Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

1488 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.8)0.13%—Rapid7 InsightvmAI24/9/202626/9/2026
An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable resolved from the machine PATH. Assessment content at or below version 0.0.261.0 included a check that invoked the…
AnalizadaAlta (7.2)1.0%—Microsoft Azure Hdinsight8/9/202623/9/2026
Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.
ModificadaMedia (6.5)0.16%—Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client12/8/20265/9/2026
A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive privilege means that a compromise of the insights-client pod or ServiceAccount…
ModificadaAlta (7.7)0.50%—Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client11/8/20265/9/2026
A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to level 2 or higher, the token is written in clear text to the pod log on every…
ModificadaMedia (6.8)0.69%—Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client11/8/20265/9/2026
A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the request path without proper validation or URL encoding. This vulnerability…
ModificadaMedia (6.5)0.16%—Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client11/8/20265/9/2026
A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read this long-lived credential. This information disclosure could grant unauthorized…
Pendiente de análisisMedia (6.5)0.24%—SssdAIRedhat Insights-coreAIClusterlabs PacemakerAI11/8/202614/8/2026
A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in archives uploaded to console.redhat.com.
AnalizadaAlta (8.8)1.0%—Microsoft Application Insights Profiler7/8/202617/8/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.
AplazadaCrítica (10)0.52%—Monsterinsights PROAI6/8/202626/8/2026
The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct variants were observed on 2026-06-11, all…
AnalizadaMedia (5.3)0.40%—IBM Business Automation Insights5/8/202610/8/2026
IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files.
AplazadaBaja (3.7)0.25%—MonsterinsightsAI4/8/202626/8/2026
The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPress plugin before 11.1.0 is not connected to Google Analytics the HMAC signing key is empty, which lets unauthenticated attackers forge a valid…
Pendiente de análisisAlta (7.8)0.16%—Rapid7 InsightvmAIRapid7 NexposeAIRapid7 Insight AgentAI24/7/202630/7/2026
Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight…
Pendiente de análisisMedia (4.8)0.38%—Rapid7 Insightconnect Markdown PluginAI26/6/202624/7/2026
Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin on Linux in versions prior to 4.0.2 allows remote attackers to make arbitrary outbound HTTP requests via unsanitized resource-loading HTML elements (img/src, CSS url(), @import) embedded in Markdown input. The initial…
AnalizadaMedia (4.3)0.29%—Rapid7 Insightconnect Compression25/6/202629/6/2026
Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file paths via crafted filename input. The impact is limited to file corruption as content cannot be controlled by the attacker.
AnalizadaAlta (8.8)1.3%—Rapid7 Insightconnect Tcpdump25/6/202629/6/2026
OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the options or filter parameters due to insufficient input sanitization in shell command construction.
AnalizadaCrítica (9.8)1.2%—Rapid7 Insightconnect Traceroute25/6/202629/6/2026
OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host, port, max_ttl, count, or time_out request parameters due to insufficient input validation when constructing shell commands.
AnalizadaCrítica (9.8)1.2%—Rapid7 Insightconnect Translate25/6/202629/6/2026
OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to insufficient input sanitization in shell command construction.
AnalizadaAlta (8.8)1.3%—Rapid7 Insightconnect Finger25/6/202629/6/2026
OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the user or host parameters due to insufficient input validation in shell command construction.
AnalizadaCrítica (9.8)1.2%—Rapid7 Insightconnect Ping25/6/202629/6/2026
OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host parameter due to insufficient input validation when constructing shell commands.
AnalizadaCrítica (9.8)1.2%—Rapid7 Insightconnect AWK25/6/202629/6/2026
OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to unsafe shell command construction in the processing pipeline.
AnalizadaAlta (8.8)1.3%—Rapid7 Insightconnect RPM25/6/202629/6/2026
OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the repo, key, or name parameters due to insufficient input sanitization in shell command construction.
AnalizadaAlta (8.8)1.3%—Rapid7 Insightconnect Sqlmap25/6/202629/6/2026
OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the api_host or api_port parameters during connection configuration due to insufficient input validation.
AplazadaCrítica (9.8)0.56%—WP InsightlyAI15/6/202617/6/2026
Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.
AplazadaAlta (7.1)0.40%—MonsterinsightsAI12/5/202617/6/2026
The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability checks on the get_ads_access_token() and reset_experience() functions in all versions up to, and including, 10.1.2.…
AnalizadaCrítica (9.9)0.77%—Microsoft Dynamics 365 Customer Insights12/5/202617/6/2026
Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network.