Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
–

143 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.4)0.31%—Openshift Oc-mirrorAIRedhat RED HAT Release KEYAI21/9/202624/9/2026
A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. A remote attacker, by intercepting or manipulating network traffic to…
AplazadaBaja (1.9)1.1%—Release-it Conventional-changelogAI23/7/202627/7/2026
A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of the file index.js of the component Changelog File Handler. Such manipulation of the argument infile leads to os command injection. The attack must be carried out locally. The…
Pendiente de análisisMedia (6.9)0.17%—Cloudfoundry Bpm-releaseAI18/6/202622/6/2026
setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow. A compromised process inside a bpm container can cause root to chown an arbitrary host file to vcap and append bpm JSON log lines to it. The chown alone lets the attacker take ownership of /etc/shadow and…
AnalizadaMedia (6.1)0.15%—Dell Powerflex Rack Release Certification Matrix17/6/202630/9/2026
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to trigger redirections.
Pendiente de análisisAlta (7.5)0.42%—Bosh-ecosystem Windows Utilities ReleaseAI4/6/202622/7/2026
Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities-release allows a network attacker to estimate VM boot time and reconstruct a small candidate list to recover the Administrator password. The randomize_password job exists solely to lock the local…
Pendiente de análisisAlta (7.5)0.65%—Cloudfoundry Cf-auth-proxyAICloudfoundry Log-cache ReleaseAI1/6/202622/7/2026
Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to every log and metric for every application and platform component via minting a JWT that the cf-auth-proxy accepts as a valid logs.admin token. Affected versions: -…
Pendiente de análisisAlta (8.1)0.42%—Cloudfoundry Diego-releaseAICloudfoundry Smb-volume-releaseAICloudfoundry CF DeploymentAI1/6/202622/7/2026
Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the mount-option allowlist, enabling privilege escalation and security control bypass on multi-tenant Diego cells. Affected…
AnalizadaMedia (5)0.20%—Cloudfoundry Cf-deploymentCloudfoundry Routing Release1/5/202617/6/2026
Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure a route-service that would allow it to send requests to HTTP services on internal networks reachable by the Gorouter,…
Pendiente de análisisAlta (7.5)0.20%—Cloudfoundry Capi ReleaseAICloudfoundry CF DeploymentAI17/3/202617/6/2026
Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on all platforms allows any user who has bypassed the firewall to potentially replace droplets and therefore applications allowing them to access secure application information.
ModificadaMedia (6.5)0.23%—Cloudfoundry Cf-deploymentCloudfoundry Uaa-release5/3/202617/6/2026
Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0.
AnalizadaAlta (7.5)0.20%—Cloudfoundry Cf-deploymentCloudfoundry UAA Release13/5/202517/6/2026
Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs.
AnalizadaMedia (6.7)0.17%—Dell Data LakehouseDell InsightiqDell Powerflex Appliance Intelligent CatalogDell Powerflex Manager+110/12/202417/6/2026
Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and…
AnalizadaCrítica (9.8)0.76%—Dell Data LakehouseDell InsightiqDell Powerflex Appliance Intelligent CatalogDell Powerflex Manager+110/12/202417/6/2026
Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and…
AplazadaCrítica (9.1)0.55%—Cloudfoundry Haproxy-boshreleaseAICloudfoundry Routing-releaseAICloudfoundry Cloud FoundryAI3/7/202417/6/2026
When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP requests that bypass mTLS authentication to Cloud Foundry applications. You are affected if you have route-services enabled in routing-release and have configured the…
ModificadaAlta (7.5)0.40%—Cloudfoundry Cf-deploymentCloudfoundry Routing Release10/6/202417/6/2026
Improper handling of requests in Routing Release > v0.273.0 and <= v0.297.0 allows an unauthenticated attacker to degrade the service availability of the Cloud Foundry deployment if performed at scale.
AnalizadaMedia (6.8)0.79%—Jenkins Subversion Partial Release Manager2/5/202417/6/2026
Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 whenever a build is triggered from a release tag, by setting the Java system property 'hudson.model.ParametersAction.keepUndefinedParameters'.
AnalizadaMedia (4.3)0.50%—Jenkins Subversion Partial Release Manager6/3/202417/6/2026
A missing permission check in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers with Item/Read permission to trigger a build.
AnalizadaMedia (4.3)0.31%—Jenkins Subversion Partial Release Manager6/3/202417/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers to trigger a build.
ModificadaMedia (5.5)0.32%—Goreleaser30/1/202417/6/2026
GoReleaser builds Go binaries for several platforms, creates a GitHub release and then pushes a Homebrew formula to a tap repository. `goreleaser release --debug` log shows secret values used in the in the custom publisher. This vulnerability is fixed in 1.24.0.
ModificadaAlta (7.5)0.54%—Pivotal Cloud Foundry DeploymentPivotal Cloud Foundry Routing Release12/1/202417/6/2026
Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route pruning and therefore degrade the service availability of the Cloud Foundry deployment.
ModificadaAlta (7.5)0.20%—3DS Teamwork Cloud NO Magic Release9/10/202317/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x could allow with some very specific conditions an attacker to send a specifically crafted query to the server.
ModificadaMedia (5.4)0.34%—3DS Teamwork Cloud NO Magic Release13/9/202317/6/2026
A stored Cross-site Scripting (XSS) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x allows an attacker to execute arbitrary script code.
ModificadaMedia (5.3)0.44%—Cloudfoundry Cf-deploymentCloudfoundry Routing-release8/9/202317/6/2026
Cloud foundry routing release versions prior to 0.278.0 are vulnerable to abuse of HTTP Hop-by-Hop Headers. An unauthenticated attacker can use this vulnerability for headers like B3 or X-B3-SpanID to affect the identification value recorded in the logs in foundations.
ModificadaMedia (6.1)0.60%—Emby.releases5/8/202317/6/2026
A vulnerability was found in Media Browser Emby Server 4.7.13.0 and classified as problematic. This issue affects some unknown processing of the file /web/. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is…
ModificadaCrítica (9.1)1.7%—Emby.releases30/5/202317/6/2026
Emby Server is a user-installable home media server which stores and organizes a user's media files of virtually any format and makes them available for viewing at home and abroad on a broad range of client devices. This vulnerability may allow administrative access to an Emby Server system, depending on certain user…