Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.8%—Golang GOGolang Http2Fedoraproject FedoraNetapp Astra Trident+111/10/202317/6/2026
A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the…
ModificadaMedia (5.4)0.36%—Tridenttechnolabs Easy Slider Revolution17/8/202317/6/2026
Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in Trident Technolabs Easy Slider Revolution plugin <= 1.0.0 versions.
ModificadaAlta (7.5)4.0%—Yaml Project YamlNetapp Astra Trident19/5/202217/6/2026
An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.
ModificadaAlta (7.5)3.2%—Golang GONetapp Astra TridentDebian Linux5/3/202217/6/2026
regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression.
ModificadaAlta (7.1)2.1%—Kubernetes Ingress-nginxNetapp Trident29/10/202117/6/2026
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.
ModificadaMedia (6.5)7.0%—Golang GOFedoraproject FedoraNetapp Cloud Insights TelegrafNetapp Storagegrid+215/7/202117/6/2026
The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.
ModificadaMedia (5.6)2.0%—Golang GONetapp Trident14/12/202017/6/2026
The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.
ModificadaMedia (5.6)2.1%—Golang GONetapp Trident14/12/202017/6/2026
The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.
ModificadaMedia (5.6)2.1%—Golang GONetapp Trident14/12/202017/6/2026
The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.
ModificadaAlta (7.5)2.3%—Golang GOFedoraproject FedoraNetapp Cloud Insights Telegraf AgentNetapp Trident18/11/202017/6/2026
Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via a malicious unquoted symbol name in a linked object file.
ModificadaAlta (7.5)3.9%—Golang GOFedoraproject FedoraNetapp Cloud Insights Telegraf AgentNetapp Trident18/11/202017/6/2026
Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.
ModificadaAlta (7.8)0.50%—Gskill Trident Z Lighting Control29/4/202017/6/2026
The ene.sys driver in G.SKILL Trident Z Lighting Control through 1.00.08 exposes mapping and un-mapping of physical memory, reading and writing to Model Specific Register (MSR) registers, and input from and output to I/O ports to local non-privileged users. This leads to privilege escalation to NT AUTHORITY\SYSTEM.
ModificadaAlta (7.5)83%—Apple SwiftnioApache Traffic ServerDebian LinuxCanonical Ubuntu Linux+2413/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can…
ModificadaMedia (5)0.50%—KubernetesNetapp TridentRedhat Openshift Container Platform22/4/201917/6/2026
In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to other users/groups, the written files may…
ModificadaAlta (8.1)1.5%—KubernetesNetapp Trident22/4/201917/6/2026
In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, and client certificate/key data). In the affected versions, rest.AnonymousClientConfig() did not effectively clear service account…
ModificadaCrítica (9.8)87%—KubernetesRedhat Openshift Container PlatformNetapp Trident5/12/201817/6/2026
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same…
ModificadaAlta (7.5)1.3%—Secluded Trident16/3/201817/6/2026
Pitchfork version 1.4.6 RC1 contains an Improper Privilege Management vulnerability in Trident Pitchfork components that can result in A standard unprivileged user could gain system administrator permissions within the web portal.. This attack appear to be exploitable via The user must be able to login, and could edit…
ModificadaMedia (5.1)5.0%—Trident Software Powerzip27/8/200616/6/2026
Stack-based buffer overflow in Trident Software PowerZip 7.06 Build 3895 on Windows 2000 allows remote attackers to execute arbitrary code via a ZIP archive containing a long filename.