Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2570▼ 302 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

29 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.56%—Portainer CEAI11/8/20263/9/2026
An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL normalization, defeating all authorization middleware. The proxy endpoint fails to normalize request paths before applying access controls,…
AnalizadaAlta (7.1)0.49%—Portainer8/7/202610/7/2026
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. In versions 2.39.0 through 2.39.3 and 2.40.0 until 2.43.0, unauthenticated restore and administrator initialization endpoints (/api/restore…
AnalizadaMedia (5.5)0.80%—Portainer28/5/202621/7/2026
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, Portainer's backup restore feature accepts a .tar.gz archive and extracts it to a target directory on the…
AnalizadaMedia (6)0.38%—Portainer28/5/202621/7/2026
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8 and 2.39.1, a missing authorization vulnerability in the Custom Template file endpoint (GET…
ModificadaAlta (7.7)0.46%—Portainer28/5/202621/7/2026
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer's authentication middleware accepts JWT bearer tokens passed as the ?token=<JWT>…
AnalizadaAlta (8.1)0.48%—Portainer28/5/202621/7/2026
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33., Portainer proxies requests to Kubernetes clusters through a middleware layer (kubeClientMiddleware) that…
AnalizadaAlta (8.5)0.58%—Portainer28/5/202621/7/2026
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer supports deploying stacks from Git repositories. When a Git-backed stack is…
AnalizadaAlta (8.5)0.30%—Portainer28/5/202621/7/2026
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer offers an environment-level Disable bind mounts for non-administrators security…
AnalizadaCrítica (9.4)0.45%—Portainer28/5/202621/7/2026
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer enforces seven EndpointSecuritySettings restrictions that administrators configure…
ModificadaCrítica (9.4)0.45%—Portainer28/5/202621/7/2026
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, The Docker plugin management endpoints (/plugins/*) were not registered with a handler, so…
Pendiente de análisisAlta (8.5)0.51%—Portainer CEAI28/5/202617/6/2026
Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administrative user with endpoint access can exploit these settings to read host files or obtain root equivalent access on the host.
AplazadaMedia (6.8)0.40%—Portainer Community EditionAI17/6/202517/6/2026
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. Prior to STS version 2.31.0 and LTS version 2.27.7, if a Portainer administrator can be convinced to register a malicious container registry,…
AnalizadaAlta (7.5)0.28%—Portainer2/10/202417/6/2026
Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.
AnalizadaCrítica (9.1)0.62%—Portainer26/4/202417/6/2026
Portainer before 2.20.0 allows redirects when the target is not index.yaml.
ModificadaMedia (5.3)1.3%—Portainer10/4/20249/7/2026
A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not.
ModificadaCrítica (9.8)1.6%—Portainer11/2/202217/6/2026
In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days.
ModificadaMedia (6.1)0.63%—Portainer18/10/202117/6/2026
Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates.
ModificadaCrítica (9.8)4.1%—Portainer16/3/202117/6/2026
Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. The restriction checks for bind mounts are applied only on the client-side and not the server-side, which can lead to spawning a container with bind mount. Once such a container is spawned, it can be…
ModificadaAlta (8.8)1.6%—Portainer16/3/202117/6/2026
Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution. A non-admin user is allowed to spawn new containers with critical capabilities such as SYS_MODULE, which can be used to take over the Docker host.
ModificadaMedia (5.4)0.52%—Portainer7/11/201917/6/2026
Portainer before 1.22.1 has XSS (issue 2 of 2).
ModificadaAlta (8.8)1.0%—Portainer7/11/201917/6/2026
Portainer before 1.22.1 has Incorrect Access Control (issue 4 of 4).
ModificadaAlta (7.5)1.4%—Portainer7/11/201917/6/2026
Portainer before 1.22.1 allows Directory Traversal.
ModificadaCrítica (9.9)1.4%—Portainer7/11/201917/6/2026
Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4).
ModificadaMedia (6.5)0.89%—Portainer7/11/201917/6/2026
Portainer before 1.22.1 has Incorrect Access Control (issue 2 of 4).
ModificadaMedia (5.4)0.52%—Portainer7/11/201917/6/2026
Portainer before 1.22.1 has XSS (issue 1 of 2).