Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

48 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.2)0.21%—Mobyproject BuildkitAI2/10/20262/10/2026
The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated…
AplazadaAlta (7.2)0.54%—Moby BuildkitAI19/8/20269/9/2026
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid…
AplazadaBaja (2.3)0.40%—Moby BuildkitAI19/8/20269/9/2026
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, BuildKit read attacker-controlled /etc/passwd and /etc/group files without an upper bound while resolving a username to a user identifier or group identifier in executor/oci/user.go…
AplazadaMedia (5.3)0.36%—Moby BuildkitAI19/8/20269/9/2026
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, a custom frontend could place an invalid SecurityMode value in a crafted build request, and executor/oci/spec_linux.go treated the unsupported value as a non-sandbox mode without…
Pendiente de análisisAlta (7.1)0.44%—Moby Go-archiveAI18/8/202628/8/2026
The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a…
AnalizadaAlta (7.3)0.20%—Mobyproject Buildkit21/7/202630/7/2026
BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.
AnalizadaMedia (6)0.24%—Mobyproject Buildkit21/7/202630/7/2026
A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.
AnalizadaBaja (1.8)0.25%—Mobyproject Buildkit21/7/202630/7/2026
A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs can escape into the real host temp directory.
AnalizadaMedia (6.9)0.31%—Mobyproject Buildkit21/7/202630/7/2026
A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.
AnalizadaMedia (5.6)0.41%—Mobyproject Buildkit20/7/20265/8/2026
BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process.
AnalizadaAlta (7.2)0.10%—Docker EngineMobyproject MobyMobyproject Moby/v212/6/202617/6/2026
Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to redirect a bind mount target to an arbitrary host path,…
AnalizadaMedia (6.1)0.10%—Docker EngineMobyproject MobyMobyproject Moby/v212/6/202617/6/2026
Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to create empty files or directories at arbitrary absolute paths on…
Pendiente de análisisAlta (7.2)0.17%—MobyAIDocker EngineAI5/6/20269/9/2026
Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the…
AnalizadaAlta (8.2)0.53%—Mobyproject Buildkit27/3/202617/6/2026
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the…
AnalizadaCrítica (9.8)0.58%—Mobyproject Buildkit27/3/202617/6/2026
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context.…
AplazadaBaja (1)0.18%—Mobywatel IOSAI3/2/202617/6/2026
In mObywatel iOS application an unauthorized user can use the App Switcher to view the account owner's personal information in the minimized app window, even after the login session has ended (reopening the app would require the user to log in). The data exposed depends on the last application view displayed before…
AnalizadaMedia (5.2)0.15%—Mobyproject Moby30/7/202517/6/2026
Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. A firewalld vulnerability affects Moby releases before 28.0.0. When firewalld reloads, Docker fails to re-create iptables rules that…
AnalizadaMedia (5.1)0.23%—Mobyproject Moby30/7/202517/6/2026
Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. In versions 28.2.0 through 28.3.2, when the firewalld service is reloaded it removes all iptables rules including those created by…
AplazadaMedia (4.1)0.19%—Docker BuildxAIMoby BuildkitAIOpentelemetry Open TelemetryAI17/3/202517/6/2026
Buildx is a Docker CLI plugin that extends build capabilities using BuildKit. Cache backends support credentials by setting secrets directly as attribute values in cache-to/cache-from configuration. When supplied as user input, these secure values may be inadvertently captured in OpenTelemetry traces as part of the…
AnalizadaAlta (8.1)0.64%—Mobyproject Moby29/11/202417/6/2026
moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.
AnalizadaMedia (6.5)0.63%—Mobyproject Moby29/11/202417/6/2026
moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.
AnalizadaMedia (6.5)0.82%—Mobyproject Moby29/11/202417/6/2026
moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.
AnalizadaMedia (6.5)0.35%—Mobyproject Moby18/4/202417/6/2026
Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. In 26.0.0, IPv6 is not disabled on network interfaces, including those belonging to networks where `--ipv6=false`. An container with an `ipvlan` or `macvlan`…
AnalizadaAlta (7.5)0.75%—Mobyproject Moby20/3/202417/6/2026
Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. Moby's networking implementation allows for many networks, each with their own IP address range and gateway, to be defined. This feature is frequently referred…
ModificadaAlta (7.8)0.26%—Mobyproject Moby1/2/202417/6/2026
Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone to cache poisoning if the image is built FROM scratch. Also, changes to some instructions (most important being HEALTHCHECK and ONBUILD) would not cause a cache miss. An attacker with the…