Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
480 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.7) | 0.53% | — | Redhat Advanced Cluster ManagementAIRedhat Multicloud Operators SubscriptionAI | 20/8/2026 | 28/8/2026 | A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This allows the `GetSecret()` function in the HelmRelease controller to fetch… | |
| Pendiente de análisis | Crítica (9.9) | 0.62% | — | Multicloud-operators SubscriptionAI | 20/8/2026 | 28/8/2026 | A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates using its own elevated ServiceAccount… | |
| Pendiente de análisis | Crítica (9.9) | 0.69% | — | Multicloud-operators SubscriptionAI | 17/8/2026 | 29/9/2026 | A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the… | |
| Pendiente de análisis | Alta (7.7) | 0.48% | — | Redhat Advanced Cluster ManagementAIRedhat Multicloud Operators ChannelAI | 12/8/2026 | 27/8/2026 | A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets and ConfigMaps within any Channel… | |
| Pendiente de análisis | Crítica (9.9) | 0.70% | — | Argoproj ArgocdAIOpen Cluster Management Multicloud IntegrationsAI | 12/8/2026 | 27/8/2026 | A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary… | |
| Pendiente de análisis | Crítica (9.6) | 0.52% | — | Argoproj ArgocdAIRedhat Advanced Cluster ManagementAIRedhat Multicloud IntegrationsAI | 12/8/2026 | 27/8/2026 | A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure… | |
| Pendiente de análisis | Alta (7.7) | 0.48% | — | Multicloud-operators SubscriptionAI | 12/8/2026 | 27/8/2026 | A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Namespace field, the user can cause the system to copy sensitive Secret… | |
| Pendiente de análisis | Media (6.4) | 0.33% | — | Multicloud-operators ChannelAI | 12/8/2026 | 5/9/2026 | A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the system handles sensitive information, known as Secrets, across different parts of the system (namespaces). By exploiting this, an attacker can modify these Secrets in… | |
| Aplazada | Crítica (9.6) | 0.45% | — | Banzaicloud Vault Secrets WebhookAI | 31/7/2026 | 10/9/2026 | vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and MutateSecret call newVaultClient in pkg/webhook/webhook.go, and… | |
| Aplazada | Media (5.5) | 0.47% | — | Huimeicloud HM EditorAI | 2/4/2026 | 24/7/2026 | A vulnerability was determined in huimeicloud hm_editor up to 2.2.3. Impacted is the function client.get of the file src/mcp-server.js of the component image-to-base64 Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. It is possible to launch the attack remotely. The… | |
| Aplazada | Media (6) | 0.39% | — | Asus AicloudAI | 25/11/2025 | 17/6/2026 | An integer underflow vulnerability has been identified in Aicloud. An authenticated attacker may trigger this vulnerability by sending a crafted request, potentially impacting the availability of the device. Refer to the ' Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more… | |
| Aplazada | Crítica (9.2) | 16% | — | Asus AicloudAISambaAI | 25/11/2025 | 17/6/2026 | An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality, potentially leading to allow execution of specific functions without proper authorization. Refer to the Security Update for ASUS Router Firmware section on the ASUS… | |
| Aplazada | Crítica (9.2) | 1.1% | — | Asus AicloudAI | 18/4/2025 | 17/6/2026 | An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leading to unauthorized execution of functions. Refer to the 'ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information. | |
| Aplazada | Alta (7.2) | 1.2% | — | Asus AicloudAI | 2/1/2025 | 17/6/2026 | An improper input insertion vulnerability in AiCloud on certain router models may lead to arbitrary command execution. Refer to the '01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information. | |
| Analizada | Alta (8.8) | 0.84% | — | IBM Cloud PAK FOR Multicloud Management Monitoring | 26/9/2024 | 17/6/2026 | IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted yaml file request. | |
| Analizada | Media (4.9) | 0.34% | — | IBM Cloud PAK FOR Multicloud Management Monitoring | 26/9/2024 | 17/6/2026 | IBM Cloud Pak for Multicloud Management 2.3 through 2.3 FP8 stores user credentials in a log file plain clear text which can be read by a privileged user. | |
| Modificada | Alta (8.8) | 0.53% | — | IBM Cloud PAK FOR Multicloud Management Monitoring | 8/2/2023 | 17/6/2026 | IBM Cloud Pak for Multicloud Management Monitoring 2.0 and 2.3 allows users without admin roles access to admin functions by specifying direct URL paths. IBM X-Force ID: 238210. | |
| Modificada | Media (6.5) | 0.95% | — | Apple IcloudApple SafariApple IpadosApple Iphone OS+3 | 15/12/2022 | 17/6/2026 | A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may disclose sensitive user information. | |
| Modificada | Alta (7.8) | 0.38% | — | Apple IcloudApple IpadosApple Iphone OSApple Macos+2 | 15/12/2022 | 17/6/2026 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing a maliciously crafted file may lead to arbitrary code execution. | |
| Modificada | Media (5.5) | 0.21% | — | Apple IcloudApple SafariApple IpadosApple Iphone OS+3 | 15/12/2022 | 17/6/2026 | A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may bypass Same Origin Policy. | |
| Modificada | Alta (7.1) | 0.44% | — | Apple IcloudApple ItunesApple IpadosApple Iphone OS+3 | 23/9/2022 | 17/6/2026 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iCloud for Windows 11.4, iOS 14.0 and iPadOS 14.0, watchOS 7.0, tvOS 14.0, iCloud for Windows 7.21, iTunes for Windows 12.10.9. Processing a maliciously crafted tiff file may lead to a denial-of-service or potentially disclose… | |
| Modificada | Alta (8.1) | 0.92% | — | IBM Cloud PAK FOR Multicloud Management Monitoring | 30/6/2022 | 17/6/2026 | IBM CloudPak for Multicloud Monitoring 2.0 and 2.3 has a few containers running in privileged mode which is vulnerable to host information leakage or destruction if unauthorized access to these containers could execute arbitrary commands. IBM X-Force ID: 211048. | |
| Modificada | Alta (8.8) | 1.1% | — | Baicloud-cms Project Baicloud-cms | 19/2/2022 | 17/6/2026 | BaiCloud-cms v2.5.7 was discovered to contain multiple SQL injection vulnerabilities via the tongji and baidu_map parameters in /user/ztconfig.php. | |
| Modificada | Alta (7.8) | 0.92% | — | Apple IcloudApple ItunesApple Iphone OSApple MAC OS X+1 | 23/12/2021 | 17/6/2026 | A null pointer dereference was addressed with improved validation. This issue is fixed in macOS High Sierra 10.13, iCloud for Windows 7.0, watchOS 4, iOS 11, iTunes 12.7 for Windows. Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution. | |
| Modificada | Crítica (9.1) | 1.0% | — | Baicloud-cms Project Baicloud-cms | 30/9/2021 | 17/6/2026 | BaiCloud-cms v2.5.7 is affected by an arbitrary file deletion vulnerability, which allows an attacker to delete arbitrary files on the server through /user/ppsave.php. |