Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3020▼ 63 respecto a la semana anterior
Críticas / altas1413▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
55 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.1) | 0.19% | — | Docker BuildxAIMoby BuildkitAIOpentelemetry Open TelemetryAI | 17/3/2025 | 17/6/2026 | Buildx is a Docker CLI plugin that extends build capabilities using BuildKit. Cache backends support credentials by setting secrets directly as attribute values in cache-to/cache-from configuration. When supplied as user input, these secure values may be inadvertently captured in OpenTelemetry traces as part of the… | |
| Analizada | Alta (8.1) | 0.64% | — | Mobyproject Moby | 29/11/2024 | 17/6/2026 | moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes. | |
| Analizada | Media (6.5) | 0.63% | — | Mobyproject Moby | 29/11/2024 | 17/6/2026 | moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion. | |
| Analizada | Media (6.5) | 0.82% | — | Mobyproject Moby | 29/11/2024 | 17/6/2026 | moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go. | |
| Analizada | Media (6.5) | 0.35% | — | Mobyproject Moby | 18/4/2024 | 17/6/2026 | Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. In 26.0.0, IPv6 is not disabled on network interfaces, including those belonging to networks where `--ipv6=false`. An container with an `ipvlan` or `macvlan`… | |
| Analizada | Alta (7.5) | 0.75% | — | Mobyproject Moby | 20/3/2024 | 17/6/2026 | Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. Moby's networking implementation allows for many networks, each with their own IP address range and gateway, to be defined. This feature is frequently referred… | |
| Modificada | Alta (7.8) | 0.26% | — | Mobyproject Moby | 1/2/2024 | 17/6/2026 | Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone to cache poisoning if the image is built FROM scratch. Also, changes to some instructions (most important being HEALTHCHECK and ONBUILD) would not cause a cache miss. An attacker with the… | |
| Modificada | Crítica (9.8) | 3.4% | — | Mobyproject Buildkit | 31/1/2024 | 17/6/2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containers as build steps, BuildKit also provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a… | |
| Modificada | Crítica (9.1) | 2.5% | — | Mobyproject Buildkit | 31/1/2024 | 17/6/2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host… | |
| Modificada | Alta (7.4) | 0.91% | — | Mobyproject Buildkit | 31/1/2024 | 17/6/2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build… | |
| Modificada | Media (5.3) | 1.1% | — | Mobyproject Buildkit | 31/1/2024 | 17/6/2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. The issue has been fixed in v0.12.5. As a workaround, avoid using BuildKit… | |
| Modificada | Media (6.8) | 1.4% | — | Mobyproject Moby | 4/4/2023 | 17/6/2026 | Moby) is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as moby/moby is commonly referred to as *Docker*. Swarm Mode, which is compiled in… | |
| Modificada | Media (6.8) | 0.69% | — | Mobyproject Moby | 4/4/2023 | 17/6/2026 | Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as moby/moby is commonly referred to as *Docker*. Swarm Mode, which is compiled in and… | |
| Modificada | Alta (8.7) | 2.6% | — | Mobyproject Moby | 4/4/2023 | 17/6/2026 | Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as moby/moby, is commonly referred to as *Docker*. Swarm Mode, which is compiled in… | |
| Modificada | Media (6.5) | 1.0% | — | Mobyproject Buildkit | 6/3/2023 | 17/6/2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In affected versions when the user sends a build request that contains a Git URL that contains credentials and the build creates a provenance attestation describing that build, these credentials could… | |
| Modificada | Media (6.5) | 0.37% | — | Mobyproject Hyperkit | 20/2/2023 | 17/6/2026 | HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior, a malicious guest can trigger a vulnerability in the host by abusing the disk driver that may lead to the disclosure of the host memory into the virtualized guest. This issue is fixed in commit… | |
| Modificada | Alta (7.8) | 0.32% | — | Mobyproject Hyperkit | 17/2/2023 | 17/6/2026 | HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107, function `pci_vtsock_proc_tx` in `virtio-sock` can lead to to uninitialized memory use. In this situation, there is a check for the return value to be less or equal to `VTSOCK_MAXSEGS`, but that check is not… | |
| Modificada | Alta (7.8) | 0.25% | — | Mobyproject Hyperkit | 17/2/2023 | 17/6/2026 | HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of HyperKit, the implementation of `qnotify` at `pci_vtrnd_notify` fails to check the return value of `vq_getchain`. This leads to `struct iovec iov;` being uninitialized and used to read memory in `len =… | |
| Modificada | Media (5.5) | 0.23% | — | Mobyproject Hyperkit | 17/2/2023 | 17/6/2026 | HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of HyperKit, ` vi_pci_write` has is a call to `vc_cfgwrite` that does not check for null which when called makes the host crash. This issue may lead to a guest crashing the host causing a denial of service.… | |
| Modificada | Media (5.5) | 0.23% | — | Mobyproject Hyperkit | 17/2/2023 | 17/6/2026 | HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of HyperKit, `virtio.c` has is a call to `vc_cfgread` that does not check for null which when called makes the host crash. This issue may lead to a guest crashing the host causing a denial of service. This… | |
| Modificada | Media (6.3) | 1.0% | — | Mobyproject MobyFedoraproject Fedora | 9/9/2022 | 17/6/2026 | Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group… | |
| Modificada | Media (5.3) | 0.24% | — | Kubernetes Cri-oFedoraproject FedoraMobyproject MobyRedhat Openshift Container Platform | 18/4/2022 | 17/6/2026 | A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable… | |
| Modificada | Media (5.9) | 0.49% | — | Mobyproject MobyFedoraproject FedoraLinuxfoundation RuncDebian Linux | 24/3/2022 | 17/6/2026 | Moby is an open-source project created by Docker to enable and accelerate software containerization. A bug was found in Moby (Docker Engine) prior to version 20.10.14 where containers were incorrectly started with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling… | |
| Modificada | Media (6.3) | 2.8% | — | Mobyproject MobyFedoraproject Fedora | 4/10/2021 | 17/6/2026 | Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where the data directory (typically `/var/lib/docker`) contained subdirectories with insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory… | |
| Modificada | Media (6.3) | 0.29% | — | Mobyproject MobyFedoraproject Fedora | 4/10/2021 | 17/6/2026 | Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where attempting to copy files using `docker cp` into a specially-crafted container can result in Unix file permission changes for existing files in the host’s filesystem, widening access to… |