Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 1.5% | — | Solarwinds Observability Self-hostedAI | 22/9/2026 | 24/9/2026 | SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode. | |
| Pendiente de análisis | Crítica (9.8) | 0.65% | — | Solarwinds Observability Self-hostedAI | 22/9/2026 | 24/9/2026 | SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected. | |
| Pendiente de análisis | Media (5.4) | 0.44% | — | Open Cluster Management Multicluster Observability AddonAIOpen Cluster Management Addon FrameworkAI | 18/9/2026 | 21/9/2026 | A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details,… | |
| Pendiente de análisis | Media (5.7) | 0.22% | — | Suse ObservabilityAIRancher-extension-stackstateAI | 17/9/2026 | 29/9/2026 | The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unauthorized access or escalate privileges within the observability environment. | |
| Pendiente de análisis | Alta (7.7) | 0.47% | — | Redhat Multicluster Observability AddonAIRedhat Opentelemetry CollectorAIRedhat Cluster LOG ForwarderAI | 11/9/2026 | 21/9/2026 | A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on… | |
| Pendiente de análisis | Alta (7.7) | 0.31% | — | IBM Observability With Instana AgentAIIBM Instana Agent OperatorAI | 4/9/2026 | 10/9/2026 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an… | |
| Pendiente de análisis | Crítica (9.6) | 0.21% | — | IBM Observability With Instana AgentAIIBM Instana Agent OperatorAI | 4/9/2026 | 8/9/2026 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace… | |
| Pendiente de análisis | Media (6.2) | 0.52% | — | Opensearch Dashboards-observabilityAI | 21/8/2026 | 27/8/2026 | Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions to OpenSearch Dashboards saved objects to execute arbitrary JavaScript in the context of other users' browser sessions by uploading a saved asset with arbitrary web… | |
| Pendiente de análisis | Alta (7.3) | 0.33% | — | IBM Observability With Instana AgentAIInstana CoreAI | 28/7/2026 | 30/7/2026 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API. | |
| Pendiente de análisis | Alta (8.1) | 0.27% | — | HCL Hive Telco ObservabilityAIKeycloakAI | 4/6/2026 | 22/7/2026 | HCL Hive Telco Observability is affected by a Required directives missing from the CSP issue is detected in keycloak component of the web application. Missing essential directives can leave a site vulnerable. | |
| Analizada | Alta (8.1) | 0.42% | — | Solarwinds Observability Self-hosted | 26/3/2026 | 17/6/2026 | SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution. | |
| Analizada | Alta (8.7) | 0.45% | — | Solarwinds Observability Self-hosted | 26/3/2026 | 17/6/2026 | SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution. | |
| Analizada | Media (4.4) | 0.23% | — | Solarwinds Observability Self-hosted | 18/11/2025 | 17/6/2026 | SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a malicious site. The attack complexity is high, and authentication is required. | |
| Analizada | Media (5.4) | 0.28% | — | Solarwinds Observability Self-hosted | 18/11/2025 | 17/6/2026 | SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL fields. This vulnerability requires authentication from a low-level account. | |
| Aplazada | Alta (8.8) | 0.33% | — | Observability OperatorAI | 12/11/2025 | 21/9/2026 | A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Custom Resource MonitorStack. This issue allows an adversarial Kubernetes Account with only namespaced-level roles, for example, a tenant controlling a namespace, to create… | |
| Analizada | Media (4.6) | 0.24% | — | Solarwinds Observability Self-hosted | 21/10/2025 | 17/6/2026 | SolarWinds Observability Self-Hosted is susceptible to SQL injection vulnerability that may display sensitive data using a low-level account. This vulnerability requires authentication from a low-privilege account. | |
| Analizada | Alta (7.8) | 0.29% | — | Solarwinds Observability Self-hosted | 24/7/2025 | 17/6/2026 | SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with low privileges can escalate privileges to run malicious files copied to a permission-protected folder. This vulnerability requires authentication from a low-level account… | |
| Analizada | Media (4.3) | 0.21% | — | Solarwinds Observability Self-hosted | 10/6/2025 | 17/6/2026 | SolarWinds Observability Self-Hosted was susceptible to a cross-site scripting (XSS) vulnerability due to an unsanitized field in the URL. The attack requires authentication using an administrator-level account and user interaction is required. | |
| Analizada | Media (4.8) | 0.19% | — | Solarwinds Observability Self-hosted | 10/6/2025 | 17/6/2026 | SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a malicious site. The attack complexity is high, and authentication is required. | |
| Modificada | Media (5.4) | 0.29% | — | Opensearch Observability | 9/7/2024 | 17/6/2026 | OpenSearch Observability is collection of plugins and applications that visualize data-driven events. An issue in the OpenSearch observability plugins allows unintended access to private tenant resources like notebooks. The system did not properly check if the user was the resource author when accessing resources in a… | |
| Modificada | Media (5.4) | 0.30% | — | Opensearch Observability | 9/7/2024 | 17/6/2026 | OpenSearch Dashboards Reports allows ‘Report Owner’ export and share reports from OpenSearch Dashboards. An issue in the OpenSearch reporting plugin allows unintended access to private tenant resources like notebooks. The system did not properly check if the user was the resource author when accessing resources in a… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Crítica (9.8) | 0.83% | — | IBM Observability With Instana | 4/10/2023 | 17/6/2026 | IBM Observability with Instana 1.0.243 through 1.0.254 could allow an attacker on the network to execute arbitrary code on the host after a successful DNS poisoning attack. IBM X-Force ID: 259789. | |
| Modificada | Alta (7.5) | 0.85% | — | Redhat Network Observability | 15/9/2023 | 17/6/2026 | A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in an OpenShift cluster to retrieve flows without authentication. | |
| Modificada | Crítica (9.1) | 8.6% | — | IBM Observability With Instana | 3/3/2023 | 17/6/2026 | Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/write access. IBM X-Force ID: 248737. |