Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.79%—Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay8/4/20269/9/2026
A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server.
ModificadaMedia (6.3)0.43%—Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay8/4/202610/9/2026
A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they do not have access to. This could allow the attacker to read, modify, or cancel…
ModificadaMedia (6.5)0.40%—Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay8/4/202610/9/2026
A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to specify an arbitrary callback URL. A backend process then makes server-side HTTP requests to this provided URL. This vulnerability, known as Server-Side Request Forgery…
AnalizadaMedia (5.3)0.29%—Redhat Mirror Registry FOR RED HAT Openshift8/4/202625/7/2026
A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different error messages during authentication failures and account creation.
ModificadaMedia (5.5)0.46%—Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay8/4/202622/9/2026
A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, Quay makes a network connection to the specified registry hostname without verifying that it points to a legitimate external service. An attacker with organization…
AnalizadaMedia (5.4)0.16%—Redhat QuayRedhat Mirror Registry12/3/202617/6/2026
A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses. When the application processes these addresses, it automatically follows redirects without verifying the final destination, allowing…
AplazadaMedia (6.5)0.21%—Mirror-registryAI20/8/202517/6/2026
The mirror-registry doesn't properly sanitize the host header HTTP header in HTTP request received, allowing an attacker to perform malicious redirects to attacker-controlled domains or phishing campaigns.
AplazadaAlta (8.2)0.23%—Redhat Mirror Registry FOR OpenshiftAIRedhat QuayAI9/5/202517/6/2026
A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has write access to the `/etc/passwd`. This flaw allows a malicious actor with access to the container to modify the passwd file and elevate their privileges to the root user within that pod.
AplazadaAlta (7.3)0.34%—RedisAIRedhat QuayAIRedhat Mirror RegistryAI25/4/202417/6/2026
A flaw was found in Quay, where Quay's database is stored in plain text in mirror-registry on Jinja's config.yaml file. This issue leaves the possibility of a malicious actor with access to this file to gain access to Quay's Redis instance.
AplazadaAlta (7.3)0.34%—Redhat QuayAIRedhat Mirror RegistryAI25/4/202417/6/2026
A flaw was found in how Quay's database is stored in plain-text in mirror-registry on the jinja's config.yaml file. This flaw allows a malicious actor with access to this file to gain access to Quay's database.
ModificadaMedia (6.5)0.43%—Redhat Mirror Registry25/4/202417/6/2026
A flaw was found when using mirror-registry to install Quay. It uses a default database secret key, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deployed using mirror-registry to have the same database secret key. This flaw allows a…
AnalizadaAlta (8.8)0.52%—Redhat Mirror Registry25/4/202417/6/2026
A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deployed using mirror-registry to have the same secret key. This flaw allows a malicious actor to craft…