Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.19% | — | IBM APP Connect Enterprise Certified Containers OperandsIBM APP Connect Operator | 3/3/2026 | 17/6/2026 | IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.20, and IBM App Connect Enterprise Certified Containers Operands versions CD 12.0.11.2‑r1 through 12.0.12.5‑r1 and 13.0.1.0‑r1 through 13.0.6.1‑r1, and LTS versions 12.0.12‑r1 through 12.0.12‑r20,… | |
| Modificada | Alta (8.8) | 0.22% | — | Katacontainers Kata Containers | 19/2/2026 | 15/7/2026 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.27.0, an issue in Kata with Cloud Hypervisor allows a user of the container to modify the file system used by the Guest micro VM ultimately… | |
| Analizada | Media (6.5) | 1.0% | — | Microsoft Confidential Sidecar Containers | 10/2/2026 | 17/6/2026 | Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.50% | — | Katacontainers Kata Containers | 29/1/2026 | 17/6/2026 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.26.0, when a container image is malformed or contains no layers, containerd falls back to bind-mounting an empty snapshotter directory for the… | |
| Analizada | Alta (8.7) | 0.79% | — | Linuxcontainers Incus | 22/1/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host… | |
| Analizada | Alta (8.7) | 0.49% | — | Linuxcontainers Incus | 22/1/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch a container with a custom YAML configuration (e.g a member of the ‘incus’ group) can create an environment variable containing newlines, which can be used to add additional configuration items in… | |
| Analizada | Crítica (9.8) | 0.49% | — | Microsoft Dynamics Omnichannel SDK Storage Containers | 20/11/2025 | 17/6/2026 | Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.6) | 0.17% | — | Linuxcontainers Incus | 10/11/2025 | 17/6/2026 | Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment where an unprivileged user may have root access to a container with an attached custom storage volume that has the `security.shifted` property set to `true` as well as access… | |
| Analizada | Media (5.3) | 0.23% | — | IBM Cognos Analytics Certified Containers | 10/11/2025 | 17/6/2026 | IBM Cognos Analytics Certified Containers 12.1.0 could disclose package parameter information due to the presence of hidden pages. | |
| Aplazada | Alta (8.7) | 0.35% | — | Confidential Containers TrusteeAI | 9/10/2025 | 17/6/2026 | Confidential Containers's Trustee project contains tools and components for attesting confidential guests and providing secrets to them. In versions prior to 0.15.0, the attestation-policy endpoint didn't check if the kbs-client submitting the request was actually authenticated (had the right key). This allowed any… | |
| Aplazada | Media (6.9) | 0.33% | — | Katacontainers Kata ContainersAI | 23/9/2025 | 17/6/2026 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In Kata Containers versions from 3.20.0 and before, a malicious host can circumvent initdata verification. On TDX systems running confidential guests, a malicious host can… | |
| Analizada | Media (5.5) | 0.11% | — | IBM APP Connect Enterprise Certified Containers OperandsIBM APP Connect Operator | 1/9/2025 | 17/6/2026 | IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potentially sensitive information in log files during installation that could be read by a local user on the container. | |
| Aplazada | Alta (8.1) | 0.23% | — | Linuxcontainers IncusAI | 25/6/2025 | 17/6/2026 | Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus versions 6.12 and 6.13generates nftables rules that partially bypass security options `security.mac_filtering`, `security.ipv4_filtering` and `security.ipv6_filtering`. This can lead to ARP spoofing on… | |
| Aplazada | Baja (3.4) | 0.25% | — | Linuxcontainers IncusAI | 25/6/2025 | 17/6/2026 | Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus version 6.12 and 6.13 generates nftables rules for local services (DHCP, DNS...) that partially bypass security options `security.mac_filtering`, `security.ipv4_filtering` and `security.ipv6_filtering`.… | |
| Analizada | Media (5.5) | 0.13% | — | IBM APP Connect Enterprise Certified Containers OperandsIBM APP Connect Operator | 9/5/2025 | 17/6/2026 | IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, 12.8, 12.9, and 12.10 DesignerAuthoring instances store their flows in a database that is protected by weaker than expected cryptographic… | |
| Analizada | Media (6.5) | 0.48% | — | IBM APP Connect Enterprise Certified Containers OperandsIBM APP Connect Operator | 12/3/2025 | 17/6/2026 | IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, and 12.8 could allow an authenticated user to cause a denial of service in the App Connect flow due to improper validation of… | |
| Aplazada | Alta (8.6) | 0.36% | — | PodmanAIContainers BuildahAI | 22/1/2025 | 31/8/2026 | A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host. | |
| Analizada | Media (5.9) | 0.07% | — | Google Migrate TO Containers | 16/10/2024 | 17/6/2026 | There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windows installs. A local "m2cuser" was greated with administrator privileges. This posed a security risk if the "analyze" or "generate" commands were interrupted or skipping the action to delete the… | |
| Modificada | Alta (8.2) | 1.0% | — | Containers CommonRedhat Openshift Container PlatformRedhat Enterprise Linux | 1/10/2024 | 11/8/2026 | A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a… | |
| Aplazada | Alta (7.6) | 0.30% | — | Aliyuncontainerservice PouchAI | 23/9/2024 | 17/6/2026 | A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to escalate privileges and write arbitrary files. | |
| Modificada | Alta (7.5) | 0.77% | — | Containers Aardvark-dns | 4/9/2024 | 30/6/2026 | A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open indefinitely, causing the server to become unresponsive and resulting in other DNS queries timing out. This issue… | |
| Aplazada | Alta (8.3) | 1.3% | — | Containers ImageAI | 14/5/2024 | 19/9/2026 | A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks. | |
| Aplazada | Alta (7.5) | 0.79% | — | Redhat Openshift ContainersAI | 25/4/2024 | 17/6/2026 | An incomplete fix was shipped for the Rapid Reset (CVE-2023-44487/CVE-2023-39325) vulnerability for an OpenShift Containers. | |
| Analizada | Crítica (9) | 18% | — | Microsoft Azure Kubernetes Service Confidential Containers | 9/4/2024 | 17/6/2026 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |