Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
228 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.27% | — | Docker Desktop | 13/3/2023 | 17/6/2026 | Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted malicious docker-desktop:// URL. | |
| Modificada | Media (6.5) | 0.42% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 17/2/2023 | 17/6/2026 | IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, 10.0.3.0, and10.0.4.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or… | |
| Modificada | Media (6.3) | 3.1% | — | Snyk CLISnyk Cocoapods CLISnyk Docker CLISnyk Gradle CLI+4 | 30/11/2022 | 17/6/2026 | The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.5; the package @snyk/snyk-cocoapods-plugin before 2.5.3; the package snyk-sbt-plugin before 2.16.2; the package snyk-python-plugin before 1.24.2; the package snyk-docker-plugin before 5.6.5; the… | |
| Modificada | Alta (7.5) | 0.60% | — | Jenkins Cloudbees Docker Hub/registry Notification | 15/11/2022 | 17/6/2026 | A missing permission check in Jenkins CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository. | |
| Modificada | Alta (8.8) | 1.9% | — | Apache-airflow-providers-docker | 16/8/2022 | 17/6/2026 | Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host. | |
| Modificada | Crítica (9.8) | 4.4% | — | Docker-tester Project Docker-tester | 2/6/2022 | 17/6/2026 | OS Command injection vulnerability in Mintzo Docker-Tester through 1.2.1 allows attackers to execute arbitrary commands via shell metacharacters in the 'ports' entry of a crafted docker-compose.yml file. | |
| Modificada | Alta (8.4) | 0.27% | — | Docker Desktop | 25/5/2022 | 17/6/2026 | Docker Desktop 4.3.0 has Incorrect Access Control. | |
| Modificada | Alta (7.1) | 0.43% | — | Docker Desktop | 25/3/2022 | 17/6/2026 | Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. Starting from version 4.6.0, the Docker Desktop installer, when run elevated, will write its log files to a location… | |
| Modificada | Alta (7.8) | 0.84% | — | Docker | 19/2/2022 | 17/6/2026 | Docker Desktop before 4.5.1 on Windows allows attackers to move arbitrary files. NOTE: this issue exists because of an incomplete fix for CVE-2022-23774. | |
| Modificada | Crítica (9.8) | 1.8% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 2/2/2022 | 17/6/2026 | IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to authenticate as any user on the system. IBM X-Force ID: 215353. | |
| Modificada | Media (5.3) | 0.93% | — | Docker Desktop | 1/2/2022 | 17/6/2026 | Docker Desktop before 4.4.4 on Windows allows attackers to move arbitrary files. | |
| Modificada | Alta (8.8) | 2.3% | — | Jenkins Docker Commons | 12/1/2022 | 17/6/2026 | Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability exploitable by attackers with Item/Configure permission or able to control the contents of a previously configured job's SCM repository. | |
| Modificada | Media (5.5) | 0.43% | — | Docker Desktop | 12/1/2022 | 17/6/2026 | Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. This only affects users if they are on Docker Desktop 4.3.0, 4.3.1 and the user has logged in while on 4.3.0, 4.3.1. Gaining access to this data would require having access… | |
| Modificada | Crítica (9) | 1.9% | — | Quobject Docker-cli-js | 22/11/2021 | 17/6/2026 | This affects all versions of package docker-cli-js. If the command parameter of the Docker.command method can at least be partially controlled by a user, they will be in a position to execute any arbitrary OS commands on the host system. | |
| Modificada | Alta (7.5) | 1.7% | — | Docker Command Line InterfaceFedoraproject Fedora | 4/10/2021 | 17/6/2026 | Docker CLI is the command line interface for the docker container runtime. A bug was found in the Docker CLI where running `docker login my-private-registry.example.com` with a misconfigured configuration file (typically `~/.docker/config.json`) listing a `credsStore` or `credHelpers` that could not be executed would… | |
| Modificada | Crítica (9.8) | 2.9% | — | Nagios XI Docker Wizard | 13/8/2021 | 17/6/2026 | Nagios XI Docker Wizard before version 1.1.3 is vulnerable to SSRF due to improper sanitation in table_population.php. | |
| Modificada | Alta (7.8) | 1.00% | — | Docker Desktop | 12/8/2021 | 17/6/2026 | Docker Desktop before 3.6.0 suffers from incorrect access control. If a low-privileged account is able to access the server running the Windows containers, it can lead to a full container compromise in both process isolation and Hyper-V isolation modes. This security issue leads an attacker with low privilege to read,… | |
| Modificada | Alta (7.9) | 0.29% | — | Synology Docker | 1/6/2021 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability container volume management component in Synology Docker before 18.09.0-0515 allows local users to read or write arbitrary files via unspecified vectors. | |
| Modificada | Media (5.5) | 0.35% | — | Oracle VirtualizationRedhat AnsibleRedhat Ansible TowerRedhat Cisco Nx-os Collection+4 | 26/5/2021 | 17/6/2026 | A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality.… | |
| Modificada | Crítica (9.8) | 46% | — | Docker Dashboard Project Docker Dashboard | 2/3/2021 | 17/6/2026 | rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. NOTE: this is NOT a Docker, Inc. product. | |
| Modificada | Media (6.5) | 3.3% | — | DockerDebian LinuxNetapp E-series Santricity OS Controller | 2/2/2021 | 17/6/2026 | In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the dockerd daemon. Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing. | |
| Modificada | Media (6.8) | 1.1% | — | DockerDebian LinuxNetapp E-series Santricity OS Controller | 2/2/2021 | 17/6/2026 | In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privilege escalation to real root. When using "--userns-remap", if the root user in the remapped namespace has access to the host filesystem they can modify files under… | |
| Modificada | Alta (7.8) | 0.17% | — | Docker | 15/1/2021 | 17/6/2026 | Docker Desktop Community before 2.5.0.0 on macOS mishandles certificate checking, leading to local privilege escalation. | |
| Modificada | Media (5.3) | 1.8% | — | Docker | 30/12/2020 | 17/6/2026 | util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls os.OpenFile with a potentially unsafe qemu-check temporary pathname, constructed with an empty first argument in an ioutil.TempDir call. | |
| Modificada | Crítica (9.8) | 2.2% | — | Memcached Docker Image | 17/12/2020 | 17/6/2026 | The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. System using the memcached docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. |