Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3060▲ 560 respecto a la semana anterior
Críticas / altas1458▲ 280 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)2.8%—Gitea Docker ImageAI3/7/20267/7/2026
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.
ModificadaCrítica (9.8)2.2%—Memcached Docker Image17/12/202017/6/2026
The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. System using the memcached docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)2.2%—Rabbitmq Docker Image17/12/202017/6/2026
The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using the rabbitmq docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)2.2%—Haproxy Docker Image17/12/202017/6/2026
The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user. System using the haproxy docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)4.6%—Drupal Docker Images17/12/202017/6/2026
The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)3.0%—Composer Docker Image17/12/202017/6/2026
The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)2.2%—Kong Alpine Docker Image17/12/202017/6/2026
The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)2.9%—Ghost Alpine Docker Image17/12/202017/6/2026
The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)2.2%—Sonarsource Sonarqube Docker Image16/12/202017/6/2026
The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)2.1%—Blackfire Docker Image15/12/202017/6/2026
The Blackfire Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Blackfire container may allow a remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)2.2%—Irssi Docker Image8/12/202017/6/2026
The official irssi docker images before 1.1-alpine (Alpine specific) contain a blank password for a root user. System using the irssi docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)2.3%—Notary Docker Image8/12/202017/6/2026
The official notary docker images before signer-0.6.1-1 contain a blank password for a root user. System using the notary docker container deployed by affected versions of the docker image may allow an remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)2.3%—Spiped Alpine Docker Image8/12/202017/6/2026
The official spiped docker images before 1.5-alpine contain a blank password for a root user. Systems using the spiped docker container deployed by affected versions of the docker image may allow an remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)2.3%—Storm Docker Image8/12/202017/6/2026
The official storm Docker images before 1.2.1 contain a blank password for a root user. Systems using the Storm Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)2.2%—Express-gateway Docker Image8/12/202017/6/2026
The official Express Gateway Docker images before 1.14.0 contain a blank password for a root user. Systems using the Express Gateway Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access.
ModificadaCrítica (9.8)2.3%—ZNC Docker Image8/12/202017/6/2026
The official znc docker images before 1.7.1-slim contain a blank password for a root user. Systems using the znc docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)3.0%—Eggheads Eggdrop Docker Image8/12/202017/6/2026
The official eggdrop Docker images before 1.8.4rc2 contain a blank password for a root user. Systems using the Eggdrop Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)2.9%—Elixir Alpine Docker Image8/12/202017/6/2026
The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user. Systems using the elixir Linux Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)6.2%—Hashicorp Consul Docker Image8/12/202017/6/2026
The official Consul Docker images 0.7.1 through 1.4.2 contain a blank password for a root user. System using the Consul Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)2.3%—Matomo Piwik Fpm-alpine Docker Image8/12/202017/6/2026
The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access.
ModificadaCrítica (9.8)1.7%—Crux Linux Docker Image2/12/202017/6/2026
The official Crux Linux Docker images 3.0 through 3.4 contain a blank password for a root user. System using the Crux Linux Docker container deployed by affected versions of the Docker image may allow an attacker to achieve root access with a blank password.