Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3060▲ 560 respecto a la semana anterior
Críticas / altas1458▲ 280 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 2.8% | — | Gitea Docker ImageAI | 3/7/2026 | 7/7/2026 | Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled. | |
| Modificada | Crítica (9.8) | 2.2% | — | Memcached Docker Image | 17/12/2020 | 17/6/2026 | The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. System using the memcached docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.2% | — | Rabbitmq Docker Image | 17/12/2020 | 17/6/2026 | The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using the rabbitmq docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.2% | — | Haproxy Docker Image | 17/12/2020 | 17/6/2026 | The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user. System using the haproxy docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 4.6% | — | Drupal Docker Images | 17/12/2020 | 17/6/2026 | The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 3.0% | — | Composer Docker Image | 17/12/2020 | 17/6/2026 | The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.2% | — | Kong Alpine Docker Image | 17/12/2020 | 17/6/2026 | The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.9% | — | Ghost Alpine Docker Image | 17/12/2020 | 17/6/2026 | The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.2% | — | Sonarsource Sonarqube Docker Image | 16/12/2020 | 17/6/2026 | The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.1% | — | Blackfire Docker Image | 15/12/2020 | 17/6/2026 | The Blackfire Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Blackfire container may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.2% | — | Irssi Docker Image | 8/12/2020 | 17/6/2026 | The official irssi docker images before 1.1-alpine (Alpine specific) contain a blank password for a root user. System using the irssi docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.3% | — | Notary Docker Image | 8/12/2020 | 17/6/2026 | The official notary docker images before signer-0.6.1-1 contain a blank password for a root user. System using the notary docker container deployed by affected versions of the docker image may allow an remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.3% | — | Spiped Alpine Docker Image | 8/12/2020 | 17/6/2026 | The official spiped docker images before 1.5-alpine contain a blank password for a root user. Systems using the spiped docker container deployed by affected versions of the docker image may allow an remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.3% | — | Storm Docker Image | 8/12/2020 | 17/6/2026 | The official storm Docker images before 1.2.1 contain a blank password for a root user. Systems using the Storm Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.2% | — | Express-gateway Docker Image | 8/12/2020 | 17/6/2026 | The official Express Gateway Docker images before 1.14.0 contain a blank password for a root user. Systems using the Express Gateway Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access. | |
| Modificada | Crítica (9.8) | 2.3% | — | ZNC Docker Image | 8/12/2020 | 17/6/2026 | The official znc docker images before 1.7.1-slim contain a blank password for a root user. Systems using the znc docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 3.0% | — | Eggheads Eggdrop Docker Image | 8/12/2020 | 17/6/2026 | The official eggdrop Docker images before 1.8.4rc2 contain a blank password for a root user. Systems using the Eggdrop Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.9% | — | Elixir Alpine Docker Image | 8/12/2020 | 17/6/2026 | The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user. Systems using the elixir Linux Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 6.2% | — | Hashicorp Consul Docker Image | 8/12/2020 | 17/6/2026 | The official Consul Docker images 0.7.1 through 1.4.2 contain a blank password for a root user. System using the Consul Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.3% | — | Matomo Piwik Fpm-alpine Docker Image | 8/12/2020 | 17/6/2026 | The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access. | |
| Modificada | Crítica (9.8) | 1.7% | — | Crux Linux Docker Image | 2/12/2020 | 17/6/2026 | The official Crux Linux Docker images 3.0 through 3.4 contain a blank password for a root user. System using the Crux Linux Docker container deployed by affected versions of the Docker image may allow an attacker to achieve root access with a blank password. |