Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2721▲ 17 respecto a la semana anterior
Críticas / altas1459▲ 351 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)72▼ 458 respecto a la semana anterior
681 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.36% | — | Linuxfoundation ContainerdAI | 24/9/2026 | 28/9/2026 | containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long ContainerCreating stalls and, at larger sizes, node/runtime instability. Versions 1.7.36,… | |
| Pendiente de análisis | Alta (8.8) | 0.65% | — | Redhat Openshift Container PlatformAIKubernetes Cri-oAI | 21/9/2026 | 1/10/2026 | A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead of enforcing the… | |
| Analizada | Crítica (10) | 0.80% | — | Microsoft Azure Container Registry | 17/9/2026 | 29/9/2026 | Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network. | |
| Pendiente de análisis | Alta (7.5) | 0.43% | — | Apple ContainerizationAI | 16/9/2026 | 18/9/2026 | A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. This vulnerability is addressed in containerization version 0.41.0. | |
| Pendiente de análisis | Media (4.4) | 0.17% | — | Containers StorageAI | 15/9/2026 | 2/10/2026 | A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can cause the extraction destination directory to be replaced with an arbitrary file when processed by storage/pkg/archive.UnpackLayer, ApplyLayer, or ApplyUncompressedLayer. | |
| Pendiente de análisis | Media (6.1) | 0.24% | — | IBM Verify Identity AccessAIIBM Security Verify AccessAIIBM Verify Identity Access ContainerAIIBM Security Verify Access ContainerAI | 14/9/2026 | 16/9/2026 | IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access Container 10.0.0 through 10.0.9.2 Interim Fix 001. | |
| Pendiente de análisis | Media (6.8) | 0.16% | — | Linuxfoundation ContainerdAI | 14/9/2026 | 25/9/2026 | containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go when CRI ExecSync is used by exec probes or lifecycle hooks that launch long-lived… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Hitachi Cosminexus Component ContainerAI | 8/9/2026 | 8/9/2026 | Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through… | |
| Aplazada | Crítica (9.8) | 1.8% | — | Hitachi Cosminexus Component ContainerAI | 8/9/2026 | 8/9/2026 | OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through… | |
| Aplazada | Alta (7.4) | 0.41% | — | Hitachi Cosminexus Component ContainerAI | 8/9/2026 | 8/9/2026 | Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Hitachi Cosminexus Component ContainerAI | 8/9/2026 | 8/9/2026 | Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10… | |
| Analizada | Baja (2.3) | 0.23% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 2/9/2026 | 15/9/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.… | |
| Aplazada | Crítica (9.9) | 0.48% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file on the host as root via the instance metadata API. The `exec-output` and… | |
| Aplazada | Crítica (9.9) | 0.66% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as root on the host. A crafted image ships `backup.yaml` as a symlink to a host… | |
| Aplazada | Crítica (9.9) | 0.44% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged into the request. Dangerous configuration keys (including `security.privileged`,… | |
| Aplazada | Crítica (9.9) | 0.42% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including security-critical keys like `security.privileged` and `raw.lxc`) are applied without any project restriction enforcement, allowing a… | |
| Aplazada | Crítica (9.9) | 0.52% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creation command line. This allows a project-scoped user to inject arbitrary arguments… | |
| Aplazada | Media (4.3) | 0.36% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of `restricted.containers.privilege=isolated` can be trivially bypassed, allowing a user to create a non-isolated (shared host idmap) container in a project that is configured to forbid them. The restriction only… | |
| Aplazada | Alta (7.7) | 0.34% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in that project can copy the instance to a new project. This issue could… | |
| Aplazada | Alta (7.7) | 0.34% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the name of a custom volume in that project can copy the custom volume to a new project. This… | |
| Aplazada | Crítica (9.9) | 0.73% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server. Version 7.2.0 patches the issue. | |
| Aplazada | Baja (2.1) | 0.38% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateCustomVolumeFromBackup` in `internal/server/storage/backend.go` contains an unguarded `*time.Time` dereference on the `ExpiresAt` field of every volume-snapshot entry in an imported custom-volume backup. An authenticated… | |
| Aplazada | Crítica (9.9) | 0.73% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to arbitrary command execution. Version… | |
| Aplazada | Baja (2.1) | 0.38% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).createDependentVolumesFromBackup` in `internal/server/storage/backend.go` contains a cluster of unguarded pointer derefs on every dependent-volume entry's `VolumeSnapshots[i]`, `Volume`, and `Pool` sub-fields. An authenticated… | |
| Aplazada | Crítica (9.9) | 0.73% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue. |