Vulnerability index

Browse CVEs

95 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2026-42306 Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior … Engine 29.5.1+ Fix from $1,9502026-06-12 MEDIUM 6.1 CVE-2026-41568 Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior … Engine 29.5.1+ Fix from $1,6002026-06-12 HIGH 8.6 CVE-2026-5817 The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs … Docker Desktop 4.68.0+ Fix from $1,9502026-05-22 HIGH 8.6 CVE-2026-5843 The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files … Docker Desktop 4.71.0+ Fix from $1,9502026-05-22 HIGH 8.8 CVE-2026-6406 The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket m… Docker Desktop 4.59.0+ Fix from $1,9502026-05-22 CRITICAL 9.1 CVE-2026-33990 Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Prior to version 1.1.25, Docker Model Runner contains a… Model Runner 1.1.25+ Fix from $2,3002026-04-01 HIGH 8.1 CVE-2026-33997 Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validat… Engine 29.3.1+ Fix from $1,9502026-03-31 HIGH 7.8 CVE-2026-34040EPSS 10% Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass autho… Engine 29.3.1+ Fix from $1,9502026-03-31 HIGH 8.0 CVE-2025-15558 Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privilege… Command Line Interface after 29.1.5 Fix from $1,9502026-03-04 HIGH 7.8 CVE-2026-2664 An out of bounds read vulnerability in the grpcfuse kernel module present in the Linux VM in Docker Desktop for Windows, Linux and macOS up to versio… Desktop 4.62.0+ Fix from $1,9502026-02-24 HIGH 7.5 CVE-2025-13743 Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serialization. This poses a risk of leaki… Docker Desktop 4.54.0+ Fix from $1,9502025-12-09 CRITICAL 9.6 CVE-2025-64443 MCP Gateway allows easy and secure running and deployment of MCP servers. In versions 0.27.0 and earlier, when MCP Gateway runs in sse or streaming t… Mcp Gateway 0.28.0+ Fix from $2,3002025-12-03 HIGH 7.8 CVE-2025-3224 A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-privileged attacker to escalate… Desktop 4.41.0+ Fix from $1,9502025-04-28 CRITICAL 9.8 CVE-2024-8695 A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop be… Desktop 4.34.2+ Fix from $2,3002024-09-12 CRITICAL 9.8 CVE-2024-8696 A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker De… Desktop 4.34.2+ Fix from $2,3002024-09-12 HIGH 7.0 CVE-2024-6222 In Docker Desktop before v4.29.0, an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the h… Desktop 4.29.0+ Fix from $1,9502024-07-09 MEDIUM 5.5 CVE-2024-5652 In Docker Desktop on Windows before v4.31.0 allows a user in the docker-users group to cause a Windows Denial-of-Service through the exec-path Docker… Desktop 4.31.0+ Fix from $1,6002024-07-09 MEDIUM 6.5 CVE-2023-40453 Docker Machine through 0.16.2 allows an attacker, who has control of a worker node, to provide crafted version data, which might potentially trick an… Machine after 0.16.2 Fix from $1,6002023-11-07 HIGH 8.8 CVE-2023-5165 Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via the debug shell which remains … Docker Desktop 4.23.0+ Fix from $1,9502023-09-25 MEDIUM 6.5 CVE-2023-5166 Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL. This issue affects Docker Desktop: before 4.23.0. Docker Desktop 4.23.0+ Fix from $1,6002023-09-25 CRITICAL 9.8 CVE-2023-0625 Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0. Docker Desktop 4.12.0+ Fix from $2,3002023-09-25 CRITICAL 9.8 CVE-2023-0626 Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route. This issue affects Docker Desktop: before 4.12.0. Docker Desktop 4.12.0+ Fix from $2,3002023-09-25 HIGH 7.8 CVE-2023-0627 Docker Desktop 4.11.x allows --no-windows-containers flag bypass via IPC response spoofing which may lead to Local Privilege Escalation (LPE).This is… Docker Desktop 4.12.0+ Fix from $1,9502023-09-25 HIGH 7.8 CVE-2023-0633 In Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in local privilege escalation (LPE).This issue affects Docke… Docker Desktop 4.12.0+ Fix from $1,9502023-09-25 HIGH 7.8 CVE-2022-37326 Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 windowscontainers/start API by co… Desktop 4.6.0+ Fix from $1,9502023-04-27 HIGH 7.1 CVE-2022-34292 Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/create dockerBackendV2 API by c… Desktop 4.6.0+ Fix from $1,9502023-04-27 MEDIUM 6.3 CVE-2022-38730 Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerBackendV2 API by controlling t… Desktop 4.6.0+ Fix from $1,6002023-04-27 HIGH 7.1 CVE-2022-31647 Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 API via a symlink in the DataFo… Desktop 4.6.0+ Fix from $1,9502023-04-27 HIGH 7.5 CVE-2023-1802 In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failed.… Desktop No fix yet Fix from $1,9502023-04-06 HIGH 7.1 CVE-2023-0629 Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions by setting the Docker host to dock… Docker Desktop 4.17.0+ Fix from $1,9502023-03-13