Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.78% | — | Opentelemetry Propagator JaegerAI | 8/7/2026 | 10/7/2026 | OpenTelemetry JavaScript is the OpenTelemetry JavaScript client. Prior to 2.9.0, @opentelemetry/propagator-jaeger decodes incoming uber-trace-id and uberctx-* HTTP header values with decodeURIComponent() without handling decode errors, allowing an unauthenticated remote attacker to send a malformed percent-encoded… | |
| Aplazada | Media (4.3) | 0.39% | — | Tempo OperatorAIJaeger UIAI | 2/4/2025 | 8/9/2026 | A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterRole. This can be exploited if a user… | |
| Modificada | Media (5.4) | 1.1% | — | Jaegertracing Jaeger UI | 17/7/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Jaegertracing Jaeger UI before v.1.31.0 allows a remote attacker to execute arbitrary code via the KeyValuesTable component. | |
| Modificada | Crítica (9.4) | 0.66% | — | ABB MybuildingsMybusch-jaeger | 27/9/2021 | 17/6/2026 | The vulnerability origins in the commissioning process where an attacker of the ControlTouch can enter a serial number in a specific way to transfer the device virtually into her/his my.busch-jaeger.de or mybuildings.abb.com profile. A successful attacker can observe and control a ControlTouch remotely under very… | |
| Modificada | Media (5.5) | 0.43% | — | Linuxfoundation Jaeger | 19/6/2020 | 17/6/2026 | Sensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when the Kafka data store is used. This flaw allows an attacker with access to the container's log file to discover the Kafka credentials. | |
| Modificada | Media (5.5) | 0.23% | — | ABB Tg/s3.2 FirmwareBusch-jaeger 6186/11 Firmware | 22/4/2020 | 17/6/2026 | The Configuration pages in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway for user profiles and services transfer the password in plaintext (although hidden when displayed). | |
| Modificada | Crítica (9.1) | 1.3% | — | ABB Tg/s3.2 FirmwareBusch-jaeger 6186/11 Firmware | 22/4/2020 | 17/6/2026 | Improper implementation of Access Control in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows an unauthorized user to access data marked as restricted, such as viewing or editing user profiles and application settings. | |
| Modificada | Media (5.5) | 0.30% | — | ABB Tg/s3.2 FirmwareBusch-jaeger 6186/11 Firmware | 22/4/2020 | 17/6/2026 | The backup function in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway saves the current settings and configuration of the application, including credentials of existing user accounts and other configuration's credentials in plaintext. | |
| Modificada | Crítica (9.8) | 1.4% | — | ABB Tg/s3.2 FirmwareBusch-jaeger 6186/11 Firmware | 22/4/2020 | 17/6/2026 | The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows access to different endpoints of the application without authenticating by accessing a specific uniform resource locator (URL) , violating the access-control (ACL) rules. This issue allows obtaining sensitive information… | |
| Modificada | Media (4.3) | 1.2% | — | Kristof DE Jaeger Display Suite | 25/6/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-1.x before 7.x-1.7 and 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via an entity bundle label. | |
| Modificada | Media (6) | 1.8% | — | Kristof DE Jaeger Bundle Copy | 14/8/2012 | 16/6/2026 | The Bundle copy module 7.x-1.x before 7.x-1.1 for Drupal does not check for the "use PHP for settings" permission while importing settings, which allows remote authenticated users with certain permissions to execute arbitrary PHP code via unspecified vectors. | |
| Modificada | Media (5) | 1.2% | — | Kristof DE Jaeger Commentreference | 31/12/2009 | 16/6/2026 | The CCK Comment Reference module 5.x before 5.x-1.2 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to bypass intended access restrictions and read comments by using the autocomplete path. |