Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (4.3)0.22%—Redhat RED HATAI23/9/202624/9/2026
—
Pendiente de análisisAlta (7.4)0.31%—Openshift Oc-mirrorAIRedhat RED HAT Release KEYAI21/9/202624/9/2026
A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. A remote attacker, by intercepting or manipulating network traffic to…
AnalizadaCrítica (9.9)0.79%—Microsoft Azure RED HAT Openshift24/7/20267/8/2026
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (6.8)0.38%—Redhat Cluster Logging OperatorRedhat Logging Subsystem FOR RED HAT Openshift23/6/20268/7/2026
A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output destinations without verifying that the ClusterLogForwarder creator has permission to use those credentials, allowing a delegated editor to exfiltrate SA tokens and…
ModificadaAlta (8.8)0.79%—Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay8/4/20269/9/2026
A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server.
ModificadaMedia (6.3)0.43%—Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay8/4/202610/9/2026
A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they do not have access to. This could allow the attacker to read, modify, or cancel…
ModificadaMedia (6.5)0.40%—Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay8/4/202610/9/2026
A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to specify an arbitrary callback URL. A backend process then makes server-side HTTP requests to this provided URL. This vulnerability, known as Server-Side Request Forgery…
AnalizadaMedia (5.3)0.29%—Redhat Mirror Registry FOR RED HAT Openshift8/4/202625/7/2026
A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different error messages during authentication failures and account creation.
ModificadaMedia (5.5)0.46%—Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay8/4/202622/9/2026
A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, Quay makes a network connection to the specified registry hostname without verifying that it points to a legitimate external service. An attacker with organization…
AnalizadaMedia (5.3)0.32%—IBM Cloud PAK SystemIBM OS Image FOR RED HAT Linux Systems4/2/202617/6/2026
IBM Cloud Pak System does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the…
AnalizadaMedia (5.3)0.32%—IBM Cloud PAK SystemIBM OS Image FOR RED HAT Linux Systems4/2/202617/6/2026
IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaAlta (7.5)0.33%—IBM Cloud PAK SystemIBM OS Image FOR RED HAT Linux Systems4/2/202617/6/2026
IBM Cloud Pak System displays sensitive information in user messages that could aid in further attacks against the system.
ModificadaMedia (5.4)0.56%—Jenkins RED HAT Dependency Analytics24/1/202417/6/2026
Jenkins Red Hat Dependency Analytics Plugin 0.7.1 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.
ModificadaMedia (5.7)0.56%—Redhat RED HAT Developer HUBLinuxfoundation Backstage4/1/202417/6/2026
A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded GitLab token includes a newline at the end of the string. The sanitized error can display on the frontend, including the raw access token. Upon gaining access to this…
ModificadaMedia (5.9)94%—Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+6418/12/202317/6/2026
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some…
AnalizadaAlta (7.5)100%⚠ Explotación activaSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaMedia (5)4.1%—EmumailEmumail RED HAT LinuxEmumail Unix12/8/200216/6/2026
Directory traversal vulnerability in emumail.cgi in EMU Webmail 4.5.x and 5.1.0 allows remote attackers to read arbitrary files or list arbitrary directories via a .. (dot dot) in the type parameter.
ModificadaAlta (7.2)0.35%—EmumailEmumail RED HAT LinuxEmumail Unix12/8/200216/6/2026
EMU Webmail allows local users to execute arbitrary programs via a .. (dot dot) in the HTTP Host header that points to a Trojan horse configuration file that contains a pageroot specifier that contains shell metacharacters.