Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3021▲ 414 respecto a la semana anterior
Críticas / altas1420▲ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 169 respecto a la semana anterior
–

368 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.9)0.24%—KubevirtRedhat Openshift Virtualization26/6/20266/7/2026
A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance with a Multus network configuration, the supplied networkName value is written verbatim into the launcher pod's v1.multus-cni.io/default-network annotation without format validation or sanitization. The only…
AnalizadaBaja (3.8)0.13%—Redhat Openshift VirtualizationKubevirt26/6/20266/7/2026
A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely until a newline character is received, with no length limit or read deadline. A user with access to a VM guest that has the downward metrics…
AnalizadaMedia (6.4)0.24%—KubevirtRedhat Openshift Virtualization26/6/20266/7/2026
A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-forward request to a VirtualMachineInstance (VMI), virt-api reads the target IP from vmi.Status.Interfaces[0].IP and passes it directly to net.Dial() without validation. For VMIs using non-masquerade…
AnalizadaMedia (4.2)0.14%—KubevirtRedhat Openshift Virtualization26/6/20266/7/2026
A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data to a launcher-rooted path using os.WriteFile and os.Chown without symlink protection. A user with access to the virt-launcher container can plant a symlink at the cache file path, causing virt-handler to…
AnalizadaMedia (6.5)0.13%—KubevirtRedhat Openshift Virtualization24/6/20266/7/2026
A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity (namespace/name) solely from the request body without validating it against the connection's origin. Each virt-launcher pod connects through a per-VMI pipe socket, but no…
ModificadaAlta (7.3)0.27%—KubevirtRedhat Openshift Virtualization24/6/202621/9/2026
A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream operations resolve the path via /proc/self/fd/N using link-following syscalls. When the leaf is a symlink, the kernel dereferences it,…
Pendiente de análisisAlta (8.6)0.21%—Suse HarvesterAISuse VirtualizationAISuse Rancher ManagerAI16/6/202630/9/2026
An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse it to bypass TLS as a security control.
AplazadaAlta (7.2)0.40%—IEI Integration Corp Ivec Virtualization Edge ComputerAI12/6/202617/6/2026
The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerability, allowing authenticated remote attackers to exploit this vulnerability to delete arbitrary system files or directories, resulting in data destruction or service disruption.
AplazadaAlta (8.6)0.95%—IEI Integration Corp Ivec Virtualization Edge ComputerAI12/6/202617/6/2026
The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injection vulnerability, allowing privileged remote attackers to inject arbitrary OS commands and execute them on the device.
AplazadaMedia (6.9)0.41%—IEI Integration Corp Ivec-iei Virtualization Edge ComputerAI12/6/202617/6/2026
The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Arbitrary File Read vulnerability, allowing privileged remote attackers to access files outside the intended directory scope.
ModificadaAlta (7.7)1.0%—AxiosRedhat Advanced Cluster Management FOR KubernetesRedhat Advanced Cluster SecurityRedhat Ansible Automation Platform+811/6/202611/9/2026
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions…
Pendiente de análisisBaja (2)0.07%—AMD Mxgpu-virtualization DriverAI15/5/202617/6/2026
A race condition in the MxGPU-Virtualization driver’s ioctl path caused by concurrent unsynchronized access to the global variable amdgv_cmd in an unlocked ioctl handler could be exploited by an attacker to trigger a heap-based buffer overflow, potentially resulting in denial-of-service within the vulnerable system…
Pendiente de análisisMedia (6.8)0.10%—Windows Display Virtualization DriverAI12/5/202617/6/2026
Improper buffer restrictions for some Display Virtualization for Windows OS driver software within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via…
AplazadaMedia (5.9)0.15%—AMD Secure Encrypted VirtualizationAI10/2/202617/6/2026
Improper Initialization within the AMD Secure Encrypted Virtualization (SEV) firmware can allow an admin privileged attacker to corrupt RMP covered memory, potentially resulting in loss of guest memory integrity
AplazadaMedia (5.9)0.15%—AMD Secure Encrypted VirtualizationAI10/2/202617/6/2026
Improper access control in AMD Secure Encrypted Virtualization (SEV) firmware could allow a malicious hypervisor to bypass RMP protections, potentially resulting in a loss of SEV-SNP guest memory integrity.
AplazadaMedia (5.4)0.12%—Display Virtualization FOR Windows OSAI11/11/202517/6/2026
Uncontrolled search path for some Display Virtualization for Windows OS software before version 1797 within Ring 2: Device Drivers may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may…
AplazadaMedia (6.4)0.19%—Container-native VirtualizationAI23/10/20256/8/2026
A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root…
AplazadaCrítica (9.3)0.40%—Siemens Simatic Virtualization AS A ServiceAI9/9/202517/6/2026
A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions). The affected application exposes a network share without any authentication. This could allow an attacker to access or alter sensitive data without proper authorization.
ModificadaMedia (6.5)0.45%—Nbdkit Project NbdkitRedhat Enterprise LinuxRedhat Enterprise Linux Advanced Virtualization9/6/202530/6/2026
There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even larger single block, the nbdkit server can encounter a critical internal error, leading to a…
AplazadaMedia (6.8)0.16%—HPE Cray Data Virtualization ServiceAI22/4/202517/6/2026
A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on race conditions and configuration, this vulnerability may lead to local/cluster unauthorized access.
AnalizadaCrítica (10)99%⚠ Explotación activaErlang/otpCisco Confd BasicCisco Network Services OrchestratorCisco Cloud Native Broadband Network Gateway+1916/4/202517/6/2026
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain…
AplazadaMedia (5.3)0.13%—Kaspersky Anti-virus SDK FOR WindowsAIKaspersky Security FOR Virtualization Light AgentAIKaspersky Endpoint Security FOR WindowsAIKaspersky Small Office SecurityAI+96/2/202517/6/2026
Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small Office Security, Kaspersky for Windows (Standard, Plus, Premium), Kaspersky Free, Kaspersky Anti-Virus, Kaspersky Internet Security,…
AnalizadaMedia (6.5)0.48%—IBM Data Virtualization ON Cloud PAK FOR DataIBM Watson Query With Cloud PAK FOR Data27/1/202517/6/2026
IBM Watson Query on Cloud Pak for Data (IBM Data Virtualization 1.8, 2.0, 2.1, 2.2, and 3.0.0) could allow an authenticated user to obtain sensitive information from objects published using Watson Query due to an improper data protection mechanism.
AnalizadaAlta (8.8)0.77%—IBM Data Virtualization Manager FOR Z/os26/11/202417/6/2026
IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL parameters and execute code on the server.
AplazadaMedia (5.5)0.14%—HPE Cray Data Virtualization ServiceAI15/11/202417/6/2026
A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.