Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.8% | — | Golang GOGolang Http2Fedoraproject FedoraNetapp Astra Trident+1 | 11/10/2023 | 17/6/2026 | A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the… | |
| Modificada | Media (5.4) | 0.36% | — | Tridenttechnolabs Easy Slider Revolution | 17/8/2023 | 17/6/2026 | Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in Trident Technolabs Easy Slider Revolution plugin <= 1.0.0 versions. | |
| Modificada | Alta (7.5) | 4.0% | — | Yaml Project YamlNetapp Astra Trident | 19/5/2022 | 17/6/2026 | An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input. | |
| Modificada | Alta (7.5) | 3.2% | — | Golang GONetapp Astra TridentDebian Linux | 5/3/2022 | 17/6/2026 | regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression. | |
| Modificada | Alta (7.1) | 2.1% | — | Kubernetes Ingress-nginxNetapp Trident | 29/10/2021 | 17/6/2026 | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster. | |
| Modificada | Media (6.5) | 7.0% | — | Golang GOFedoraproject FedoraNetapp Cloud Insights TelegrafNetapp Storagegrid+2 | 15/7/2021 | 17/6/2026 | The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic. | |
| Modificada | Media (5.6) | 2.0% | — | Golang GONetapp Trident | 14/12/2020 | 17/6/2026 | The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications. | |
| Modificada | Media (5.6) | 2.1% | — | Golang GONetapp Trident | 14/12/2020 | 17/6/2026 | The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications. | |
| Modificada | Media (5.6) | 2.1% | — | Golang GONetapp Trident | 14/12/2020 | 17/6/2026 | The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications. | |
| Modificada | Alta (7.5) | 2.3% | — | Golang GOFedoraproject FedoraNetapp Cloud Insights Telegraf AgentNetapp Trident | 18/11/2020 | 17/6/2026 | Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via a malicious unquoted symbol name in a linked object file. | |
| Modificada | Alta (7.5) | 3.9% | — | Golang GOFedoraproject FedoraNetapp Cloud Insights Telegraf AgentNetapp Trident | 18/11/2020 | 17/6/2026 | Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service. | |
| Modificada | Alta (7.8) | 0.50% | — | Gskill Trident Z Lighting Control | 29/4/2020 | 17/6/2026 | The ene.sys driver in G.SKILL Trident Z Lighting Control through 1.00.08 exposes mapping and un-mapping of physical memory, reading and writing to Model Specific Register (MSR) registers, and input from and output to I/O ports to local non-privileged users. This leads to privilege escalation to NT AUTHORITY\SYSTEM. | |
| Modificada | Alta (7.5) | 83% | — | Apple SwiftnioApache Traffic ServerDebian LinuxCanonical Ubuntu Linux+24 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can… | |
| Modificada | Media (5) | 0.50% | — | KubernetesNetapp TridentRedhat Openshift Container Platform | 22/4/2019 | 17/6/2026 | In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to other users/groups, the written files may… | |
| Modificada | Alta (8.1) | 1.5% | — | KubernetesNetapp Trident | 22/4/2019 | 17/6/2026 | In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, and client certificate/key data). In the affected versions, rest.AnonymousClientConfig() did not effectively clear service account… | |
| Modificada | Crítica (9.8) | 87% | — | KubernetesRedhat Openshift Container PlatformNetapp Trident | 5/12/2018 | 17/6/2026 | In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same… | |
| Modificada | Alta (7.5) | 1.3% | — | Secluded Trident | 16/3/2018 | 17/6/2026 | Pitchfork version 1.4.6 RC1 contains an Improper Privilege Management vulnerability in Trident Pitchfork components that can result in A standard unprivileged user could gain system administrator permissions within the web portal.. This attack appear to be exploitable via The user must be able to login, and could edit… | |
| Modificada | Media (5.1) | 5.0% | — | Trident Software Powerzip | 27/8/2006 | 16/6/2026 | Stack-based buffer overflow in Trident Software PowerZip 7.06 Build 3895 on Windows 2000 allows remote attackers to execute arbitrary code via a ZIP archive containing a long filename. |