Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

101 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.6)0.61%—Katacontainers Kata RuntimeAI7/8/20269/9/2026
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated configuration path annotation. The runtime accepts an arbitrary…
AnalizadaMedia (5.8)0.59%—Katacontainers Kata Containers23/7/20266/8/2026
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0 ship with a default configuration that allows pod creators to inject arbitrary command-line arguments into the virtiofsd process through the…
AplazadaAlta (8.8)0.14%—Servereye ClientAIServereye SensorhubAIServereye ClientagentcontainerserviceAI22/7/202622/7/2026
The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the directory…
AnalizadaMedia (4.3)0.39%—Linuxcontainers Incus7/5/202617/6/2026
Incus is a system container and virtual machine manager. Prior to version 7.0.0, uploads of large amount of data by authenticated users can run the Incus server out of disk space, potentially taking down the host system. The impact here is limited for anyone using storage.images_volume and storage.backups_volume as…
AnalizadaMedia (6.5)0.47%—Linuxcontainers Incus7/5/202617/6/2026
Incus is a system container and virtual machine manager. Prior to version 7.0.0, backup.GetInfo() trusts the inline backup/index.yaml config when present and only falls back to parsing the legacy backup/container/backup.yaml file if result.Config == nil. As a result, an archive can carry a valid inline config that…
AnalizadaMedia (5.3)0.39%—Linuxcontainers Incus7/5/202617/6/2026
Incus is a system container and virtual machine manager. Prior to version 7.0.0, user provided image and backup tarballs would be unpacked and YAML files parsed without any size restrictions. This was making it easy for an authenticated user to provide a crafted image or backup tarball that when parsed by Incus would…
AnalizadaMedia (6.5)0.47%—Linuxcontainers Incus7/5/202617/6/2026
Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an authenticated Incus user to cause a daemon crash through the import of a truncated storage bucket backup file. This issue has been patched in version 7.0.0.
AnalizadaAlta (7.1)0.47%—Linuxcontainers Incus6/5/202617/6/2026
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon to crash. The backup restore subsystem contains an out-of-bounds panic…
AnalizadaBaja (2.3)0.22%—Linuxcontainers Incus6/5/202617/6/2026
Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OVN database connection logic can allow connections to an attacker's OVN database. The OVN client implementations disable Go standard TLS server verification and replace it with custom peer-certificate…
AnalizadaAlta (7.1)0.44%—Linuxcontainers Incus6/5/202617/6/2026
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon to crash. The custom volume backup import subsystem contains a nil-pointer…
AnalizadaAlta (7.1)0.44%—Linuxcontainers Incus6/5/202617/6/2026
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage bucket import logic allows an authenticated user with access to the storage bucket feature to cause the Incus daemon to crash. The vulnerability is present in the backup metadata handling logic,…
AnalizadaMedia (4.3)0.14%—Linuxcontainers LXC5/5/202624/7/2026
lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_line() function that allows an unprivileged user to delete OVS-attached network interfaces belonging to other users. When lxc-user-nic delete scans its NIC database to authorize a deletion request,…
AnalizadaMedia (5.3)0.29%—Linuxcontainers Incus5/5/202624/7/2026
Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues an outbound HEAD request to a user-supplied URL before validating the request against project restrictions such as restricted.images.servers. The imgPostURLInfo function constructs and sends a HEAD…
ModificadaAlta (8.2)0.37%—Katacontainers Confidential ContainersKatacontainers Kata Containers24/4/202624/8/2026
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations inside the guest…
AnalizadaAlta (7.5)0.46%—Containers Aardvark-dns7/4/202624/7/2026
Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU. This vulnerability is fixed in 1.17.1.
AnalizadaCrítica (9.6)0.53%—Linuxcontainers Incus27/3/202617/6/2026
Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a shared directory. Prior to version 6.23.0, an attacker can set a configuration key named something like…
AnalizadaAlta (8.8)0.48%—Linuxcontainers Incus27/3/202617/6/2026
Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authentication token such that an invalid value will be accepted. `incus webui` runs a local web server on a random localhost port. For authentication, it provides the…
AnalizadaCrítica (9.9)0.53%—Linuxcontainers Incus26/3/202617/6/2026
Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writes as root on the host server. Incus allows for pongo2 templates within instances which can be used at various times in the instance lifecycle to template files inside of…
AnalizadaMedia (6.5)0.44%—Linuxcontainers Incus26/3/202617/6/2026
Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incus' storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of…
AnalizadaMedia (4.7)0.18%—Linuxcontainers Incus26/3/202617/6/2026
Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API relies on the use of a temporary file for QEMU to write the screenshot to which is then picked up and sent to the user prior to deletion. As versions prior to 6.23.0 use predictable paths under /tmp for…
AnalizadaMedia (5.7)0.20%—Linuxcontainers Incus26/3/202617/6/2026
Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fingerprint when downloading from simplestreams image servers opens the door to image cache poisoning and under very narrow circumstances exposes other tenants to running attacker controlled images…
AnalizadaMedia (4.4)0.08%—IBM Planning Analytics Advanced Certified Containers10/3/202617/6/2026
IBM Planning Analytics Advanced Certified Containers 3.1.0 through 3.1.4 could allow a local privileged user to obtain sensitive information from environment variables.
AnalizadaMedia (6.7)0.40%—Microsoft ACI Confidential Containers5/3/202617/6/2026
'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (6.5)1.0%—Microsoft ACI Confidential Containers5/3/202617/6/2026
Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
AnalizadaMedia (6.7)0.60%—Microsoft ACI Confidential Containers5/3/202617/6/2026
Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.