peak Unity Edgeconnect FOR Amazon WEB ServicesSilver-peak Unity Edgeconnect FOR AzureSilver-peak Unity Edgeconnect FOR Google Cloud PlatformSilver-peak Unity Orchestrator+20 | 5/5/2020 | 17/6/2026 | The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator. | |
| Modificada | Media (4.9) | 0.72% | — | Silver-peak Unity Edgeconnect FOR Amazon WEB ServicesSilver-peak Unity Edgeconnect FOR AzureSilver-peak Unity Edgeconnect FOR Google Cloud PlatformSilver-peak Unity Orchestrator+20 | 5/5/2020 | 17/6/2026 | 1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could use this material to decrypt in-flight communication. 2. The vulnerability requires administrative access and shell… | |
| Modificada | Alta (7.8) | 2.1% | — | Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+51 | 5/8/2019 | 17/6/2026 | CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials. |