Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

698 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.3%—Crun Project CrunFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux4/4/202217/6/2026
A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable…
ModificadaAlta (7.5)1.4%—Podman Project PodmanRedhat Developer ToolsRedhat Openshift Container PlatformRedhat Enterprise Linux+104/4/202217/6/2026
A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with…
ModificadaBaja (3.7)0.77%—Redhat Openshift Container PlatformRedhat Openshift Machine-config-operator1/4/202217/6/2026
It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accessed externally from clusters without authentication. The MCS endpoint (port 22623) provides ignition configuration used for bootstrapping Nodes and can include some sensitive data, e.g. registry pull…
ModificadaMedia (6.5)0.98%—IBM APP Connect Enterprise Certified Container1/4/202217/6/2026
IBM App Connect Enterprise Certified Container Dashboard UI (IBM App Connect Enterprise Certified Container 1.5, 2.0, 2.1, 3.0, and 3.1) may be vulnerable to denial of service due to excessive rate limiting.
ModificadaAlta (7)0.43%—Linux KernelRedhat 3scale API ManagementRedhat Build OF QuarkusRedhat Codeready Linux Builder EUS+283/3/202217/6/2026
.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.
ModificadaAlta (7.5)27%💥 PoCLinuxfoundation ContainerdDebian LinuxFedoraproject Fedora3/3/202217/6/2026
containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration could gain access to read-only copies of…
ModificadaMedia (6.3)0.49%—Redhat LibvirtRedhat Openshift Container PlatformRedhat Enterprise LinuxNetapp Ontap Select Deploy Administration Utility2/3/202217/6/2026
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.
ModificadaAlta (7.5)17%—HaproxyRedhat Openshift Container PlatformRedhat Software CollectionsRedhat Enterprise Linux+12/3/202217/6/2026
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.
AnalizadaAlta (7.8)24%⚠ Explotación activa💥 ExploitPolkit Project PolkitDebian LinuxCanonical Ubuntu LinuxRedhat Virtualization+216/2/202217/6/2026
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to…
ModificadaMedia (4.2)0.77%—Kubernetes Cri-oRedhat Openshift Container Platform9/2/202217/6/2026
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.
ModificadaAlta (8.8)1.00%—Mirantis Container Cloud Lens Extension4/2/202217/6/2026
Lack of validation of URLs causes Mirantis Container Cloud Lens Extension before v3.1.1 to open external programs other than the default browser to perform sign on to a new cluster. An attacker could host a webserver which serves a malicious Mirantis Container Cloud configuration file and induce the victim to add a…
ModificadaAlta (7.5)0.90%—Mirantis Container Runtime10/1/202217/6/2026
When running with FIPS mode enabled, Mirantis Container Runtime 20.10.8 leaks memory during TLS Handshakes which could be abused to cause a denial of service.
ModificadaCrítica (9.1)1.7%—Linuxfoundation ContainerdFedoraproject Fedora5/1/202217/6/2026
containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod scheduled to the node may bind mount, via hostPath volume, any privileged,…
ModificadaAlta (7.5)81%💥 PoCApache Log4jFedoraproject FedoraRedhat Codeready StudioRedhat Integration Camel K+4214/12/202117/6/2026
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in…
ModificadaCrítica (9.1)2.8%—Lapack Project LapackOpenblas Project OpenblasJulialang JuliaRedhat Ceph Storage+48/12/202117/6/2026
An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory.
ModificadaMedia (5)2.2%—Linuxfoundation Open Container Initiative Distribution SpecificationLinuxfoundation Open Container Initiative Image Format SpecificationFedoraproject Fedora17/11/202117/6/2026
The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specification version 1.0.0 and prior, the Content-Type header alone was used to determine the type of document during push and pull operations. Documents that contain both…
ModificadaMedia (5.5)0.22%—IBM APP Connect Enterprise Certified Container8/10/202117/6/2026
IBM App Connect Enterprise Certified Container 1.0, 1.1, 1.2, 1.3, 1.4 and 1.5 could disclose sensitive information to a local user when it is configured to use an IBM Cloud API key to connect to cloud-based connectors. IBM X-Force ID: 207630.
ModificadaAlta (7.8)0.52%—Linuxfoundation ContainerdFedoraproject FedoraDebian Linux4/10/202117/6/2026
containerd is an open source container runtime with an emphasis on simplicity, robustness and portability. A bug was found in containerd where container root directories and some plugins had insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory contents and execute…
AnalizadaAlta (7.8)2.9%⚠ Explotación activaMicrosoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+715/9/202110/8/2026
Open Management Infrastructure Elevation of Privilege Vulnerability
AnalizadaAlta (7.8)11%⚠ Explotación activa💥 ExploitMicrosoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+715/9/202110/8/2026
Open Management Infrastructure Elevation of Privilege Vulnerability
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitMicrosoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+615/9/202110/8/2026
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
AnalizadaAlta (7.8)2.7%⚠ Explotación activaMicrosoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+615/9/202110/8/2026
Open Management Infrastructure Elevation of Privilege Vulnerability
ModificadaMedia (6.3)1.6%—Linuxfoundation ContainerdFedoraproject Fedora19/7/202117/6/2026
containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expected owner…
ModificadaBaja (2.3)0.26%—IBM APP Connect Enterprise Certified Container7/7/202117/6/2026
IBM App Connect Enterprise Certified Container 1.0, 1.1, 1.2, and 1.3 could allow a privileged user to obtain sensitive information from internal log files. IBM X-Force ID: 202212.
ModificadaAlta (7.1)0.70%—Redhat Noobaa-operatorRedhat Openshift Container Platform2/6/202117/6/2026
A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in the application response, resulting in arbitrary JavaScript being…