Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.4) | 0.31% | — | Openshift Oc-mirrorAIRedhat RED HAT Release KEYAI | 21/9/2026 | 24/9/2026 | A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. A remote attacker, by intercepting or manipulating network traffic to… | |
| Aplazada | Baja (1.9) | 1.1% | — | Release-it Conventional-changelogAI | 23/7/2026 | 27/7/2026 | A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of the file index.js of the component Changelog File Handler. Such manipulation of the argument infile leads to os command injection. The attack must be carried out locally. The… | |
| Pendiente de análisis | Media (6.9) | 0.17% | — | Cloudfoundry Bpm-releaseAI | 18/6/2026 | 22/6/2026 | setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow. A compromised process inside a bpm container can cause root to chown an arbitrary host file to vcap and append bpm JSON log lines to it. The chown alone lets the attacker take ownership of /etc/shadow and… | |
| Analizada | Media (6.1) | 0.15% | — | Dell Powerflex Rack Release Certification Matrix | 17/6/2026 | 30/9/2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to trigger redirections. | |
| Pendiente de análisis | Alta (7.5) | 0.42% | — | Bosh-ecosystem Windows Utilities ReleaseAI | 4/6/2026 | 22/7/2026 | Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities-release allows a network attacker to estimate VM boot time and reconstruct a small candidate list to recover the Administrator password. The randomize_password job exists solely to lock the local… | |
| Pendiente de análisis | Alta (7.5) | 0.65% | — | Cloudfoundry Cf-auth-proxyAICloudfoundry Log-cache ReleaseAI | 1/6/2026 | 22/7/2026 | Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to every log and metric for every application and platform component via minting a JWT that the cf-auth-proxy accepts as a valid logs.admin token. Affected versions: -… | |
| Pendiente de análisis | Alta (8.1) | 0.42% | — | Cloudfoundry Diego-releaseAICloudfoundry Smb-volume-releaseAICloudfoundry CF DeploymentAI | 1/6/2026 | 22/7/2026 | Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the mount-option allowlist, enabling privilege escalation and security control bypass on multi-tenant Diego cells. Affected… | |
| Analizada | Media (5) | 0.20% | — | Cloudfoundry Cf-deploymentCloudfoundry Routing Release | 1/5/2026 | 17/6/2026 | Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure a route-service that would allow it to send requests to HTTP services on internal networks reachable by the Gorouter,… | |
| Pendiente de análisis | Alta (7.5) | 0.20% | — | Cloudfoundry Capi ReleaseAICloudfoundry CF DeploymentAI | 17/3/2026 | 17/6/2026 | Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on all platforms allows any user who has bypassed the firewall to potentially replace droplets and therefore applications allowing them to access secure application information. | |
| Modificada | Media (6.5) | 0.23% | — | Cloudfoundry Cf-deploymentCloudfoundry Uaa-release | 5/3/2026 | 17/6/2026 | Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0. | |
| Analizada | Alta (7.5) | 0.20% | — | Cloudfoundry Cf-deploymentCloudfoundry UAA Release | 13/5/2025 | 17/6/2026 | Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs. | |
| Analizada | Media (6.7) | 0.17% | — | Dell Data LakehouseDell InsightiqDell Powerflex Appliance Intelligent CatalogDell Powerflex Manager+1 | 10/12/2024 | 17/6/2026 | Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and… | |
| Analizada | Crítica (9.8) | 0.76% | — | Dell Data LakehouseDell InsightiqDell Powerflex Appliance Intelligent CatalogDell Powerflex Manager+1 | 10/12/2024 | 17/6/2026 | Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and… | |
| Aplazada | Crítica (9.1) | 0.55% | — | Cloudfoundry Haproxy-boshreleaseAICloudfoundry Routing-releaseAICloudfoundry Cloud FoundryAI | 3/7/2024 | 17/6/2026 | When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP requests that bypass mTLS authentication to Cloud Foundry applications. You are affected if you have route-services enabled in routing-release and have configured the… | |
| Modificada | Alta (7.5) | 0.40% | — | Cloudfoundry Cf-deploymentCloudfoundry Routing Release | 10/6/2024 | 17/6/2026 | Improper handling of requests in Routing Release > v0.273.0 and <= v0.297.0 allows an unauthenticated attacker to degrade the service availability of the Cloud Foundry deployment if performed at scale. | |
| Analizada | Media (6.8) | 0.79% | — | Jenkins Subversion Partial Release Manager | 2/5/2024 | 17/6/2026 | Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 whenever a build is triggered from a release tag, by setting the Java system property 'hudson.model.ParametersAction.keepUndefinedParameters'. | |
| Analizada | Media (4.3) | 0.50% | — | Jenkins Subversion Partial Release Manager | 6/3/2024 | 17/6/2026 | A missing permission check in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers with Item/Read permission to trigger a build. | |
| Analizada | Media (4.3) | 0.31% | — | Jenkins Subversion Partial Release Manager | 6/3/2024 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers to trigger a build. | |
| Modificada | Media (5.5) | 0.32% | — | Goreleaser | 30/1/2024 | 17/6/2026 | GoReleaser builds Go binaries for several platforms, creates a GitHub release and then pushes a Homebrew formula to a tap repository. `goreleaser release --debug` log shows secret values used in the in the custom publisher. This vulnerability is fixed in 1.24.0. | |
| Modificada | Alta (7.5) | 0.54% | — | Pivotal Cloud Foundry DeploymentPivotal Cloud Foundry Routing Release | 12/1/2024 | 17/6/2026 | Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route pruning and therefore degrade the service availability of the Cloud Foundry deployment. | |
| Modificada | Alta (7.5) | 0.20% | — | 3DS Teamwork Cloud NO Magic Release | 9/10/2023 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x could allow with some very specific conditions an attacker to send a specifically crafted query to the server. | |
| Modificada | Media (5.4) | 0.34% | — | 3DS Teamwork Cloud NO Magic Release | 13/9/2023 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x allows an attacker to execute arbitrary script code. | |
| Modificada | Media (5.3) | 0.44% | — | Cloudfoundry Cf-deploymentCloudfoundry Routing-release | 8/9/2023 | 17/6/2026 | Cloud foundry routing release versions prior to 0.278.0 are vulnerable to abuse of HTTP Hop-by-Hop Headers. An unauthenticated attacker can use this vulnerability for headers like B3 or X-B3-SpanID to affect the identification value recorded in the logs in foundations. | |
| Modificada | Media (6.1) | 0.60% | — | Emby.releases | 5/8/2023 | 17/6/2026 | A vulnerability was found in Media Browser Emby Server 4.7.13.0 and classified as problematic. This issue affects some unknown processing of the file /web/. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is… | |
| Modificada | Crítica (9.1) | 1.7% | — | Emby.releases | 30/5/2023 | 17/6/2026 | Emby Server is a user-installable home media server which stores and organizes a user's media files of virtually any format and makes them available for viewing at home and abroad on a broad range of client devices. This vulnerability may allow administrative access to an Emby Server system, depending on certain user… |