Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

697 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.52%—Redhat Openshift Container PlatformRedhat Openshift Container Platform FOR LinuxoneRedhat Openshift Container Platform FOR PowerRedhat Openshift Container Platform IBM Z Systems+15/7/202317/6/2026
A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.
ModificadaMedia (6.5)0.94%—Redhat Openshift API FOR Data ProtectionRedhat Openshift Container PlatformRedhat Openshift Developer Tools AND Services6/6/202317/6/2026
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array,…
ModificadaAlta (7.8)0.19%—IBM Spectrum Scale Container Native Storage Access29/4/202317/6/2026
IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0 contains an unspecified vulnerability that could allow a local user to obtain root privileges. IBM X-Force ID: 237810.
ModificadaAlta (8.4)0.20%—IBM Spectrum Scale Container Native Storage Access26/4/202317/6/2026
IBM Spectrum Scale (IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0) could allow programs running inside the container to overcome isolation mechanism and gain additional capabilities or access sensitive information on the host. IBM X-Force ID: 237815.
ModificadaAlta (8.2)1.2%—Cloudbase Open VswitchDebian LinuxRedhat Openshift Container PlatformRedhat Openstack Platform+210/4/202317/6/2026
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow,…
ModificadaMedia (5.4)0.70%💥 PoCRedhat KeycloakRedhat Single Sign-onRedhat Openshift Container Platform29/3/202317/6/2026
A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.
ModificadaMedia (5.5)0.25%—Redhat Openshift Assisted InstallerRedhat Openshift Container Platform24/3/202317/6/2026
A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.
ModificadaMedia (6.5)1.8%—HaproxyRedhat Ceph StorageRedhat Software CollectionsRedhat Openshift Container Platform+523/3/202317/6/2026
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
ModificadaAlta (8.8)0.75%—IBM MQ Certified Container15/3/202317/6/2026
IBM MQ Certified Container 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1 could allow authenticated users with the cluster to be granted administration access to the MQ console due to improper access controls. IBM X-Force ID: 248417.
ModificadaMedia (6.1)0.39%—IBM APP Connect Enterprise Certified Container15/3/202317/6/2026
IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, 6.2, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…
ModificadaAlta (7)0.45%—Linuxfoundation RuncRedhat Openshift Container PlatformRedhat Enterprise LinuxDebian Linux3/3/202317/6/2026
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921…
ModificadaAlta (7.8)0.54%—Linuxfoundation Containerd16/2/202317/6/2026
containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use…
ModificadaMedia (5.5)0.36%—Linuxfoundation Containerd16/2/202317/6/2026
containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service. This bug has been fixed in…
ModificadaMedia (4.9)0.67%—IBM APP Connect EnterpriseIBM APP Connect Enterprise Certified Container6/2/202317/6/2026
IBM App Connect Enterprise 11.0.0.17 through 11.0.0.19 and 12.0.4.0 and 12.0.5.0 contains an unspecified vulnerability in the Discovery Connector nodes which may cause a 3rd party system’s credentials to be exposed to a privileged attacker. IBM X-Force ID: 238211.
ModificadaMedia (6.5)0.36%—IBM APP Connect Enterprise Certified Container1/2/202317/6/2026
IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, and 6.2 could disclose sensitive information to an attacker due to a weak hash of an API Key in the configuration. IBM X-Force ID: 241583.
ModificadaAlta (7.6)0.71%—Sylabs Singularity Container Services Library17/1/202317/6/2026
github.com/sylabs/scs-library-client is the Go client for the Singularity Container Services (SCS) Container Library Service. When the scs-library-client is used to pull a container image, with authentication, the HTTP Authorization header sent by the client to the library service may be incorrectly leaked to an S3…
ModificadaBaja (3.3)0.70%💥 PoCLinuxcontainers LXC1/1/202317/6/2026
lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "does not refer to a network namespace path" often indicates that a file exists.…
ModificadaMedia (5.9)0.68%—Redhat Openshift Container PlatformRedhat Openshift Osin28/12/202217/6/2026
A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch is 8612686d6dda34ae9ef6b5a974e4b7accb4fea29. It is recommended to…
ModificadaMedia (4.2)0.59%—Amazon Efs-utilsAmazon Elastic File System Container Storage Interface Driver28/12/202217/6/2026
efs-utils is a set of Utilities for Amazon Elastic File System (EFS). A potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to…
ModificadaMedia (6.5)1.1%—Linuxfoundation Containerd7/12/202217/6/2026
containerd is an open source container runtime. A bug was found in containerd's CRI implementation where a user can exhaust memory on the host. In the CRI stream server, a goroutine is launched to handle terminal resize events if a TTY is requested. If the user's process fails to launch due to, for example, a faulty…
ModificadaAlta (7.8)0.29%—IBM Spectrum Scale Container Native Storage Access6/12/202217/6/2026
IBM Spectrum Scale 5.1.0.1 through 5.1.4.1 could allow a local attacker to execute arbitrary commands in the container. IBM X-Force ID: 239437.
ModificadaAlta (7.5)0.21%—Hcltech HCL Launch Container Image31/10/202217/6/2026
The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages.
ModificadaAlta (8.8)2.2%—Dell Container Storage Modules11/10/202217/6/2026
Dell Container Storage Modules 1.2 contains an OS Command Injection in goiscsi and gobrick libraries. A remote unauthenticated attacker could exploit this vulnerability leading to modification of intended OS command execution.
ModificadaAlta (8.8)1.6%—Dell Container Storage Modules11/10/202217/6/2026
Dell Container Storage Modules 1.2 contains an Improper Limitation of a Pathname to a Restricted Directory in goiscsi and gobrick libraries which could lead to OS command injection. A remote unauthenticated attacker could exploit this vulnerability leading to unintentional access to path outside of restricted…
ModificadaMedia (5.4)0.72%—Jenkins Anchore Container Image Scanner21/9/202217/6/2026
Jenkins Anchore Container Image Scanner Plugin 1.0.24 and earlier does not escape content provided by the Anchore engine API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control API responses by Anchore engine.
Orbitaley — Vulnerabilidades