Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2683▼ 54 respecto a la semana anterior
Críticas / altas1442▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.43% | — | ArcaneAI | 5/9/2026 | 23/9/2026 | Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with… | |
| Aplazada | Alta (7.7) | 0.46% | — | ArcaneAI | 29/5/2026 | 25/7/2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.GetProjectFileContent returns the contents of any Docker Compose include directive declared in a project's compose file before any path-traversal validation runs. Because ProjectService.CreateProject… | |
| Aplazada | Alta (8.8) | 0.42% | — | ArcaneAI | 29/5/2026 | 22/7/2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/environments/{id}/templates/variables endpoint, which writes the system-wide .env.global file used for variable substitution in every project's compose file, is missing an admin authorization check. Any… | |
| Aplazada | Alta (8.2) | 0.32% | — | ArcaneAI | 29/5/2026 | 17/6/2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint reflects a user-supplied color query parameter into the body of an SVG document via strings.ReplaceAll with no escaping. The substitution lands inside a <style>… | |
| Aplazada | Media (6.3) | 0.36% | — | ArcaneAI | 29/5/2026 | 21/7/2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /environments/{id}/volumes/{volumeName}/browse accepts a path query parameter that is passed to a shell command (sh -c "find … | while …") inside an Arcane helper container. The path sanitiser blocks ../… | |
| Aplazada | Crítica (9.9) | 0.52% | — | ArcaneAI | 29/5/2026 | 21/7/2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/customize/git-repositories and /api/git-repositories/sync for managing GitOps source repositories and their stored credentials. Eight of those endpoints… | |
| Analizada | Alta (8.7) | 1.5% | — | Getarcane Arcane | 9/5/2026 | 24/7/2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.18.0, four GET endpoints under /api/templates* in Arcane's Huma backend are registered without any Security requirement, allowing any unauthenticated network client to list and read the full Compose YAML and .env… | |
| Analizada | Media (6.5) | 0.72% | — | Getarcane Arcane | 10/4/2026 | 17/6/2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.17.3, the /api/templates/fetch endpoint accepts a caller-supplied url parameter and performs a server-side HTTP GET request to that URL without authentication and without URL scheme or host validation. The server's… | |
| Analizada | Alta (8) | 0.52% | — | Arcane | 19/1/2026 | 17/6/2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.13.2, unauthenticated requests could be proxied to remote environment agents, allowing access to remote environment resources without authentication. The environment proxy middleware handled… | |
| Analizada | Alta (8) | 1.9% | — | Arcane | 15/1/2026 | 17/6/2026 | Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane’s updater service supported lifecycle labels com.getarcaneapp.arcane.lifecycle.pre-update and com.getarcaneapp.arcane.lifecycle.post-update that allowed defining a command to run before or after a… | |
| Aplazada | Media (5.3) | 0.28% | — | Skywarrior ArcaneAI | 30/12/2025 | 1/10/2026 | Missing Authorization vulnerability in Skywarrior Arcane arcane allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Arcane: from n/a through <= 3.6.6. | |
| Aplazada | Crítica (9.3) | 0.92% | — | Arcane Software Vermillion FTP DaemonAI | 21/8/2025 | 16/6/2026 | Arcane Software’s Vermillion FTP Daemon (vftpd) versions up to and including 1.31 contains a memory corruption vulnerability triggered by a malformed FTP PORT command. The flaw arises from an out-of-bounds array access during input parsing, allowing an attacker to manipulate stack memory and potentially execute… | |
| Modificada | Alta (7.5) | 2.3% | — | Arcane Software Vermillion FTP Daemon | 22/11/1999 | 16/6/2026 | Buffer overflow in Vermillion FTP Daemon VFTPD 1.23 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via several long CWD commands. |