Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2500▼ 420 respecto a la semana anterior
Críticas / altas1284▲ 11 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.59% | — | Pipelines-as-codeAITektonAI | 15/9/2026 | 30/9/2026 | Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation token created during webhook processing is not scoped to the repository that triggered the event when the App is installed across multiple… | |
| Pendiente de análisis | Alta (8.2) | 0.27% | — | Cd.foundation Pipelines AS CodeAI | 15/9/2026 | 30/9/2026 | Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processing webhook events containing an installation.id, before webhook signature… | |
| Aplazada | Crítica (10) | 0.62% | — | Kubeflow PipelinesAI | 28/8/2026 | 9/9/2026 | Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in frontend/server/proxy-middleware.ts. The _routePathWithReferer()… | |
| Pendiente de análisis | Alta (7.6) | 0.51% | — | Data Science PipelinesAIArgoproj Argo WorkflowsAI | 10/8/2026 | 8/9/2026 | A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker.… | |
| Pendiente de análisis | Alta (7.1) | 0.48% | — | Kubeflow Data Science PipelinesAI | 10/8/2026 | 21/9/2026 | A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged ServiceAccount (SA) during a CreateRun request, an attacker can bypass authorization checks. This allows the tenant to… | |
| Pendiente de análisis | Alta (8.8) | 0.73% | — | Data Science Pipelines OperatorAIMysqlAI | 10/8/2026 | 21/9/2026 | A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Source Name (DSN) string. By manipulating these parameters, an attacker can enable… | |
| Pendiente de análisis | Alta (7.5) | 0.61% | — | MariadbAIMinioAIRedhat Data Science Pipelines OperatorAI | 10/8/2026 | 21/9/2026 | A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords and MinIO access/secret keys, if they can access the MinIO Route or MariaDB Service. The flaw occurs because the operator uses a… | |
| Pendiente de análisis | Alta (8.7) | 0.70% | — | Kubeflow Data Science Pipelines OperatorAI | 10/8/2026 | 21/9/2026 | A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to execute commands within pods and manage cluster-wide roles, could be… | |
| Pendiente de análisis | Alta (7.1) | 0.22% | — | Openshift Pipelines OperatorAITektonAIKueueAICert-managerAI | 4/6/2026 | 6/9/2026 | A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any… | |
| Modificada | Alta (8.5) | 0.90% | — | Linuxfoundation Tekton Pipelines | 21/4/2026 | 24/8/2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the git resolver's revision parameter is passed directly as a positional argument to git fetch without any validation that it does not begin… | |
| Modificada | Media (6.5) | 0.47% | — | Linuxfoundation Tekton Pipelines | 21/4/2026 | 17/6/2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the HTTP resolver's FetchHttpResource function calls io.ReadAll(resp.Body) with no response body size limit. Any tenant with permission to… | |
| Modificada | Media (5.4) | 0.32% | — | Linuxfoundation Tekton Pipelines | 21/4/2026 | 17/6/2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, a validation bypass in the VolumeMount path restriction allows mounting volumes under restricted /tekton/ internal paths by using .. path… | |
| Modificada | Media (6.5) | 0.43% | — | Linuxfoundation Tekton Pipelines | 21/4/2026 | 17/6/2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the Tekton Pipelines git resolver in API mode sends the system-configured Git API token to a user-controlled serverURL when the user omits… | |
| Modificada | Media (6.5) | 0.39% | — | Linuxfoundation Tekton Pipelines | 21/4/2026 | 17/6/2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 0.43.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, trusted resources verification policies match a resource source string (refSource.URI) against spec.resources[].pattern using… | |
| Modificada | Crítica (9.6) | 0.70% | — | Linuxfoundation Tekton Pipelines | 24/3/2026 | 7/9/2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permission to create… | |
| Analizada | Media (6.5) | 0.45% | — | Linuxfoundation Tekton Pipelines | 20/3/2026 | 17/6/2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Versions 0.60.0 through 1.0.0, 1.1.0 through 1.3.2, 1.4.0 through 1.6.0, 1.7.0 through 1.9.0, 1.10.0, and 1.10.1 have a denial-of-service vulnerability in that allows any user who can create a TaskRun or PipelineRun to crash the… | |
| Aplazada | Media (6.4) | 0.32% | — | AI Content PipelinesAI | 5/4/2025 | 17/6/2026 | The AI Content Pipelines plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Analizada | Alta (7.1) | 0.21% | — | Kubeflow Pipelines | 18/11/2024 | 17/6/2026 | There exists a stored XSS Vulnerability in Kubeflow Pipeline View web UI. The Kubeflow Web UI allows to create new pipelines. When creating a new pipeline, it is possible to add a description. The description field allows html tags, which are not filtered properly. Leading to a stored XSS. We recommend upgrading past… | |
| Modificada | Media (5.9) | 94% | — | Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+64 | 18/12/2023 | 17/6/2026 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some… | |
| Modificada | Alta (8.8) | 2.0% | — | Microsoft Azure Pipelines Agent | 14/11/2023 | 17/6/2026 | Azure DevOps Server Remote Code Execution Vulnerability | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (4.3) | 0.38% | — | Linuxfoundation Tekton Pipelines | 7/7/2023 | 17/6/2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 0.35.0, pipelines do not validate child UIDs, which means that a user that has access to create TaskRuns can create their own Tasks that the Pipelines controller will accept as the child Task. While the… | |
| Modificada | Media (4.3) | 0.38% | — | Chocolatey Azure-pipelines-agent | 29/11/2022 | 17/6/2026 | Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent and all files located in that folder. | |
| Modificada | Alta (7.5) | 6.6% | — | Microsoft .net CoreMicrosoft Asp.net CoreMicrosoft System.io.pipelines | 13/9/2018 | 17/6/2026 | A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1. |