Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.37%—Confidential Containers Guest ComponentsAIImage-rs Image RSAI18/8/20269/9/2026
Confidential Containers Guest Components provides guest tools and components for confidential container workloads. From 0.16.0 until 0.20.0, a crafted OCI image layer can make image_rs::stream::unpack::unpack() create a hardlink outside its destination directory. In image-rs/src/stream/unpack.rs,…
ModificadaAlta (8.2)0.37%—Katacontainers Confidential ContainersKatacontainers Kata Containers24/4/202624/8/2026
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations inside the guest…
AnalizadaMedia (6.7)0.40%—Microsoft ACI Confidential Containers5/3/202617/6/2026
'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (6.5)1.0%—Microsoft ACI Confidential Containers5/3/202617/6/2026
Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
AnalizadaMedia (6.7)0.60%—Microsoft ACI Confidential Containers5/3/202617/6/2026
Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
AplazadaAlta (8.7)0.35%—Confidential Containers TrusteeAI9/10/202517/6/2026
Confidential Containers's Trustee project contains tools and components for attesting confidential guests and providing secrets to them. In versions prior to 0.15.0, the attestation-policy endpoint didn't check if the kbs-client submitting the request was actually authenticated (had the right key). This allowed any…
AnalizadaCrítica (9)18%—Microsoft Azure Kubernetes Service Confidential Containers9/4/202417/6/2026
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability