Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
228 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.23% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 3/2/2024 | 17/6/2026 | IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a local user to escalate their privileges due to an improper security configuration. IBM X-Force ID: 254767. | |
| Modificada | Crítica (9) | 0.99% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 3/2/2024 | 17/6/2026 | IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a remote attacker to gain access to the underlying system using man in the middle techniques. IBM X-Force ID: 254765. | |
| Modificada | Alta (7.5) | 1.0% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 3/2/2024 | 17/6/2026 | IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 254651. | |
| Modificada | Media (6.1) | 0.92% | — | Plone Docker Official Image | 25/1/2024 | 9/7/2026 | An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of input by the HOST headers. | |
| Modificada | Media (5.5) | 0.15% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 11/1/2024 | 17/6/2026 | IBM Security Access Manager Appliance (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 260584. | |
| Modificada | Alta (7.8) | 0.25% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 11/1/2024 | 17/6/2026 | IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254658. | |
| Modificada | Media (5.5) | 0.21% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 11/1/2024 | 17/6/2026 | IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254653. | |
| Modificada | Media (4.3) | 0.64% | — | Jupyter Dockerspawner | 8/12/2023 | 17/6/2026 | dockerspawner is a tool to spawn JupyterHub single user servers in Docker containers. Users of JupyterHub deployments running DockerSpawner starting with 0.11.0 without specifying `DockerSpawner.allowed_images` configuration allow users to launch _any_ pullable docker image, instead of restricting to only the single… | |
| Modificada | Media (6.5) | 0.90% | — | Docker Machine | 7/11/2023 | 17/6/2026 | Docker Machine through 0.16.2 allows an attacker, who has control of a worker node, to provide crafted version data, which might potentially trick an administrator into performing an unsafe action (via escape sequence injection), or might have a data size that causes a denial of service to a bastion node. NOTE: This… | |
| Modificada | Media (6.5) | 0.79% | — | Docker Desktop | 25/9/2023 | 17/6/2026 | Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL. This issue affects Docker Desktop: before 4.23.0. | |
| Modificada | Alta (8.8) | 0.33% | — | Docker Desktop | 25/9/2023 | 17/6/2026 | Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via the debug shell which remains accessible for a short time window after launching Docker Desktop. The affected functionality is available for Docker Business customers only and assumes an environment… | |
| Modificada | Alta (7.8) | 0.39% | — | Docker Desktop | 25/9/2023 | 17/6/2026 | In Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in local privilege escalation (LPE).This issue affects Docker Desktop: before 4.12.0. | |
| Modificada | Alta (7.8) | 0.27% | — | Docker Desktop | 25/9/2023 | 17/6/2026 | Docker Desktop 4.11.x allows --no-windows-containers flag bypass via IPC response spoofing which may lead to Local Privilege Escalation (LPE).This issue affects Docker Desktop: 4.11.X. | |
| Modificada | Crítica (9.8) | 0.87% | — | Docker Desktop | 25/9/2023 | 17/6/2026 | Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route. This issue affects Docker Desktop: before 4.12.0. | |
| Modificada | Crítica (9.8) | 0.87% | — | Docker Desktop | 25/9/2023 | 17/6/2026 | Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0. | |
| Modificada | Media (6.6) | 0.63% | — | Python WiremockWiremock StudioWiremockWiremock Docker | 6/9/2023 | 17/6/2026 | WireMock is a tool for mocking HTTP services. The proxy mode of WireMock, can be protected by the network restrictions configuration, as documented in Preventing proxying to and recording from specific target addresses. These restrictions can be configured using the domain names, and in such a case the configuration… | |
| Modificada | Media (5.4) | 0.59% | — | Jenkins Docker Swarm | 16/8/2023 | 17/6/2026 | Jenkins Docker Swarm Plugin 1.11 and earlier does not escape values returned from Docker before inserting them into the Docker Swarm Dashboard view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control responses from Docker. | |
| Modificada | Crítica (9.8) | 0.95% | — | Play With Docker Project Play With Docker | 29/6/2023 | 17/6/2026 | Play With Docker < 0.0.2 has an insecure CAP_SYS_ADMIN privileged mode causing the docker container to escape. | |
| Modificada | Media (6.3) | 0.29% | — | Docker Desktop | 27/4/2023 | 17/6/2026 | Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerBackendV2 API by controlling the data-root field inside the DaemonJSON field in the WindowsContainerStartRequest class. This allows exploiting a symlink vulnerability in… | |
| Modificada | Alta (7.8) | 0.30% | — | Docker Desktop | 27/4/2023 | 17/6/2026 | Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 windowscontainers/start API by controlling the pidfile field inside the DaemonJSON field in the WindowsContainerStartRequest class. This can indirectly lead to privilege escalation. | |
| Modificada | Alta (7.1) | 0.34% | — | Docker Desktop | 27/4/2023 | 17/6/2026 | Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/create dockerBackendV2 API by controlling the DataFolder parameter for DockerDesktop.vhdx, a similar issue to CVE-2022-31647. | |
| Modificada | Alta (7.1) | 0.33% | — | Docker Desktop | 27/4/2023 | 17/6/2026 | Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 API via a symlink in the DataFolder parameter, a different vulnerability than CVE-2022-26659. | |
| Modificada | Alta (7.5) | 0.55% | — | Docker Desktop | 6/4/2023 | 17/6/2026 | In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failed. A targeted network sniffing attack can lead to a disclosure of sensitive information. Only users who have Access Experimental Features enabled and have logged in to a… | |
| Modificada | Media (6.5) | 0.70% | — | Play-with-docker Play With Docker | 16/3/2023 | 17/6/2026 | Play With Docker is a browser-based Docker playground. Versions 0.0.2 and prior are vulnerable to domain hijacking. Because CORS configuration was not correct, an attacker could use `play-with-docker.com` as an example and set the origin header in an http request as `evil-play-with-docker.com`. The domain would echo… | |
| Modificada | Alta (7.1) | 0.22% | — | Docker Desktop | 13/3/2023 | 17/6/2026 | Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions by setting the Docker host to docker.raw.sock, or npipe:////.pipe/docker_engine_linux on Windows, via the -H (--host) CLI flag or the DOCKER_HOST environment variable and launch containers without the… |