Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.44% | — | Linuxcontainers Incus | 6/5/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage bucket import logic allows an authenticated user with access to the storage bucket feature to cause the Incus daemon to crash. The vulnerability is present in the backup metadata handling logic,… | |
| Analizada | Media (5.3) | 0.29% | — | Linuxcontainers Incus | 5/5/2026 | 24/7/2026 | Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues an outbound HEAD request to a user-supplied URL before validating the request against project restrictions such as restricted.images.servers. The imgPostURLInfo function constructs and sends a HEAD… | |
| Analizada | Crítica (9.6) | 0.53% | — | Linuxcontainers Incus | 27/3/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a shared directory. Prior to version 6.23.0, an attacker can set a configuration key named something like… | |
| Analizada | Alta (8.8) | 0.48% | — | Linuxcontainers Incus | 27/3/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authentication token such that an invalid value will be accepted. `incus webui` runs a local web server on a random localhost port. For authentication, it provides the… | |
| Analizada | Crítica (9.9) | 0.53% | — | Linuxcontainers Incus | 26/3/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writes as root on the host server. Incus allows for pongo2 templates within instances which can be used at various times in the instance lifecycle to template files inside of… | |
| Analizada | Media (6.5) | 0.44% | — | Linuxcontainers Incus | 26/3/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incus' storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of… | |
| Analizada | Media (4.7) | 0.18% | — | Linuxcontainers Incus | 26/3/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API relies on the use of a temporary file for QEMU to write the screenshot to which is then picked up and sent to the user prior to deletion. As versions prior to 6.23.0 use predictable paths under /tmp for… | |
| Analizada | Media (5.7) | 0.20% | — | Linuxcontainers Incus | 26/3/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fingerprint when downloading from simplestreams image servers opens the door to image cache poisoning and under very narrow circumstances exposes other tenants to running attacker controlled images… | |
| Aplazada | Alta (7.6) | 0.17% | 💥 PoC | IncusosAISystemd-cryptenrollAI | 18/3/2026 | 17/6/2026 | IncusOS is an immutable OS image dedicated to running Incus. Prior to 202603142010, the default configuration of systemd-cryptenroll as used by IncusOS through mkosi allows for an attacker with physical access to the machine to access the encrypted data without requiring any interaction by the system's owner or any… | |
| Analizada | Alta (8.7) | 0.79% | — | Linuxcontainers Incus | 22/1/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host… | |
| Analizada | Alta (8.7) | 0.49% | — | Linuxcontainers Incus | 22/1/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch a container with a custom YAML configuration (e.g a member of the ‘incus’ group) can create an environment variable containing newlines, which can be used to add additional configuration items in… | |
| Analizada | Alta (8.6) | 0.17% | — | Linuxcontainers Incus | 10/11/2025 | 17/6/2026 | Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment where an unprivileged user may have root access to a container with an attached custom storage volume that has the `security.shifted` property set to `true` as well as access… | |
| Aplazada | Alta (8.1) | 0.23% | — | Linuxcontainers IncusAI | 25/6/2025 | 17/6/2026 | Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus versions 6.12 and 6.13generates nftables rules that partially bypass security options `security.mac_filtering`, `security.ipv4_filtering` and `security.ipv6_filtering`. This can lead to ARP spoofing on… | |
| Aplazada | Baja (3.4) | 0.25% | — | Linuxcontainers IncusAI | 25/6/2025 | 17/6/2026 | Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus version 6.12 and 6.13 generates nftables rules for local services (DHCP, DNS...) that partially bypass security options `security.mac_filtering`, `security.ipv4_filtering` and `security.ipv6_filtering`.… | |
| Modificada | Media (4.3) | 0.67% | — | Otrs ItsmconfigurationmanagementOtrscisincustomerfrontend | 22/3/2021 | 17/6/2026 | Agents are able to see linked Config Items without permissions, which are defined in General Catalog. This issue affects: OTRSCIsInCustomerFrontend 7.0.15 and prior versions, ITSMConfigurationManagement 7.0.24 and prior versions |