Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 0.31% | — | KatelloAI | 1/10/2026 | 2/10/2026 | A flaw was found in rubygem-katello. The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registry_authorize filter. While the application identifies unauthorized requests and triggers an error response via the unauthorized method, it fails to… | |
| Pendiente de análisis | Media (6.5) | 0.27% | — | Redhat Satellite KatelloAI | 1/10/2026 | 2/10/2026 | A flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController. The methods check_blob_push_org_label and get_matching_products_from_org take… | |
| Pendiente de análisis | Baja (2.1) | 0.30% | — | KatexAI | 1/10/2026 | 2/10/2026 | KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. From 0.11.0 until 0.18.2, KaTeX uses ordinary JavaScript property access for the renderer options object, the trust setting, default and processor setting metadata, and namespace lookup and group restoration, allowing inherited… | |
| Pendiente de análisis | Media (5.4) | 0.24% | — | KatelloAI | 27/8/2026 | 28/8/2026 | A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the parent Content View Filter. An authenticated, low-privileged user with Content View permissions in one organization may be able to access and modify filter rules belonging to a Content View Filter in… | |
| Pendiente de análisis | Media (4.3) | 0.37% | — | KatelloAI | 26/8/2026 | 2/10/2026 | A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may be able to access the lifecycle history of a Content View belonging to another… | |
| Pendiente de análisis | Media (4.3) | 0.22% | — | Redhat SatelliteAIRedhat KatelloAI | 17/6/2026 | 4/8/2026 | A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization checks in the ContentUploadsController allowed users with the edit_products permission to query content information for repositories outside the products they were authorized to manage. An authenticated… | |
| Pendiente de análisis | Media (5.4) | 0.43% | — | Redhat SatelliteAIRedhat KatelloAI | 17/3/2026 | 17/6/2026 | A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of user-provided input, allows a remote attacker to inject arbitrary SQL commands into the sort_by parameter of the /api/hosts/bootc_images API endpoint. This can lead to a Denial of Service (DoS) by… | |
| Modificada | Alta (8.1) | 0.50% | — | Axiomthemes Katelyn | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Katelyn katelyn allows PHP Local File Inclusion.This issue affects Katelyn: from n/a through <= 1.0.10. | |
| Aplazada | Alta (8.1) | 0.60% | — | Tmrw-studio Katerio - MagazineAI | 27/6/2025 | 17/6/2026 | Path Traversal vulnerability in TMRW-studio Katerio - Magazine allows PHP Local File Inclusion. This issue affects Katerio - Magazine: from n/a through 1.5.1. | |
| Analizada | Alta (7.2) | 0.41% | — | Katex | 17/1/2025 | 17/6/2026 | KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions with `renderToString` could encounter malicious input using `\htmlData` that runs arbitrary JavaScript, or generate invalid HTML. Users are advised to upgrade to KaTeX v0.16.21… | |
| Aplazada | Media (4.3) | 0.41% | — | Ekaterir Cache Sniper FOR NginxAI | 16/1/2025 | 17/6/2026 | Missing Authorization vulnerability in ekaterir Cache Sniper for Nginx snipe-nginx-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cache Sniper for Nginx: from n/a through <= 1.0.4.2. | |
| Modificada | Media (4.8) | 0.27% | — | Katello Project KatelloRedhat Satellite | 5/6/2024 | 17/6/2026 | A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the "Description" field of a user. This code can be executed when opening certain pages, for example, Host Collections. | |
| Aplazada | Alta (7.5) | 1.2% | — | Stakater ForecastleAI | 15/5/2024 | 17/6/2026 | Stakater Forecastle 1.0.139 and before allows %5C../ directory traversal in the website component. | |
| Analizada | Media (5.4) | 0.41% | — | Katex | 25/3/2024 | 17/6/2026 | KaTeX is a JavaScript library for TeX math rendering on the web. Code that uses KaTeX's `trust` option, specifically that provides a function to blacklist certain URL protocols, can be fooled by URLs in malicious inputs that use uppercase characters in the protocol. In particular, this can allow for malicious input to… | |
| Analizada | Media (6.1) | 0.41% | — | Katex | 25/3/2024 | 17/6/2026 | KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\includegraphics` that runs arbitrary JavaScript, or generate invalid HTML. Upgrade to KaTeX v0.16.10 to remove this vulnerability. | |
| Analizada | Media (6.5) | 2.2% | — | Katex | 25/3/2024 | 17/6/2026 | KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\def` or `\newcommand` that causes a near-infinite loop, despite setting `maxExpand` to avoid such loops. KaTeX supports an option named maxExpand which aims… | |
| Modificada | Media (6.5) | 1.4% | — | Katex | 25/3/2024 | 17/6/2026 | KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\edef` that causes a near-infinite loop, despite setting `maxExpand` to avoid such loops. This can be used as an availability attack, where e.g. a client… | |
| Modificada | Alta (7.8) | 0.89% | — | KDE KateKDE Ktexteditor | 11/2/2022 | 17/6/2026 | The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 and KTextEditor before 5.91.0 tries to execute the associated LSP server binary when opening a file of a given type. If this binary is absent from the PATH, it will try running the LSP server binary in the directory of the file that was just opened… | |
| Modificada | Crítica (9.8) | 8.9% | — | Themerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+59 | 10/3/2020 | 17/6/2026 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Theforeman Katello | 10/12/2019 | 16/6/2026 | Katello has a Denial of Service vulnerability in API OAuth authentication | |
| Modificada | Media (5.4) | 0.55% | — | Theforeman Katello | 5/12/2019 | 16/6/2026 | Katello: Username in Notification page has cross site scripting | |
| Modificada | Media (5.4) | 0.55% | — | Theforeman KatelloRedhat Satellite | 3/12/2019 | 16/6/2026 | Katello has multiple XSS issues in various entities | |
| Modificada | Baja (2.7) | 0.65% | — | Theforeman Katello | 25/11/2019 | 17/6/2026 | A cleartext password storage issue was discovered in Katello, versions 3.x.x.x before katello 3.12.0.9. Registry credentials used during container image discovery were inadvertently logged without being masked. This flaw could expose the registry credentials to other privileged users. | |
| Modificada | Media (5.4) | 1.00% | — | Redhat SatelliteTheforeman Katello | 13/1/2019 | 17/6/2026 | A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organizations and locations is able to execute a XSS attacks against other users through the Subscriptions or the Red Hat Repositories wizards. This can possibly lead to malicious code execution… | |
| Modificada | Media (4.3) | 1.4% | — | Theforeman Katello | 14/12/2018 | 17/6/2026 | A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is related to an incomplete fix for CVE-2016-3072. Version 3.10 and older is vulnerable. |