Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
228 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.9) | 14% | — | Docker ComposeAI | 27/10/2025 | 17/6/2026 | Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile with its local cache directory and… | |
| Aplazada | Alta (8.8) | 0.11% | — | Docker DesktopAI | 27/10/2025 | 17/6/2026 | Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for required DLLs in the user's Downloads folder before checking system directories, allowing local privilege escalation through malicious DLL placement.This issue affects Docker Desktop: through 4.48.0. | |
| Analizada | Crítica (9.3) | 0.19% | — | IBM Security Verify AccessIBM Security Verify Access DockerIBM Verify Identity AccessIBM Verify Identity Access Docker | 6/10/2025 | 17/6/2026 | IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to escalate their privileges to root due to execution with more privileges than required. | |
| Analizada | Alta (8.5) | 0.17% | — | IBM Security Verify AccessIBM Security Verify Access DockerIBM Verify Identity AccessIBM Verify Identity Access Docker | 6/10/2025 | 17/6/2026 | IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to execute malicious scripts from outside of its control sphere. | |
| Analizada | Alta (7.3) | 0.33% | — | IBM Security Verify AccessIBM Security Verify Access DockerIBM Verify Identity AccessIBM Verify Identity Access Docker | 6/10/2025 | 17/6/2026 | IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow an unauthenticated user to execute arbitrary commands with lower user privileges on the system due to improper validation of user supplied input. | |
| Aplazada | Alta (8.7) | 0.14% | — | Docker DesktopAI | 26/9/2025 | 17/6/2026 | In a hardened Docker environment, with Enhanced Container Isolation ( ECI https://docs.docker.com/enterprise/security/hardened-desktop/enhanced-container-isolation/ ) enabled, an administrator can utilize the command restrictions feature… | |
| Aplazada | Media (6.1) | 0.32% | — | Asian Arts Talents Foundation Aatf WebsiteAIDockerAI | 2/9/2025 | 17/6/2026 | Asian Arts Talents Foundation (AATF) Website v5.1.x and Docker version 2024.12.8.1 are vulnerable to Cross Site Scripting (XSS). The vulnerability exists in the /ip.php endpoint, which processes and displays the X-Forwarded-For HTTP header without proper sanitization or output encoding. This allows an attacker to… | |
| Aplazada | Alta (8.7) | 0.40% | — | Airlink DaemonAIDockerAI | 25/8/2025 | 17/6/2026 | Airlink's Daemon interfaces with Docker and the Panel to provide secure access for controlling instances via the Panel. In version 1.0.0, an attacker with access to the affected container can create symbolic links inside the mounted directory (/app/data). Because the container bind-mounts an arbitrary host path, these… | |
| Aplazada | Crítica (9.3) | 1.9% | — | Docker DesktopAI | 20/8/2025 | 17/6/2026 | A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine API via the configured Docker subnet, at 192.168.65.7:2375 by default. This vulnerability occurs with or without Enhanced Container Isolation (ECI) enabled, and with or without the "Expose daemon on… | |
| Analizada | Crítica (9.8) | 2.8% | — | Linuxserver Docker-heimdall | 30/7/2025 | 17/6/2026 | LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks. This allows the loading of external… | |
| Aplazada | Crítica (9.3) | 1.1% | — | Mesosphere DC OSAIMesosphere MarathonAIDockerAI | 23/7/2025 | 17/6/2026 | The Marathon UI in DC/OS < 1.9.0 allows unauthenticated users to deploy arbitrary Docker containers. Due to improper restriction of volume mount configurations, attackers can deploy a container that mounts the host's root filesystem (/) with read/write privileges. When using a malicious Docker image, the attacker can… | |
| Aplazada | Media (5.2) | 0.15% | — | Docker DesktopAI | 3/7/2025 | 17/6/2026 | System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such as api keys, passwords, etc. A malicious actor with read access to these logs could obtain secrets and further use them to gain… | |
| Analizada | Media (5.3) | 0.34% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 11/6/2025 | 17/6/2026 | IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames due to an observable response discrepancy of disabled accounts. | |
| Aplazada | Media (4.3) | 0.15% | — | Docker DesktopAI | 29/4/2025 | 17/6/2026 | Registry Access Management (RAM) is a security feature allowing administrators to restrict access for their developers to only allowed registries. When a MacOS configuration profile is used to enforce organization sign-in, the RAM policies are not being applied, which would allow Docker Desktop users to pull down… | |
| Aplazada | Media (5.2) | 0.17% | — | Docker DesktopAI | 29/4/2025 | 17/6/2026 | Recording of environment variables, configured for running containers, in Docker Desktop application logs could lead to unintentional disclosure of sensitive information such as api keys, passwords, etc. A malicious actor with read access to these logs could obtain sensitive credentials information and further use it… | |
| Analizada | Alta (7.3) | 0.25% | — | Docker Desktop | 28/4/2025 | 17/6/2026 | A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-privileged attacker to escalate privileges to SYSTEM. During an update, Docker Desktop attempts to delete files and subdirectories under the path C:\ProgramData\Docker\config with high privileges.… | |
| Aplazada | Media (5.9) | 0.17% | — | Docker LibcontainerAI | 21/3/2025 | 17/6/2026 | libcontainer is a library for container control. Prior to libcontainer 0.5.3, while creating a tenant container, the tenant builder accepts a list of capabilities to be added in the spec of tenant container. The logic here adds the given capabilities to all capabilities of main container if present in spec, otherwise… | |
| Modificada | Media (4.3) | 0.48% | — | Mintplexlabs Anythingllm Docker | 20/3/2025 | 17/6/2026 | A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profile pictures by changing the 'id' parameter in the user cookie. This issue is present in versions prior to 1.3.1. | |
| Aplazada | Media (4.1) | 0.19% | — | Docker BuildxAIMoby BuildkitAIOpentelemetry Open TelemetryAI | 17/3/2025 | 17/6/2026 | Buildx is a Docker CLI plugin that extends build capabilities using BuildKit. Cache backends support credentials by setting secrets directly as attribute values in cache-to/cache-from configuration. When supplied as user input, these secure values may be inadvertently captured in OpenTelemetry traces as part of the… | |
| Aplazada | Media (5.2) | 0.17% | — | Docker DesktopAI | 6/3/2025 | 17/6/2026 | A vulnerability exists in Docker Desktop prior to version 4.39.0 that could lead to the unintentional disclosure of sensitive information via application logs. In affected versions, proxy configuration data—potentially including sensitive details—was written to log files in clear text whenever an HTTP GET request was… | |
| Aplazada | Media (6.8) | 0.23% | — | Docker-proxyAI | 13/2/2025 | 17/6/2026 | An issue in Docker-proxy v18.09.0 allows attackers to cause a denial of service. | |
| Analizada | Media (6.7) | 0.14% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 4/2/2025 | 17/6/2026 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment. | |
| Analizada | Alta (7.5) | 0.25% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 4/2/2025 | 17/6/2026 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. | |
| Analizada | Media (6.1) | 0.31% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 4/2/2025 | 17/6/2026 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted… | |
| Analizada | Media (5.3) | 0.37% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 4/2/2025 | 17/6/2026 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system. |