Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
228 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.23% | — | Compose-goAIDocker ComposeAI | 23/1/2025 | 17/6/2026 | The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to cause the compose-go to consume excessive amount of Memory and CPU cycles while parsing YAML, such as used by Docker Compose from versions v2.27.0 to v2.29.7 included | |
| Analizada | Crítica (9.8) | 0.27% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 20/1/2025 | 17/6/2026 | IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow could an unverified user to change the password of an expired user without prior knowledge of that password. | |
| Aplazada | Media (6.5) | 0.47% | — | Processmaker Pm4core-dockerAI | 15/1/2025 | 17/6/2026 | An arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitrary code via uploading a crafted PHP or HTML file. | |
| Aplazada | Media (4.8) | 0.35% | — | Processmaker Pm4core-dockerAI | 15/1/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter. | |
| Aplazada | Alta (7.6) | 0.55% | — | OpenshiftAIDockerAI | 31/12/2024 | 21/9/2026 | A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credentials necessary for pulling images from private repositories. The mount is not… | |
| Modificada | Alta (7.8) | 0.23% | — | IBM Security Verify Access Docker | 19/12/2024 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges. | |
| Aplazada | Alta (8.8) | 0.21% | — | DockerAI | 19/11/2024 | 17/6/2026 | A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escalation to the administrative level due to the usage of component vendor Docker images running with root permissions. Exploiting this misconfiguration leads to the fact… | |
| Aplazada | Alta (8.9) | 0.47% | — | Docker DesktopAI | 16/10/2024 | 17/6/2026 | Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view. | |
| Aplazada | Media (4.7) | 0.29% | — | DockerfileAI | 1/10/2024 | 17/6/2026 | A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, allowing users to pass arbitrary parameters to the mount instruction. This issue can be exploited to mount sensitive directories from the host into a… | |
| Analizada | Alta (8.9) | 1.2% | — | Docker Desktop | 12/9/2024 | 17/6/2026 | A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2. | |
| Analizada | Crítica (9) | 1.3% | — | Docker Desktop | 12/9/2024 | 17/6/2026 | A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2. | |
| Modificada | Alta (8.2) | 1.8% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 29/8/2024 | 17/6/2026 | IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect… | |
| Aplazada | Crítica (9.9) | 16% | — | Docker-ceAIDocker EEAIDocker EngineAIMirantis Container RuntimeAI | 24/7/2024 | 17/6/2026 | Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detected in certain versions of Docker Engine, which could allow an attacker to bypass authorization plugins (AuthZ) under specific circumstances. The base likelihood of this being exploited is low. Using… | |
| Modificada | Alta (7.3) | 0.56% | — | Docker Desktop | 9/7/2024 | 17/6/2026 | In Docker Desktop before v4.29.0, an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the host by passing extensions and dashboard related IPC messages. Docker Desktop v4.29.0 https://docs.docker.com/desktop/release-notes/#4290 fixes the issue on MacOS, Linux… | |
| Modificada | Media (5.5) | 0.37% | — | Docker Desktop | 9/7/2024 | 17/6/2026 | In Docker Desktop on Windows before v4.31.0 allows a user in the docker-users group to cause a Windows Denial-of-Service through the exec-path Docker daemon config option in Windows containers mode. | |
| Analizada | Crítica (9.6) | 0.97% | — | Mintplexlabs Anythingllm DesktopMintplexlabs Anythingllm Docker | 6/6/2024 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability exists in mintplex-labs/anything-llm, affecting both the desktop application version 1.2.0 and the latest version of the web application. The vulnerability arises from the application's feature to fetch and embed content from websites into workspaces, which can be exploited… | |
| Modificada | Alta (7.8) | 0.23% | — | IBM Security Verify Access Docker | 31/5/2024 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges. IBM X-Force ID: 292418. | |
| Modificada | Alta (7.8) | 0.13% | — | IBM Security Verify Access Docker | 31/5/2024 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to improper certificate validation. IBM X-Force ID: 292416. | |
| Analizada | Alta (8.8) | 0.83% | — | Jenkins Docker-build-step | 6/3/2024 | 17/6/2026 | A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting future build step… | |
| Analizada | Media (6.1) | 0.41% | — | Jenkins Docker-build-step | 6/3/2024 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting future build step executions. | |
| Modificada | Crítica (9.8) | 1.3% | — | Plone Docker Official Image | 5/2/2024 | 9/7/2026 | An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm). | |
| Modificada | Alta (7.3) | 0.71% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 3/2/2024 | 17/6/2026 | IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a remote user to log into the server due to a user account with an empty password. IBM X-Force ID: 266154. | |
| Modificada | Media (5.5) | 0.15% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 3/2/2024 | 17/6/2026 | IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a user to download files from an incorrect repository due to improper file validation. IBM X-Force ID: 254972. | |
| Modificada | Alta (7.1) | 0.96% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 3/2/2024 | 17/6/2026 | IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose… | |
| Modificada | Alta (7.5) | 0.89% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 3/2/2024 | 17/6/2026 | IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to a denial of service attacks on the DSC server. IBM X-Force ID: 254776. |