Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

101 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.3)0.70%💥 PoCLinuxcontainers LXC1/1/202317/6/2026
lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "does not refer to a network namespace path" often indicates that a file exists.…
ModificadaBaja (3.3)0.69%—Containers-image Project Containers-imageRedhat Enterprise Linux27/5/202117/6/2026
A malicious container image can consume an unbounded amount of memory when being pulled to a container runtime host, such as Red Hat Enterprise Linux using podman, or OpenShift Container Platform. An attacker can use this flaw to trick a user, with privileges to pull container images, into crashing the process…
ModificadaAlta (7.3)0.65%—Bitnami Containers3/3/202117/6/2026
In Bitnami Containers, all Laravel container versions prior to: 6.20.0-debian-10-r107 for Laravel 6, 7.30.1-debian-10-r108 for Laravel 7 and 8.5.11-debian-10-r0 for Laravel 8, the file /tmp/app/.env is generated at the time that the docker image bitnami/laravel was built, and the value of APP_KEY is fixed under…
ModificadaCrítica (9.8)1.6%—Containers Project Containers26/1/202117/6/2026
An issue was discovered in the containers crate before 0.9.11 for Rust. When a panic occurs, a util::{mutate,mutate2} double drop can be performed.
ModificadaAlta (8.8)2.0%—Katacontainers Kata Containers7/12/202017/6/2026
An issue was discovered in Kata Containers through 1.11.3 and 2.x through 2.0-rc1. The runtime will execute binaries given using annotations without any kind of validation. Someone who is granted access rights to a cluster will be able to have kata-runtime execute arbitrary binaries as root on the worker nodes.
ModificadaAlta (7.1)0.37%—Katacontainers Kata-containers17/11/202017/6/2026
An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath volume and mounting either a file or directory into a container as readonly, the file/directory is mounted as readOnly inside the container, but is still writable inside the guest. For a container…
ModificadaAlta (8.8)0.47%—Katacontainers RuntimeFedoraproject Fedora10/6/202017/6/2026
A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path, potentially allowing for code execution on the host. This issue affects: Kata Containers 1.11…
ModificadaMedia (6.3)1.1%💥 PoCKatacontainers Runtime10/6/202017/6/2026
Kata Containers doesn't restrict containers from accessing the guest's root filesystem device. Malicious containers can exploit this to gain code execution on the guest and masquerade as the kata-agent. This issue affects Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than…
ModificadaAlta (8.8)0.31%—Katacontainers Runtime19/5/202017/6/2026
Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the host. A malicious guest can overwrite the image file to gain control of all subsequent guest VMs. Since Kata Containers uses the same VM image file with all VMMs, this issue may also affect QEMU and…
ModificadaMedia (6.5)0.37%—Katacontainers Runtime19/5/202017/6/2026
An improper link resolution vulnerability affects Kata Containers versions prior to 1.11.0. Upon container teardown, a malicious guest can trick the kata-runtime into unmounting any mount point on the host and all mount points underneath it, potentiality resulting in a host DoS.
ModificadaAlta (8.1)1.5%—Linuxcontainers LXC10/2/202017/6/2026
In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.
ModificadaAlta (8.1)0.90%—Linuxcontainers LXD22/4/201917/6/2026
LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the Filepath.Walk() function. A symbolic link created in that window could cause any file on the system to have any mode of the attacker's choice.
ModificadaAlta (8.6)98%💥 ExploitDockerLinuxfoundation RuncRedhat Container Development KITRedhat Openshift+1511/2/201917/6/2026
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image,…
ModificadaBaja (3.3)0.35%—Canonical Ubuntu LinuxLinuxcontainers LXCSuse Caas PlatformSuse Openstack Cloud+210/8/201817/6/2026
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of…
ModificadaCrítica (9.8)8.6%—Vmware Vrealize AutomationVmware Vsphere Integrated Containers29/1/201817/6/2026
VMware vRealize Automation (7.3 and 7.2) and vSphere Integrated Containers (1.x before 1.3) contain a deserialization vulnerability via Xenon. Successful exploitation of this issue may allow remote attackers to execute arbitrary code on the appliance.
ModificadaCrítica (9.1)2.8%—Linuxcontainers LXC1/5/201717/6/2026
lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of the host's /proc, to access the rest of the host's filesystem via the openat() family of syscalls.
ModificadaBaja (3.3)0.34%—Linuxcontainers LXC14/3/201717/6/2026
lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name of those interfaces by leveraging lack of netns ownership check.
ModificadaAlta (8.6)1.5%—Linuxcontainers LXC9/1/201717/6/2026
An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the container.
AnalizadaAlta (7.5)96%⚠ Explotación activa💥 ExploitRubyonrails RailsOpensuse LeapOpensuseSuse Linux Enterprise Module FOR Containers+216/2/201617/6/2026
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a…
ModificadaAlta (7.2)0.46%—Linuxcontainers LXCCanonical Ubuntu Linux1/10/201517/6/2026
lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source.
ModificadaMedia (4.6)0.37%—Linuxcontainers LXC12/8/201517/6/2026
attach.c in LXC 1.1.2 and earlier uses the proc filesystem in a container, which allows local container users to escape AppArmor or SELinux confinement by mounting a proc filesystem with a crafted (1) AppArmor profile or (2) SELinux label.
ModificadaMedia (4.9)0.46%—Linuxcontainers LXC12/8/201517/6/2026
lxclock.c in LXC 1.1.2 and earlier allows local users to create arbitrary files via a symlink attack on /run/lock/lxc/*.
ModificadaBaja (2.1)0.36%—Linuxcontainers CgmanagerCanonical Ubuntu Linux7/1/201517/6/2026
cmanager 0.32 does not properly enforce nesting when modifying cgroup properties, which allows local users to set cgroup values for all cgroups via unspecified vectors.
ModificadaAlta (7.2)0.50%—Linuxcontainers LXC14/2/201417/6/2026
The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows local users to gain privileges by modifying the init file.
ModificadaMedia (6.8)0.33%—Hp-ux Containers4/11/201116/6/2026
Unspecified vulnerability in HP-UX Containers (formerly HP-UX Secure Resource Partitions (SRP)) A.03.00, A.03.00.002, and A.03.01, when running with patch PHKL_42310, allows local users to gain privileges via unknown vectors.
Orbitaley — Vulnerabilidades