Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

3 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.37%—Kubernetes Secrets-store-csi-driver7/6/202317/6/2026
Kubernetes secrets-store-csi-driver in versions before 1.3.3 discloses service account tokens in logs.
ModificadaMedia (6.5)1.3%—Kubernetes Secrets Store CSI Driver21/1/202117/6/2026
Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassPodStatus/Status resource the ability to write content to the host filesystem and sync file contents to Kubernetes Secrets. This includes paths under var/lib/kubelet/pods that contain other Kubernetes…
ModificadaMedia (6.5)1.4%—Google Secret Manager Provider FOR Secret Store CSI DriverHashicorp Vault Provider FOR Secrets Store CSI DriverMicrosoft Azure KEY Vault Provider FOR Secrets Store CSI Driver21/1/202117/6/2026
Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including /var/lib/kubelet/pods.