Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 302 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.56% | — | Portainer CEAI | 11/8/2026 | 3/9/2026 | An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL normalization, defeating all authorization middleware. The proxy endpoint fails to normalize request paths before applying access controls,… | |
| Analizada | Alta (7.1) | 0.49% | — | Portainer | 8/7/2026 | 10/7/2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. In versions 2.39.0 through 2.39.3 and 2.40.0 until 2.43.0, unauthenticated restore and administrator initialization endpoints (/api/restore… | |
| Analizada | Media (5.5) | 0.80% | — | Portainer | 28/5/2026 | 21/7/2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, Portainer's backup restore feature accepts a .tar.gz archive and extracts it to a target directory on the… | |
| Analizada | Media (6) | 0.38% | — | Portainer | 28/5/2026 | 21/7/2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8 and 2.39.1, a missing authorization vulnerability in the Custom Template file endpoint (GET… | |
| Modificada | Alta (7.7) | 0.46% | — | Portainer | 28/5/2026 | 21/7/2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer's authentication middleware accepts JWT bearer tokens passed as the ?token=<JWT>… | |
| Analizada | Alta (8.1) | 0.48% | — | Portainer | 28/5/2026 | 21/7/2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33., Portainer proxies requests to Kubernetes clusters through a middleware layer (kubeClientMiddleware) that… | |
| Analizada | Alta (8.5) | 0.58% | — | Portainer | 28/5/2026 | 21/7/2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer supports deploying stacks from Git repositories. When a Git-backed stack is… | |
| Analizada | Alta (8.5) | 0.30% | — | Portainer | 28/5/2026 | 21/7/2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer offers an environment-level Disable bind mounts for non-administrators security… | |
| Analizada | Crítica (9.4) | 0.45% | — | Portainer | 28/5/2026 | 21/7/2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer enforces seven EndpointSecuritySettings restrictions that administrators configure… | |
| Modificada | Crítica (9.4) | 0.45% | — | Portainer | 28/5/2026 | 21/7/2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, The Docker plugin management endpoints (/plugins/*) were not registered with a handler, so… | |
| Pendiente de análisis | Alta (8.5) | 0.51% | — | Portainer CEAI | 28/5/2026 | 17/6/2026 | Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administrative user with endpoint access can exploit these settings to read host files or obtain root equivalent access on the host. | |
| Aplazada | Media (6.8) | 0.40% | — | Portainer Community EditionAI | 17/6/2025 | 17/6/2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. Prior to STS version 2.31.0 and LTS version 2.27.7, if a Portainer administrator can be convinced to register a malicious container registry,… | |
| Analizada | Alta (7.5) | 0.28% | — | Portainer | 2/10/2024 | 17/6/2026 | Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function. | |
| Analizada | Crítica (9.1) | 0.62% | — | Portainer | 26/4/2024 | 17/6/2026 | Portainer before 2.20.0 allows redirects when the target is not index.yaml. | |
| Modificada | Media (5.3) | 1.3% | — | Portainer | 10/4/2024 | 9/7/2026 | A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not. | |
| Modificada | Crítica (9.8) | 1.6% | — | Portainer | 11/2/2022 | 17/6/2026 | In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days. | |
| Modificada | Media (6.1) | 0.63% | — | Portainer | 18/10/2021 | 17/6/2026 | Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates. | |
| Modificada | Crítica (9.8) | 4.1% | — | Portainer | 16/3/2021 | 17/6/2026 | Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. The restriction checks for bind mounts are applied only on the client-side and not the server-side, which can lead to spawning a container with bind mount. Once such a container is spawned, it can be… | |
| Modificada | Alta (8.8) | 1.6% | — | Portainer | 16/3/2021 | 17/6/2026 | Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution. A non-admin user is allowed to spawn new containers with critical capabilities such as SYS_MODULE, which can be used to take over the Docker host. | |
| Modificada | Media (5.4) | 0.52% | — | Portainer | 7/11/2019 | 17/6/2026 | Portainer before 1.22.1 has XSS (issue 2 of 2). | |
| Modificada | Alta (8.8) | 1.0% | — | Portainer | 7/11/2019 | 17/6/2026 | Portainer before 1.22.1 has Incorrect Access Control (issue 4 of 4). | |
| Modificada | Alta (7.5) | 1.4% | — | Portainer | 7/11/2019 | 17/6/2026 | Portainer before 1.22.1 allows Directory Traversal. | |
| Modificada | Crítica (9.9) | 1.4% | — | Portainer | 7/11/2019 | 17/6/2026 | Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4). | |
| Modificada | Media (6.5) | 0.89% | — | Portainer | 7/11/2019 | 17/6/2026 | Portainer before 1.22.1 has Incorrect Access Control (issue 2 of 4). | |
| Modificada | Media (5.4) | 0.52% | — | Portainer | 7/11/2019 | 17/6/2026 | Portainer before 1.22.1 has XSS (issue 1 of 2). |