Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
104 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.51% | — | Zotregistry ZOTAI | 18/9/2026 | 30/9/2026 | zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior to 2.1.18, the bearer authentication handler in pkg/api/authn.go maps every HTTP method other than GET and HEAD to the push action, so DELETE requests are not checked for the distinct delete… | |
| Analizada | Crítica (10) | 0.80% | — | Microsoft Azure Container Registry | 17/9/2026 | 29/9/2026 | Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (8.1) | 0.21% | — | Socketdev Socket-registry-firewallAIOpenrestyAI | 12/9/2026 | 22/9/2026 | Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_verify configuration keys are omitted from socket.yml, the generated configuration sets SOCKET_API_SSL_VERIFY='false' and… | |
| Pendiente de análisis | Alta (8.6) | 0.58% | — | Amazon Mcp-gateway-registryAI | 6/7/2026 | 7/7/2026 | Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-gateway-registry before 1.0.13 might allow an authenticated remote user to execute arbitrary SQL queries via a crafted table_name value that is interpolated into SQL statements in identifier position.… | |
| Modificada | Media (6.5) | 0.52% | — | Redhat Build OF Apicurio Registry | 26/6/2026 | 25/8/2026 | A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE declarations or enable FEATURE_SECURE_PROCESSING. An attacker with artifact-write permission can upload XML documents with internal entity-expansion payloads (billion-laughs… | |
| Modificada | Alta (7.4) | 0.34% | — | Redhat Build OF Apicurio Registry | 25/6/2026 | 26/8/2026 | A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature. When the VALIDITY rule is set to FULL, an attacker with Developer-role access can upload a WSDL document containing attacker-controlled import locations, causing the… | |
| Modificada | Alta (8.5) | 0.44% | — | Redhat Build OF Apicurio Registry | 25/6/2026 | 26/8/2026 | A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without enabling secure processing features or disabling external entity resolution. An attacker with artifact-write permission (or unauthenticated when the registry runs with default configuration) can upload… | |
| Aplazada | Baja (3.1) | 0.17% | — | Docker RegistryAIBlacklanternsecurity BbotAI | 17/6/2026 | 22/6/2026 | The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authentication endpoint without validation. An attacker in a man-in-the-middle position between bbot and a Docker registry could modify this header to redirect the authentication request to an arbitrary… | |
| Analizada | Baja (2.1) | 0.27% | — | Lfprojects MCP Registry | 14/5/2026 | 17/6/2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.6, the client-side and server-side GitHub OIDC flow is bound only to a global audience string, not to the specific registry instance being targeted. On the client side, the publisher always appends… | |
| Aplazada | Ninguna (0) | 0.44% | — | Lfprojects MCP RegistryAI | 14/5/2026 | 17/6/2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. From 1.1.0 to 1.7.4, the TrailingSlashMiddleware in internal/api/server.go is vulnerable to an open redirect attack. An attacker can craft a URL with a protocol-relative path (e.g., //evil.com/) that, after trailing… | |
| Aplazada | Baja (3.5) | 0.25% | — | Lfprojects MCP RegistryAI | 14/5/2026 | 17/6/2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.9, OCI ownership validation skips label-match check when upstream OCI registry returns HTTP 429, letting any authenticated publisher bind their io.github.<user>/* namespace to OCI images they do not… | |
| Modificada | Media (6.3) | 0.29% | — | Lfprojects MCP Registry | 14/5/2026 | 17/6/2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the Registry's HTTP-based namespace verification (POST /v0/auth/http, POST /v0.1/auth/http) uses safeDialContext (internal/api/handlers/v0/auth/http.go:67-110) to refuse dialling private/internal… | |
| Analizada | Media (5.1) | 0.24% | — | Lfprojects MCP Registry | 14/5/2026 | 17/6/2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the public catalogue UI served at GET / (file internal/api/handlers/v0/ui_index.html) is vulnerable to stored cross-site scripting via the server.websiteUrl field of any published server.json.… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Analizada | Media (5.9) | 0.21% | — | Elastic Package Registry | 28/4/2026 | 24/7/2026 | Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positioned to intercept network traffic, or to otherwise influence the contents served to a self-hosted registry, to substitute a tampered package without the integrity check failing closed. | |
| Modificada | Alta (8.8) | 0.79% | — | Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay | 8/4/2026 | 9/9/2026 | A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server. | |
| Modificada | Media (6.3) | 0.43% | — | Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay | 8/4/2026 | 10/9/2026 | A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they do not have access to. This could allow the attacker to read, modify, or cancel… | |
| Modificada | Media (6.5) | 0.40% | — | Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay | 8/4/2026 | 10/9/2026 | A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to specify an arbitrary callback URL. A backend process then makes server-side HTTP requests to this provided URL. This vulnerability, known as Server-Side Request Forgery… | |
| Analizada | Media (5.3) | 0.29% | — | Redhat Mirror Registry FOR RED HAT Openshift | 8/4/2026 | 25/7/2026 | A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different error messages during authentication failures and account creation. | |
| Modificada | Media (5.5) | 0.46% | — | Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay | 8/4/2026 | 22/9/2026 | A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, Quay makes a network connection to the specified registry hostname without verifying that it points to a legitimate external service. An attacker with organization… | |
| Aplazada | Media (5.3) | 0.29% | — | Nmerii NM Gift Registry AND Wishlist LiteAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in nmerii NM Gift Registry and Wishlist Lite nm-gift-registry-and-wishlist-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NM Gift Registry and Wishlist Lite: from n/a through <= 5.13. | |
| Analizada | Alta (8.5) | 0.61% | — | Netgate Registry Cleaner | 4/4/2026 | 21/7/2026 | NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the unquoted path and trigger service restart or system reboot to… | |
| Analizada | Media (5.4) | 0.16% | — | Redhat QuayRedhat Mirror Registry | 12/3/2026 | 17/6/2026 | A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses. When the application processes these addresses, it automatically follows redirects without verifying the final destination, allowing… | |
| Analizada | Alta (7.7) | 0.31% | — | Zotregistry ZOT | 10/3/2026 | 17/6/2026 | zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. From 1.3.0 to 2.1.14, zot’s dist-spec authorization middleware infers the required action for PUT /v2/{name}/manifests/{reference} as create by default, and only switches to update when the tag already exists… | |
| Analizada | Alta (8.1) | 0.57% | — | Internet Routing Registry Daemon Project Internet Routing Registry Daemon | 6/3/2026 | 17/6/2026 | Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version 4.4.5 and from version 4.5.0 to before version 4.5.1, an attacker can manipulate the HTTP Host header on a password reset or account creation request. The confirmation… |