Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3042▲ 436 respecto a la semana anterior
Críticas / altas1431▲ 190 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 168 respecto a la semana anterior
598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.36% | — | Linuxfoundation ContainerdAI | 25/9/2026 | 28/9/2026 | containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long ContainerCreating stalls and, at larger sizes, node/runtime instability. Versions 1.7.36,… | |
| Pendiente de análisis | Alta (8.1) | 0.62% | — | Linuxfoundation KubeedgeAI | 21/9/2026 | 24/9/2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.16.0 until 1.21.2, 1.22.2, and 1.23.1, the DecompressTarGz function in keadm/cmd/keadm/app/cmd/util/common.go joins archive entry names to the extraction destination without sufficient… | |
| Pendiente de análisis | Alta (8.8) | 0.48% | — | Linuxfoundation KubeedgeAI | 21/9/2026 | 24/9/2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.21.0 until 1.21.2, 1.22.2, and 1.23.1, ConfigUpdateJob processing in edge/pkg/taskmanager/actions/configupdatejob.go concatenates authenticated user-controlled updateFields values into… | |
| Pendiente de análisis | Alta (8.8) | 0.48% | — | Linuxfoundation KubeedgeAI | 21/9/2026 | 24/9/2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.12.0 until 1.21.2, 1.22.2, and 1.23.1, the v1alpha2 NodeUpgradeJob handler in edge/pkg/taskmanager/actions/nodeupgradejob.go concatenates authenticated user-controlled spec.version and… | |
| Pendiente de análisis | Media (6.5) | 0.50% | — | Linuxfoundation KubeedgeAI | 21/9/2026 | 29/9/2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.0.0 until 1.21.2, 1.22.2, and 1.23.1, Reader.Read in pkg/viaduct/pkg/packer trusts the 32-bit PackageHeader.PayloadLen received through the CloudHub viaduct message-processing path and… | |
| Pendiente de análisis | Alta (7.1) | 0.45% | — | Linuxfoundation HarborAI | 16/9/2026 | 24/9/2026 | Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials. Project administrators can exploit fuzzy filtering on the AccessCredential column to recover the scanner adapter secret one character at a time through response row counts. | |
| Pendiente de análisis | Media (5.4) | 0.25% | — | Apache KafkaAILinuxfoundation StrimziAI | 15/9/2026 | 30/9/2026 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, deploying only the Topic Operator or only the User Operator through the Kafka custom resource leaves the Entity Operator ServiceAccount with RBAC permissions for both… | |
| Pendiente de análisis | Alta (8) | 0.29% | — | Apache KafkaAILinuxfoundation StrimziAI | 15/9/2026 | 30/9/2026 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, an attacker who can create a Kafka custom resource can set Kafka.spec.entityOperator watchedNamespace to a target namespace, causing the Cluster Operator to create a Role… | |
| Pendiente de análisis | Media (6.9) | 0.52% | — | Linuxfoundation Inspektor GadgetAI | 15/9/2026 | 30/9/2026 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.27.0 until 0.53.1, the uprobe library resolver can allow an unprivileged container to consume excessive CPU and block other containers from starting by supplying a… | |
| Pendiente de análisis | Baja (2.9) | 0.63% | — | Linuxfoundation Inspektor GadgetAI | 15/9/2026 | 30/9/2026 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.28.0 until 0.53.1, the USDT note parser in pkg/uprobetracer/usdt.go can allow an unprivileged container to crash or exhaust the memory of the privileged Inspektor Gadget… | |
| Pendiente de análisis | Media (6.8) | 0.16% | — | Linuxfoundation ContainerdAI | 14/9/2026 | 25/9/2026 | containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go when CRI ExecSync is used by exec probes or lifecycle hooks that launch long-lived… | |
| Aplazada | Media (6.5) | 0.37% | — | FleetAILinuxfoundation OsqueryAI | 26/8/2026 | 9/9/2026 | Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) allowed an authenticated user with the lowest-privilege Observer role to extract sensitive values from joined database tables,… | |
| Aplazada | Media (6.5) | 0.37% | — | FleetAILinuxfoundation OsqueryAI | 26/8/2026 | 9/9/2026 | Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an authenticated user with the lowest-privilege Observer role to extract host enrollment secrets through a sort-order oracle. The… | |
| Analizada | Media (6.8) | 0.16% | — | Linuxfoundation Onnx | 21/8/2026 | 16/9/2026 | In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()' check. A local attacker with write access to the directory where a victim serializes… | |
| Aplazada | Crítica (9.4) | 0.77% | — | PostgresqlAILinuxfoundation CloudnativepgAI | 20/8/2026 | 18/9/2026 | CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened superuser connections without pinning search_path in fillDefaultParameters in pkg/management/postgres/pool/profiles.go. A role holding DATABASE OWNER could create… | |
| Aplazada | Alta (8.5) | 0.50% | — | PostgresqlAILinuxfoundation CloudnativepgAI | 20/8/2026 | 18/9/2026 | CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by SetUserPassword in pkg/management/postgres/utils/roles.go and appendPasswordOption in… | |
| Pendiente de análisis | Media (5.3) | 0.43% | — | Linuxfoundation VitessAI | 18/8/2026 | 18/9/2026 | Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /debug/vrlog endpoint registered by addHttpEndpoint() in go/vt/vttablet/tabletmanager/vreplication/vrlog.go invokes vrlogStatsHandler() without acl.CheckAccessHTTP(r, acl.DEBUGGING), unlike comparable debug endpoints. A… | |
| Aplazada | Alta (8.2) | 0.68% | — | OpenchoreoAILinuxfoundation BackstageAI | 13/8/2026 | 8/9/2026 | OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPolicy and auth.providers.guest.dangerouslyAllowOutsideDevelopment to true, exposing /api/* without authentication and allowing unauthenticated… | |
| Pendiente de análisis | Media (4.7) | 0.28% | — | Backstage Plugin-auth-backendAILinuxfoundation BackstageAI | 13/8/2026 | 18/9/2026 | Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registration and client ID metadata document features in the @backstage/plugin-auth-backend use full-string matcher.isMatch glob matching for… | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | Linuxfoundation RekorAI | 13/8/2026 | 18/9/2026 | Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK file into in-memory buffers without bounding the total decompressed size. The existing… | |
| Analizada | Alta (7.1) | 0.45% | — | Linuxfoundation Torchvision | 23/7/2026 | 17/9/2026 | PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy. Attackers can supply malicious or truncated GIF files to cause denial of service via segmentation fault or disclose… | |
| Analizada | Alta (7.5) | 0.49% | — | Linuxfoundation Oras | 17/7/2026 | 26/8/2026 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request,… | |
| Analizada | Alta (7.5) | 0.74% | — | Linuxfoundation Sigstore Timestamp Authority | 17/7/2026 | 30/7/2026 | Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path and raw HTTP request method r.Method as Prometheus labels for latency and request count metric vectors before routing, allowing an unauthenticated remote… | |
| Analizada | Alta (7.3) | 0.11% | — | Linuxfoundation Cert-manager | 16/7/2026 | 30/7/2026 | cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing and using those certificates. From 1.18.0 until 1.19.6 and 1.20.3, Challenge resources under acme.cert-manager.io can be created directly by namespace users without… | |
| Analizada | Alta (7.5) | 1.1% | — | Linuxfoundation Spinnaker | 10/7/2026 | 21/7/2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations allow unsafe YAML tag processing in rosco manifests. This can lead to remote code execution on rosco pods when performing… |