Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
174 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.40% | — | Pivotal Reactor Netty | 27/8/2026 | 2/9/2026 | The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server to consume an excessive amount of memory. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier | |
| Pendiente de análisis | Ninguna (0) | 0.53% | — | Pivotal Software ConcourseAI | 14/8/2026 | 18/9/2026 | Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in a phishing attack to steal user's credentials. This has been fixed in 8.2.3. No… | |
| Aplazada | Alta (8.1) | 0.72% | — | Vmware CRMAIVmware Pivotal.core.common.dllAIVmware Pivotal.engine.client.services.conversion.dllAI | 23/6/2026 | 25/6/2026 | An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Services.Conversion.dll components. | |
| Modificada | Alta (7.5) | 0.54% | — | Pivotal Cloud Foundry DeploymentPivotal Cloud Foundry Routing Release | 12/1/2024 | 17/6/2026 | Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route pruning and therefore degrade the service availability of the Cloud Foundry deployment. | |
| Modificada | Media (6.5) | 0.54% | — | Pivotal Cloud Foundry NFS VolumePivotal Cloud Foundry NotificationsPivotal Cloud Foundry SMB Volume | 16/6/2023 | 17/6/2026 | Vulnerability in Cloud Foundry Notifications, Cloud Foundry SMB-volume release, Cloud FOundry cf-nfs-volume release.This issue affects Notifications: All versions prior to 63; SMB-volume release: All versions prior to 3.1.19; cf-nfs-volume release: 5.0.X versions prior to 5.0.27, 7.1.X versions prior to 7.1.19. | |
| Modificada | Media (5.4) | 0.45% | — | Pivotal Software Concourse | 19/12/2022 | 17/6/2026 | Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body including :team_name=team2 to bypass team scope check to gain access to certain resources belong to any other team. | |
| Modificada | Media (6.5) | 1.3% | — | Pivotal Spring Security OauthOracle Communications Design Studio | 21/4/2022 | 17/6/2026 | <Issue Description> Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client application. A malicious user or attacker can send multiple requests initiating the… | |
| Modificada | Alta (8.8) | 3.3% | — | Pivotal Software Spring SecurityVmware Spring SecurityOracle Communications Element ManagerOracle Communications Interactive Session Recorder+4 | 23/2/2021 | 17/6/2026 | Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A malicious user cannot cause the bug to happen (it must be programmed in). However, if the… | |
| Modificada | Crítica (9.8) | 0.71% | — | Vmware Pivotal Scheduler | 11/11/2020 | 17/6/2026 | Scheduler for TAS prior to version 1.4.0 was permitting plaintext transmission of UAA client token by sending it over a non-TLS connection. This also depended on the configuration of the MySQL server which is used to cache a UAA client token used by the service. If intercepted the token can give an attacker admin… | |
| Modificada | Media (6.7) | 0.45% | — | Broadcom Rabbitmq ServerPivotal Software Rabbitmq | 31/8/2020 | 17/6/2026 | RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation directory and local access on Windows could carry out a local binary hijacking (planting) attack and… | |
| Modificada | Crítica (10) | 1.2% | — | Pivotal Software Concourse | 12/8/2020 | 17/6/2026 | Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of configuring a GitLab account with the same full name as another user who is granted access to a Concourse team. GitLab groups do not have this vulnerability, so GitLab users… | |
| Modificada | Media (6.5) | 1.6% | — | Pivotal Software Spring SecurityVmware Spring Security | 14/5/2020 | 17/6/2026 | Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A malicious user with access to the data that has been encrypted using… | |
| Modificada | Media (6.1) | 0.91% | — | Pivotal Software Concourse | 14/5/2020 | 17/6/2026 | Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could convince a user to click on a link using the OAuth redirect link with an untrusted website and gain access to that user's access token in Concourse. (This issue is similar… | |
| Modificada | Alta (8.8) | 1.2% | — | Pivotal Software Spring Security | 13/5/2020 | 17/6/2026 | Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping vulnerability during SAML response validation. When using the spring-security-saml2-service-provider component, a malicious user can carefully modify an otherwise valid SAML response and append an arbitrary assertion… | |
| Modificada | Alta (7.2) | 2.1% | — | Linuxfoundation HarborPivotal Vmware Harbor Registry | 20/3/2020 | 17/6/2026 | Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform. | |
| Modificada | Media (4.9) | 1.4% | — | Linuxfoundation HarborPivotal Vmware Harbor Registry | 20/3/2020 | 17/6/2026 | Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform. | |
| Modificada | Alta (8.8) | 1.0% | — | Linuxfoundation HarborPivotal Vmware Harbor Registry | 20/3/2020 | 17/6/2026 | Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform. | |
| Modificada | Alta (8.8) | 1.6% | — | Linuxfoundation HarborPivotal Vmware Harbor Registry | 20/3/2020 | 17/6/2026 | Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry for the Pivotal Platform. | |
| Modificada | Alta (7.4) | 0.53% | — | Cloudfoundry CredhubPivotal Software Cloud Foundry Cf-deployment | 12/2/2020 | 17/6/2026 | Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with access to the network between CredHub and its MySQL database may eavesdrop on database connections and thereby gain unauthorized access to CredHub and other components. | |
| Modificada | Alta (7) | 0.27% | — | Pivotal TC RuntimesPivotal TC Server | 27/1/2020 | 17/6/2026 | In Pivotal tc Server, 3.x versions prior to 3.2.19 and 4.x versions prior to 4.0.10, and Pivotal tc Runtimes, 7.x versions prior to 7.0.99.B, 8.x versions prior to 8.5.47.A, and 9.x versions prior to 9.0.27.A, when a tc Runtime instance is configured with the JMX Socket Listener, a local attacker without access to the… | |
| Modificada | Media (5.4) | 1.8% | — | Pivotal Software Spring Framework | 10/1/2020 | 17/6/2026 | The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a (1) line separator or (2) paragraph separator Unicode character or… | |
| Modificada | Media (6.5) | 1.1% | — | Pivotal Software Operations Manager | 9/1/2020 | 17/6/2026 | Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2.7.5, logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well. | |
| Modificada | Alta (7.5) | 4.4% | — | Broadcom Rabbitmq ServerPivotal Software RabbitmqFedoraproject FedoraRedhat Openstack+1 | 23/11/2019 | 17/6/2026 | Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a… | |
| Modificada | Alta (8.8) | 1.5% | — | Cloudfoundry Cf-deploymentPivotal Software Cloud Foundry SMB Volume | 23/10/2019 | 17/6/2026 | Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for volumes that have been recently created, allowing the user to take control of the SMB Volume. | |
| Modificada | Media (4.3) | 1.1% | — | Cloudfoundry Cf-deploymentPivotal Software Cloud Foundry UAA | 23/10/2019 | 17/6/2026 | Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote authenticated malicious user with scim.invite scope can craft a request with malicious content which can leak information about users of the UAA. |