Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
698 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Crun Project CrunFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux | 4/4/2022 | 17/6/2026 | A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable… | |
| Modificada | Alta (7.5) | 1.4% | — | Podman Project PodmanRedhat Developer ToolsRedhat Openshift Container PlatformRedhat Enterprise Linux+10 | 4/4/2022 | 17/6/2026 | A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with… | |
| Modificada | Baja (3.7) | 0.77% | — | Redhat Openshift Container PlatformRedhat Openshift Machine-config-operator | 1/4/2022 | 17/6/2026 | It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accessed externally from clusters without authentication. The MCS endpoint (port 22623) provides ignition configuration used for bootstrapping Nodes and can include some sensitive data, e.g. registry pull… | |
| Modificada | Media (6.5) | 0.98% | — | IBM APP Connect Enterprise Certified Container | 1/4/2022 | 17/6/2026 | IBM App Connect Enterprise Certified Container Dashboard UI (IBM App Connect Enterprise Certified Container 1.5, 2.0, 2.1, 3.0, and 3.1) may be vulnerable to denial of service due to excessive rate limiting. | |
| Modificada | Alta (7) | 0.43% | — | Linux KernelRedhat 3scale API ManagementRedhat Build OF QuarkusRedhat Codeready Linux Builder EUS+28 | 3/3/2022 | 17/6/2026 | .A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root. | |
| Modificada | Alta (7.5) | 27% | 💥 PoC | Linuxfoundation ContainerdDebian LinuxFedoraproject Fedora | 3/3/2022 | 17/6/2026 | containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration could gain access to read-only copies of… | |
| Modificada | Media (6.3) | 0.49% | — | Redhat LibvirtRedhat Openshift Container PlatformRedhat Enterprise LinuxNetapp Ontap Select Deploy Administration Utility | 2/3/2022 | 17/6/2026 | A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity. | |
| Modificada | Alta (7.5) | 17% | — | HaproxyRedhat Openshift Container PlatformRedhat Software CollectionsRedhat Enterprise Linux+1 | 2/3/2022 | 17/6/2026 | A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability. | |
| Analizada | Alta (7.8) | 24% | ⚠ Explotación activa💥 Exploit | Polkit Project PolkitDebian LinuxCanonical Ubuntu LinuxRedhat Virtualization+2 | 16/2/2022 | 17/6/2026 | It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to… | |
| Modificada | Media (4.2) | 0.77% | — | Kubernetes Cri-oRedhat Openshift Container Platform | 9/2/2022 | 17/6/2026 | An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace. | |
| Modificada | Alta (8.8) | 1.00% | — | Mirantis Container Cloud Lens Extension | 4/2/2022 | 17/6/2026 | Lack of validation of URLs causes Mirantis Container Cloud Lens Extension before v3.1.1 to open external programs other than the default browser to perform sign on to a new cluster. An attacker could host a webserver which serves a malicious Mirantis Container Cloud configuration file and induce the victim to add a… | |
| Modificada | Alta (7.5) | 0.90% | — | Mirantis Container Runtime | 10/1/2022 | 17/6/2026 | When running with FIPS mode enabled, Mirantis Container Runtime 20.10.8 leaks memory during TLS Handshakes which could be abused to cause a denial of service. | |
| Modificada | Crítica (9.1) | 1.7% | — | Linuxfoundation ContainerdFedoraproject Fedora | 5/1/2022 | 17/6/2026 | containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod scheduled to the node may bind mount, via hostPath volume, any privileged,… | |
| Modificada | Alta (7.5) | 81% | 💥 PoC | Apache Log4jFedoraproject FedoraRedhat Codeready StudioRedhat Integration Camel K+42 | 14/12/2021 | 17/6/2026 | JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in… | |
| Modificada | Crítica (9.1) | 2.8% | — | Lapack Project LapackOpenblas Project OpenblasJulialang JuliaRedhat Ceph Storage+4 | 8/12/2021 | 17/6/2026 | An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory. | |
| Modificada | Media (5) | 2.2% | — | Linuxfoundation Open Container Initiative Distribution SpecificationLinuxfoundation Open Container Initiative Image Format SpecificationFedoraproject Fedora | 17/11/2021 | 17/6/2026 | The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specification version 1.0.0 and prior, the Content-Type header alone was used to determine the type of document during push and pull operations. Documents that contain both… | |
| Modificada | Media (5.5) | 0.22% | — | IBM APP Connect Enterprise Certified Container | 8/10/2021 | 17/6/2026 | IBM App Connect Enterprise Certified Container 1.0, 1.1, 1.2, 1.3, 1.4 and 1.5 could disclose sensitive information to a local user when it is configured to use an IBM Cloud API key to connect to cloud-based connectors. IBM X-Force ID: 207630. | |
| Modificada | Alta (7.8) | 0.52% | — | Linuxfoundation ContainerdFedoraproject FedoraDebian Linux | 4/10/2021 | 17/6/2026 | containerd is an open source container runtime with an emphasis on simplicity, robustness and portability. A bug was found in containerd where container root directories and some plugins had insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory contents and execute… | |
| Analizada | Alta (7.8) | 2.9% | ⚠ Explotación activa | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+7 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.8) | 11% | ⚠ Explotación activa💥 Exploit | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+7 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+6 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | |
| Analizada | Alta (7.8) | 2.7% | ⚠ Explotación activa | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+6 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| Modificada | Media (6.3) | 1.6% | — | Linuxfoundation ContainerdFedoraproject Fedora | 19/7/2021 | 17/6/2026 | containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expected owner… | |
| Modificada | Baja (2.3) | 0.26% | — | IBM APP Connect Enterprise Certified Container | 7/7/2021 | 17/6/2026 | IBM App Connect Enterprise Certified Container 1.0, 1.1, 1.2, and 1.3 could allow a privileged user to obtain sensitive information from internal log files. IBM X-Force ID: 202212. | |
| Modificada | Alta (7.1) | 0.70% | — | Redhat Noobaa-operatorRedhat Openshift Container Platform | 2/6/2021 | 17/6/2026 | A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in the application response, resulting in arbitrary JavaScript being… |