Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
228 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.2% | — | Rabbitmq Docker Image | 17/12/2020 | 17/6/2026 | The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using the rabbitmq docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.2% | — | Haproxy Docker Image | 17/12/2020 | 17/6/2026 | The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user. System using the haproxy docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 4.6% | 💥 PoC | Drupal Docker Images | 17/12/2020 | 17/6/2026 | The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.9% | — | Docker Adminer | 17/12/2020 | 17/6/2026 | The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user. System using the adminer docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 3.0% | — | Composer Docker Image | 17/12/2020 | 17/6/2026 | The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.2% | — | Kong Alpine Docker Image | 17/12/2020 | 17/6/2026 | The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.9% | — | Ghost Alpine Docker Image | 17/12/2020 | 17/6/2026 | The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.2% | — | Sonarsource Sonarqube Docker Image | 16/12/2020 | 17/6/2026 | The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.2% | — | Docker Docs | 15/12/2020 | 17/6/2026 | The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Docker Docs container may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.1% | — | Blackfire Docker Image | 15/12/2020 | 17/6/2026 | The Blackfire Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Blackfire container may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.6% | — | Docker Registry | 11/12/2020 | 17/6/2026 | Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deployed using affected versions of the registry container may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.2% | — | Irssi Docker Image | 8/12/2020 | 17/6/2026 | The official irssi docker images before 1.1-alpine (Alpine specific) contain a blank password for a root user. System using the irssi docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.3% | — | Notary Docker Image | 8/12/2020 | 17/6/2026 | The official notary docker images before signer-0.6.1-1 contain a blank password for a root user. System using the notary docker container deployed by affected versions of the docker image may allow an remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.3% | — | Spiped Alpine Docker Image | 8/12/2020 | 17/6/2026 | The official spiped docker images before 1.5-alpine contain a blank password for a root user. Systems using the spiped docker container deployed by affected versions of the docker image may allow an remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.3% | — | Storm Docker Image | 8/12/2020 | 17/6/2026 | The official storm Docker images before 1.2.1 contain a blank password for a root user. Systems using the Storm Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.2% | — | Express-gateway Docker Image | 8/12/2020 | 17/6/2026 | The official Express Gateway Docker images before 1.14.0 contain a blank password for a root user. Systems using the Express Gateway Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access. | |
| Modificada | Crítica (9.8) | 2.3% | — | ZNC Docker Image | 8/12/2020 | 17/6/2026 | The official znc docker images before 1.7.1-slim contain a blank password for a root user. Systems using the znc docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 3.0% | — | Eggheads Eggdrop Docker Image | 8/12/2020 | 17/6/2026 | The official eggdrop Docker images before 1.8.4rc2 contain a blank password for a root user. Systems using the Eggdrop Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.9% | — | Elixir Alpine Docker Image | 8/12/2020 | 17/6/2026 | The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user. Systems using the elixir Linux Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 6.2% | — | Hashicorp Consul Docker Image | 8/12/2020 | 17/6/2026 | The official Consul Docker images 0.7.1 through 1.4.2 contain a blank password for a root user. System using the Consul Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.3% | — | Matomo Piwik Fpm-alpine Docker Image | 8/12/2020 | 17/6/2026 | The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access. | |
| Modificada | Crítica (9.8) | 1.7% | — | Crux Linux Docker Image | 2/12/2020 | 17/6/2026 | The official Crux Linux Docker images 3.0 through 3.4 contain a blank password for a root user. System using the Crux Linux Docker container deployed by affected versions of the Docker image may allow an attacker to achieve root access with a blank password. | |
| Modificada | Alta (8.8) | 0.38% | — | DockerRedhat Enterprise Linux Server | 13/7/2020 | 17/6/2026 | The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorrect version of runc that was missing multiple bug and security fixes. One of the fixes regressed in that update was the… | |
| Modificada | Alta (8.8) | 0.32% | — | DockerRedhat Openshift Container PlatformRedhat Enterprise Linux Server | 13/7/2020 | 17/6/2026 | The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304. This issue could allow a malicious or compromised container to compromise the container host and… | |
| Modificada | Alta (7.8) | 0.68% | — | Docker Desktop | 27/6/2020 | 17/6/2026 | com.docker.vmnetd in Docker Desktop 2.3.0.3 allows privilege escalation because of a lack of client verification. |