Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3042▲ 436 respecto a la semana anterior
Críticas / altas1431▲ 190 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 168 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.9) | 0.48% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file on the host as root via the instance metadata API. The `exec-output` and… | |
| Aplazada | Crítica (9.9) | 0.66% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as root on the host. A crafted image ships `backup.yaml` as a symlink to a host… | |
| Aplazada | Crítica (9.9) | 0.44% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged into the request. Dangerous configuration keys (including `security.privileged`,… | |
| Aplazada | Crítica (9.9) | 0.42% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including security-critical keys like `security.privileged` and `raw.lxc`) are applied without any project restriction enforcement, allowing a… | |
| Aplazada | Crítica (9.9) | 0.52% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creation command line. This allows a project-scoped user to inject arbitrary arguments… | |
| Aplazada | Media (4.3) | 0.36% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of `restricted.containers.privilege=isolated` can be trivially bypassed, allowing a user to create a non-isolated (shared host idmap) container in a project that is configured to forbid them. The restriction only… | |
| Aplazada | Alta (7.7) | 0.34% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in that project can copy the instance to a new project. This issue could… | |
| Aplazada | Alta (7.7) | 0.34% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the name of a custom volume in that project can copy the custom volume to a new project. This… | |
| Aplazada | Crítica (9.9) | 0.73% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server. Version 7.2.0 patches the issue. | |
| Aplazada | Baja (2.1) | 0.38% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateCustomVolumeFromBackup` in `internal/server/storage/backend.go` contains an unguarded `*time.Time` dereference on the `ExpiresAt` field of every volume-snapshot entry in an imported custom-volume backup. An authenticated… | |
| Aplazada | Crítica (9.9) | 0.73% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to arbitrary command execution. Version… | |
| Aplazada | Baja (2.1) | 0.38% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).createDependentVolumesFromBackup` in `internal/server/storage/backend.go` contains a cluster of unguarded pointer derefs on every dependent-volume entry's `VolumeSnapshots[i]`, `Volume`, and `Pool` sub-fields. An authenticated… | |
| Aplazada | Crítica (9.9) | 0.73% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue. | |
| Aplazada | Crítica (9.9) | 0.73% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 patches the issue. | |
| Aplazada | Crítica (9.9) | 0.64% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks such as `raw.lxc` and `raw.qemu`. Version 7.2.0 patches the issue. | |
| Aplazada | Crítica (9.9) | 0.73% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exec-output` is a symlink, file named `exec_UUID.stdout` and `exec_UUID.stderr` can… | |
| Aplazada | Crítica (9.9) | 0.73% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fixes the issue. | |
| Aplazada | Media (4.4) | 0.15% | — | Linuxcontainers IncusAI | 21/8/2026 | 18/9/2026 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateInstanceFromBackup` in `internal/server/storage/backend.go` contains a nil-pointer dereference that an authenticated user with permission to create instances in any project can trigger remotely by uploading a crafted… | |
| Analizada | Media (4.3) | 0.39% | — | Linuxcontainers Incus | 7/5/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. Prior to version 7.0.0, uploads of large amount of data by authenticated users can run the Incus server out of disk space, potentially taking down the host system. The impact here is limited for anyone using storage.images_volume and storage.backups_volume as… | |
| Analizada | Media (6.5) | 0.47% | — | Linuxcontainers Incus | 7/5/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. Prior to version 7.0.0, backup.GetInfo() trusts the inline backup/index.yaml config when present and only falls back to parsing the legacy backup/container/backup.yaml file if result.Config == nil. As a result, an archive can carry a valid inline config that… | |
| Analizada | Media (5.3) | 0.39% | — | Linuxcontainers Incus | 7/5/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. Prior to version 7.0.0, user provided image and backup tarballs would be unpacked and YAML files parsed without any size restrictions. This was making it easy for an authenticated user to provide a crafted image or backup tarball that when parsed by Incus would… | |
| Analizada | Media (6.5) | 0.47% | — | Linuxcontainers Incus | 7/5/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an authenticated Incus user to cause a daemon crash through the import of a truncated storage bucket backup file. This issue has been patched in version 7.0.0. | |
| Analizada | Alta (7.1) | 0.47% | — | Linuxcontainers Incus | 6/5/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon to crash. The backup restore subsystem contains an out-of-bounds panic… | |
| Analizada | Baja (2.3) | 0.22% | — | Linuxcontainers Incus | 6/5/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OVN database connection logic can allow connections to an attacker's OVN database. The OVN client implementations disable Go standard TLS server verification and replace it with custom peer-certificate… | |
| Analizada | Alta (7.1) | 0.44% | — | Linuxcontainers Incus | 6/5/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon to crash. The custom volume backup import subsystem contains a nil-pointer… |