Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
4007 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.27% | — | Suse Rancher Fleet | 28/9/2026 | 7/10/2026 | A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where different tenants share the same downstream clusters, for… | |
| Pendiente de análisis | Alta (8.1) | 0.25% | — | Suse RancherAI | 28/9/2026 | 29/9/2026 | Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE Rancher 2.15 before 2.15.2. | |
| Pendiente de análisis | Crítica (9.6) | 0.54% | — | Suse RancherAI | 28/9/2026 | 29/9/2026 | An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18. | |
| Analizada | Media (6.5) | 0.17% | — | Suse Rancher Fleet | 28/9/2026 | 7/10/2026 | A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations options, the resulting namespace metadata update was not subject to the same authorization as the rest of the bundle's deployment. As a result, a bundle could change… | |
| Analizada | Media (5.4) | 0.23% | — | Suse Rancher Fleet | 28/9/2026 | 7/10/2026 | A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the spec.pollingInterval field of a matching GitRepo resource in any namespace. A caller… | |
| Analizada | Alta (7.1) | 0.17% | — | Suse Rancher Fleet | 28/9/2026 | 7/10/2026 | A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster… | |
| Analizada | Media (6.5) | 0.30% | — | Suse Rancher Fleet | 28/9/2026 | 7/10/2026 | A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesystem of the environment that processes the bundle and include their contents in the… | |
| Pendiente de análisis | Media (5.3) | 0.61% | — | Beautiful SoupAIFacelessuser Soup SieveAI | 17/9/2026 | 30/9/2026 | Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent quantified groups over overlapping character classes, and VALUE embeds IDENTIFIER for attribute selectors. When an attacker-controlled… | |
| Pendiente de análisis | Media (5.3) | 0.61% | — | Beautiful SoupAIFacelessuser Soup SieveAI | 17/9/2026 | 23/9/2026 | Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC whitespace-and-comment expression used with search(), so the regular expression engine retries a greedy scan at every… | |
| Pendiente de análisis | Media (5.7) | 0.22% | — | Suse ObservabilityAIRancher-extension-stackstateAI | 17/9/2026 | 29/9/2026 | The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unauthorized access or escalate privileges within the observability environment. | |
| Pendiente de análisis | Media (6.8) | 0.20% | — | Suse NeuvectorAI | 9/9/2026 | 10/9/2026 | An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container’s log This issue affects neuvector: before 5.4.5. | |
| Analizada | Media (5.3) | 0.36% | — | Suse Rancher Fleet | 3/9/2026 | 7/10/2026 | A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. A user who can supply bundle content to a repository referenced by a `GitRepo` resource can cause the Fleet controller to: -… | |
| Analizada | Alta (7.1) | 0.34% | — | Suse Rancher | 3/9/2026 | 18/9/2026 | A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authenticated user could therefore list and watch every other user's tokens, disclosing… | |
| Analizada | Alta (7.4) | 0.32% | — | Suse Rancher | 3/9/2026 | 18/9/2026 | A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process cache, so each replica only detected replays that reached the same pod. In a high-availability deployment, an attacker holding a captured assertion could… | |
| Analizada | Alta (7.7) | 0.34% | — | Suse Rancher | 3/9/2026 | 18/9/2026 | A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the referenced project belonged to the same downstream cluster. A user able to create namespaces on one cluster could set the annotation to a project ID… | |
| Analizada | Alta (8.7) | 0.42% | — | Suse Rancher | 3/9/2026 | 18/9/2026 | A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation and overwrote that object's rules without verifying ownership. A user with delegated GlobalRole create or update permission could point the… | |
| Analizada | Media (6.1) | 0.37% | — | Suse Rancher | 3/9/2026 | 18/9/2026 | A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `username` and `principalIds` fields. A user holding the `update` verb on `users.management.cattle.io` could inject a foreign identity provider principal into any account, so that the next login by the… | |
| Pendiente de análisis | Alta (8.6) | 1.6% | — | Suse Yast2-usersAI | 1/9/2026 | 2/9/2026 | An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of a user, get_password_term() in src/include/users/dialogs.rb read the shadowLastChange and shadowExpire fields with GetString(), which performs no numeric validation, and passed the resulting string to… | |
| Pendiente de análisis | Media (5.5) | 0.16% | — | Fedora DNFAISuse ZypperAIRedhat YUMAIOpensuse LibsolvAI | 28/8/2026 | 28/8/2026 | A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id values from the file's compressed filelist data without validating that they fall within the… | |
| Pendiente de análisis | Alta (7.5) | 0.61% | — | Facelessuser Pymdown-extensionsAI | 6/8/2026 | 10/9/2026 | pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can partition a run of delimiter characters in exponentially many ways, causing… | |
| Pendiente de análisis | Media (5.3) | 0.40% | — | Facelessuser Pymdown ExtensionsAI | 6/8/2026 | 10/9/2026 | PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vulnerable to a path traversal that discloses arbitrary files: it inlines images referenced by <img src="..."> by joining the src onto the configured base_path with… | |
| Pendiente de análisis | Alta (7.5) | 0.48% | — | Opensuse PCPAI | 30/7/2026 | 1/10/2026 | A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads. | |
| Analizada | Media (4.3) | 0.40% | — | Facelessuser Pymdown Extensions | 16/7/2026 | 30/7/2026 | PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.snippets uses a string-prefix containment check in SnippetPreprocessor.get_snippet_path() in pymdownx/snippets.py when `restrict_base_path: True`, allowing markdown snippet directives to read files… | |
| Pendiente de análisis | Alta (7.5) | 0.82% | — | Opensuse LibsolvAI | 16/7/2026 | 31/8/2026 | A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted… | |
| Analizada | Alta (7.5) | 0.64% | — | Facelessuser Soup Sieve | 14/7/2026 | 28/7/2026 | Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in soupsieve/css_parser.py, allowing an… |