Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3021▲ 414 respecto a la semana anterior
Críticas / altas1420▲ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 169 respecto a la semana anterior
368 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.9) | 0.24% | — | KubevirtRedhat Openshift Virtualization | 26/6/2026 | 6/7/2026 | A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance with a Multus network configuration, the supplied networkName value is written verbatim into the launcher pod's v1.multus-cni.io/default-network annotation without format validation or sanitization. The only… | |
| Analizada | Baja (3.8) | 0.13% | — | Redhat Openshift VirtualizationKubevirt | 26/6/2026 | 6/7/2026 | A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely until a newline character is received, with no length limit or read deadline. A user with access to a VM guest that has the downward metrics… | |
| Analizada | Media (6.4) | 0.24% | — | KubevirtRedhat Openshift Virtualization | 26/6/2026 | 6/7/2026 | A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-forward request to a VirtualMachineInstance (VMI), virt-api reads the target IP from vmi.Status.Interfaces[0].IP and passes it directly to net.Dial() without validation. For VMIs using non-masquerade… | |
| Analizada | Media (4.2) | 0.14% | — | KubevirtRedhat Openshift Virtualization | 26/6/2026 | 6/7/2026 | A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data to a launcher-rooted path using os.WriteFile and os.Chown without symlink protection. A user with access to the virt-launcher container can plant a symlink at the cache file path, causing virt-handler to… | |
| Analizada | Media (6.5) | 0.13% | — | KubevirtRedhat Openshift Virtualization | 24/6/2026 | 6/7/2026 | A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity (namespace/name) solely from the request body without validating it against the connection's origin. Each virt-launcher pod connects through a per-VMI pipe socket, but no… | |
| Modificada | Alta (7.3) | 0.27% | — | KubevirtRedhat Openshift Virtualization | 24/6/2026 | 21/9/2026 | A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream operations resolve the path via /proc/self/fd/N using link-following syscalls. When the leaf is a symlink, the kernel dereferences it,… | |
| Pendiente de análisis | Alta (8.6) | 0.21% | — | Suse HarvesterAISuse VirtualizationAISuse Rancher ManagerAI | 16/6/2026 | 30/9/2026 | An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse it to bypass TLS as a security control. | |
| Aplazada | Alta (7.2) | 0.40% | — | IEI Integration Corp Ivec Virtualization Edge ComputerAI | 12/6/2026 | 17/6/2026 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerability, allowing authenticated remote attackers to exploit this vulnerability to delete arbitrary system files or directories, resulting in data destruction or service disruption. | |
| Aplazada | Alta (8.6) | 0.95% | — | IEI Integration Corp Ivec Virtualization Edge ComputerAI | 12/6/2026 | 17/6/2026 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injection vulnerability, allowing privileged remote attackers to inject arbitrary OS commands and execute them on the device. | |
| Aplazada | Media (6.9) | 0.41% | — | IEI Integration Corp Ivec-iei Virtualization Edge ComputerAI | 12/6/2026 | 17/6/2026 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Arbitrary File Read vulnerability, allowing privileged remote attackers to access files outside the intended directory scope. | |
| Modificada | Alta (7.7) | 1.0% | — | AxiosRedhat Advanced Cluster Management FOR KubernetesRedhat Advanced Cluster SecurityRedhat Ansible Automation Platform+8 | 11/6/2026 | 11/9/2026 | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions… | |
| Pendiente de análisis | Baja (2) | 0.07% | — | AMD Mxgpu-virtualization DriverAI | 15/5/2026 | 17/6/2026 | A race condition in the MxGPU-Virtualization driver’s ioctl path caused by concurrent unsynchronized access to the global variable amdgv_cmd in an unlocked ioctl handler could be exploited by an attacker to trigger a heap-based buffer overflow, potentially resulting in denial-of-service within the vulnerable system… | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | Windows Display Virtualization DriverAI | 12/5/2026 | 17/6/2026 | Improper buffer restrictions for some Display Virtualization for Windows OS driver software within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via… | |
| Aplazada | Media (5.9) | 0.15% | — | AMD Secure Encrypted VirtualizationAI | 10/2/2026 | 17/6/2026 | Improper Initialization within the AMD Secure Encrypted Virtualization (SEV) firmware can allow an admin privileged attacker to corrupt RMP covered memory, potentially resulting in loss of guest memory integrity | |
| Aplazada | Media (5.9) | 0.15% | — | AMD Secure Encrypted VirtualizationAI | 10/2/2026 | 17/6/2026 | Improper access control in AMD Secure Encrypted Virtualization (SEV) firmware could allow a malicious hypervisor to bypass RMP protections, potentially resulting in a loss of SEV-SNP guest memory integrity. | |
| Aplazada | Media (5.4) | 0.12% | — | Display Virtualization FOR Windows OSAI | 11/11/2025 | 17/6/2026 | Uncontrolled search path for some Display Virtualization for Windows OS software before version 1797 within Ring 2: Device Drivers may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may… | |
| Aplazada | Media (6.4) | 0.19% | — | Container-native VirtualizationAI | 23/10/2025 | 6/8/2026 | A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Siemens Simatic Virtualization AS A ServiceAI | 9/9/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions). The affected application exposes a network share without any authentication. This could allow an attacker to access or alter sensitive data without proper authorization. | |
| Modificada | Media (6.5) | 0.45% | — | Nbdkit Project NbdkitRedhat Enterprise LinuxRedhat Enterprise Linux Advanced Virtualization | 9/6/2025 | 30/6/2026 | There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even larger single block, the nbdkit server can encounter a critical internal error, leading to a… | |
| Aplazada | Media (6.8) | 0.16% | — | HPE Cray Data Virtualization ServiceAI | 22/4/2025 | 17/6/2026 | A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on race conditions and configuration, this vulnerability may lead to local/cluster unauthorized access. | |
| Analizada | Crítica (10) | 99% | ⚠ Explotación activa | Erlang/otpCisco Confd BasicCisco Network Services OrchestratorCisco Cloud Native Broadband Network Gateway+19 | 16/4/2025 | 17/6/2026 | Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain… | |
| Aplazada | Media (5.3) | 0.13% | — | Kaspersky Anti-virus SDK FOR WindowsAIKaspersky Security FOR Virtualization Light AgentAIKaspersky Endpoint Security FOR WindowsAIKaspersky Small Office SecurityAI+9 | 6/2/2025 | 17/6/2026 | Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small Office Security, Kaspersky for Windows (Standard, Plus, Premium), Kaspersky Free, Kaspersky Anti-Virus, Kaspersky Internet Security,… | |
| Analizada | Media (6.5) | 0.48% | — | IBM Data Virtualization ON Cloud PAK FOR DataIBM Watson Query With Cloud PAK FOR Data | 27/1/2025 | 17/6/2026 | IBM Watson Query on Cloud Pak for Data (IBM Data Virtualization 1.8, 2.0, 2.1, 2.2, and 3.0.0) could allow an authenticated user to obtain sensitive information from objects published using Watson Query due to an improper data protection mechanism. | |
| Analizada | Alta (8.8) | 0.77% | — | IBM Data Virtualization Manager FOR Z/os | 26/11/2024 | 17/6/2026 | IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL parameters and execute code on the server. | |
| Aplazada | Media (5.5) | 0.14% | — | HPE Cray Data Virtualization ServiceAI | 15/11/2024 | 17/6/2026 | A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access. |