Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2507▼ 423 respecto a la semana anterior
Críticas / altas1283▲ 4 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.20% | — | Openstack Tripleo AnsibleRedhat OpenstackRedhat Openstack FOR IBM Power | 23/3/2023 | 17/6/2026 | A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important… | |
| Modificada | Media (5.5) | 0.20% | — | Openstack Tripleo AnsibleRedhat OpenstackRedhat Openstack FOR IBM Power | 23/3/2023 | 17/6/2026 | A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to information disclosure of important configuration… | |
| Modificada | Media (5.9) | 0.44% | — | Openstack BarbicanRedhat OpenstackRedhat Openstack FOR IBM PowerRedhat Openstack Platform | 18/1/2023 | 17/6/2026 | A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API. | |
| Modificada | Alta (7.5) | 89% | — | Apache Http ServerOracle Communications Element ManagerOracle Communications Session Report ManagerOracle Communications Session Route Manager+21 | 7/8/2020 | 17/6/2026 | Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers. | |
| Modificada | Media (4.8) | 1.2% | — | Pivotal Software RabbitmqRedhat OpenstackRedhat Openstack FOR IBM PowerDebian Linux+1 | 16/10/2019 | 17/6/2026 | Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits page, and the federation management UI, which do not properly sanitize user input. A remote… |