Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

25 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.8)1.5%—Solarwinds Observability Self-hostedAI22/9/202624/9/2026
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.
Pendiente de análisisCrítica (9.8)0.65%—Solarwinds Observability Self-hostedAI22/9/202624/9/2026
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.
Pendiente de análisisMedia (5.4)0.44%—Open Cluster Management Multicluster Observability AddonAIOpen Cluster Management Addon FrameworkAI18/9/202621/9/2026
A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details,…
Pendiente de análisisMedia (5.7)0.22%—Suse ObservabilityAIRancher-extension-stackstateAI17/9/202629/9/2026
The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unauthorized access or escalate privileges within the observability environment.
Pendiente de análisisAlta (7.7)0.47%—Redhat Multicluster Observability AddonAIRedhat Opentelemetry CollectorAIRedhat Cluster LOG ForwarderAI11/9/202621/9/2026
A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on…
Pendiente de análisisAlta (7.7)0.31%—IBM Observability With Instana AgentAIIBM Instana Agent OperatorAI4/9/202610/9/2026
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an…
Pendiente de análisisCrítica (9.6)0.21%—IBM Observability With Instana AgentAIIBM Instana Agent OperatorAI4/9/20268/9/2026
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace…
Pendiente de análisisMedia (6.2)0.52%—Opensearch Dashboards-observabilityAI21/8/202627/8/2026
Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions to OpenSearch Dashboards saved objects to execute arbitrary JavaScript in the context of other users' browser sessions by uploading a saved asset with arbitrary web…
Pendiente de análisisAlta (7.3)0.33%—IBM Observability With Instana AgentAIInstana CoreAI28/7/202630/7/2026
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API.
Pendiente de análisisAlta (8.1)0.27%—HCL Hive Telco ObservabilityAIKeycloakAI4/6/202622/7/2026
HCL Hive Telco Observability is affected by a Required directives missing from the CSP issue is detected in keycloak component of the web application. Missing essential directives can leave a site vulnerable.
AnalizadaAlta (8.1)0.42%—Solarwinds Observability Self-hosted26/3/202617/6/2026
SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution.
AnalizadaAlta (8.7)0.45%—Solarwinds Observability Self-hosted26/3/202617/6/2026
SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution.
AnalizadaMedia (4.4)0.23%—Solarwinds Observability Self-hosted18/11/202517/6/2026
SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a malicious site. The attack complexity is high, and authentication is required.
AnalizadaMedia (5.4)0.28%—Solarwinds Observability Self-hosted18/11/202517/6/2026
SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL fields. This vulnerability requires authentication from a low-level account.
AplazadaAlta (8.8)0.33%—Observability OperatorAI12/11/202521/9/2026
A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Custom Resource MonitorStack. This issue allows an adversarial Kubernetes Account with only namespaced-level roles, for example, a tenant controlling a namespace, to create…
AnalizadaMedia (4.6)0.24%—Solarwinds Observability Self-hosted21/10/202517/6/2026
SolarWinds Observability Self-Hosted is susceptible to SQL injection vulnerability that may display sensitive data using a low-level account. This vulnerability requires authentication from a low-privilege account.
AnalizadaAlta (7.8)0.29%—Solarwinds Observability Self-hosted24/7/202517/6/2026
SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with low privileges can escalate privileges to run malicious files copied to a permission-protected folder. This vulnerability requires authentication from a low-level account…
AnalizadaMedia (4.3)0.21%—Solarwinds Observability Self-hosted10/6/202517/6/2026
SolarWinds Observability Self-Hosted was susceptible to a cross-site scripting (XSS) vulnerability due to an unsanitized field in the URL. The attack requires authentication using an administrator-level account and user interaction is required.
AnalizadaMedia (4.8)0.19%—Solarwinds Observability Self-hosted10/6/202517/6/2026
SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a malicious site. The attack complexity is high, and authentication is required.
ModificadaMedia (5.4)0.29%—Opensearch Observability9/7/202417/6/2026
OpenSearch Observability is collection of plugins and applications that visualize data-driven events. An issue in the OpenSearch observability plugins allows unintended access to private tenant resources like notebooks. The system did not properly check if the user was the resource author when accessing resources in a…
ModificadaMedia (5.4)0.30%—Opensearch Observability9/7/202417/6/2026
OpenSearch Dashboards Reports allows ‘Report Owner’ export and share reports from OpenSearch Dashboards. An issue in the OpenSearch reporting plugin allows unintended access to private tenant resources like notebooks. The system did not properly check if the user was the resource author when accessing resources in a…
AnalizadaAlta (7.5)100%⚠ Explotación activaSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaCrítica (9.8)0.83%—IBM Observability With Instana4/10/202317/6/2026
IBM Observability with Instana 1.0.243 through 1.0.254 could allow an attacker on the network to execute arbitrary code on the host after a successful DNS poisoning attack. IBM X-Force ID: 259789.
ModificadaAlta (7.5)0.85%—Redhat Network Observability15/9/202317/6/2026
A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in an OpenShift cluster to retrieve flows without authentication.
ModificadaCrítica (9.1)8.6%—IBM Observability With Instana3/3/202317/6/2026
Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/write access. IBM X-Force ID: 248737.