Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.35% | — | Alpinelinux Aports | 5/7/2021 | 17/6/2026 | In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used. | |
| Modificada | Alta (7.5) | 1.6% | — | Alpinelinux Apk-tools | 21/4/2021 | 17/6/2026 | In Alpine Linux apk-tools before 2.12.5, the tarball parser allows a buffer overflow and crash. | |
| Modificada | Crítica (9.8) | 2.2% | — | Kong Alpine Docker Image | 17/12/2020 | 17/6/2026 | The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.9% | — | Ghost Alpine Docker Image | 17/12/2020 | 17/6/2026 | The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.3% | — | Spiped Alpine Docker Image | 8/12/2020 | 17/6/2026 | The official spiped docker images before 1.5-alpine contain a blank password for a root user. Systems using the spiped docker container deployed by affected versions of the docker image may allow an remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.9% | — | Elixir Alpine Docker Image | 8/12/2020 | 17/6/2026 | The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user. Systems using the elixir Linux Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.3% | — | Matomo Piwik Fpm-alpine Docker Image | 8/12/2020 | 17/6/2026 | The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access. | |
| Modificada | Alta (7.5) | 1.8% | — | Alpine Project AlpineFedoraproject FedoraDebian Linux | 19/6/2020 | 17/6/2026 | Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do. | |
| Modificada | Media (6.5) | 0.87% | — | Thealpinepress Alpine-photo-tile-for-instagram | 26/9/2019 | 17/6/2026 | The alpine-photo-tile-for-instagram plugin before 1.2.7.6 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=alpine-photo-tile-for-instagram-settings tab parameter. | |
| Modificada | Media (6.5) | 1.3% | — | Alpinelinux Abuild | 18/6/2019 | 17/6/2026 | Alpine Linux abuild through 3.4.0 allows an unprivileged member of the abuild group to add an untrusted package via a --keys-dir option that causes acceptance of an untrusted signing key. | |
| Modificada | Crítica (9.8) | 6.3% | — | Gliderlabs Docker-alpineOpensuse LeapF5 Big-ip Controller | 8/5/2019 | 17/6/2026 | Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize… | |
| Modificada | Alta (8.8) | 3.5% | — | Alpinelinux Alpine Linux | 20/12/2018 | 17/6/2026 | Alpine Linux version Versions prior to 2.6.10, 2.7.6, and 2.10.1 contains a Other/Unknown vulnerability in apk-tools (Alpine Linux' package manager) that can result in Remote Code Execution. This attack appear to be exploitable via A specially crafted APK-file can cause apk to write arbitrary data to an… | |
| Modificada | Alta (7.8) | 3.2% | — | Alpinelinux Alpine Linux | 17/7/2017 | 17/6/2026 | A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achieve code execution, by crafting a malicious APKINDEX.tar.gz file with a bad pax header block. | |
| Modificada | Alta (7.8) | 3.2% | — | Alpinelinux Alpine Linux | 17/7/2017 | 17/6/2026 | A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achieve code execution by crafting a malicious APKINDEX.tar.gz file. | |
| Modificada | Alta (10) | 6.4% | — | University OF Washington AlpineUniversity OF Washington Imap Toolkit | 10/11/2008 | 16/6/2026 | Multiple stack-based buffer overflows in (1) University of Washington IMAP Toolkit 2002 through 2007c, (2) University of Washington Alpine 2.00 and earlier, and (3) Panda IMAP allow (a) local users to gain privileges by specifying a long folder extension argument on the command line to the tmail or dmail program; and… |