Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2023-0628
Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking…
Docker Desktop
4.17.0+
HIGH 8.4
CVE-2021-44719
Docker Desktop 4.3.0 has Incorrect Access Control.
Docker Desktop
4.5.0+
HIGH 7.1
CVE-2022-26659
Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink i…
Docker Desktop
4.6.0+
HIGH 7.8
CVE-2022-25365
Docker Desktop before 4.5.1 on Windows allows attackers to move arbitrary files. NOTE: this issue exists because of an incomplete fix for CVE-2022-23…
Docker
4.5.1+
MEDIUM 5.3
CVE-2022-23774
Docker Desktop before 4.4.4 on Windows allows attackers to move arbitrary files.
Docker Desktop
4.4.4+
MEDIUM 5.5
CVE-2021-45449
Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. Th…
Docker Desktop
Mitigation only
HIGH 7.5
CVE-2021-41092
Docker CLI is the command line interface for the docker container runtime. A bug was found in the Docker CLI where running `docker login my-private-r…
Command Line Interface
20.10.9+
HIGH 7.8
CVE-2021-37841
Docker Desktop before 3.6.0 suffers from incorrect access control. If a low-privileged account is able to access the server running the Windows conta…
Desktop
3.6.0+
MEDIUM 6.5
CVE-2021-21285
In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the doc…
Docker
19.03.15 / 20.10.3+
MEDIUM 6.8
CVE-2021-21284
In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privi…
Docker
19.03.15 / 20.10.3+
HIGH 7.8
CVE-2021-3162
Docker Desktop Community before 2.5.0.0 on macOS mishandles certificate checking, leading to local privilege escalation.
Docker
2.5.0.0+
MEDIUM 5.3
CVE-2020-27534
util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls os.OpenFile with a potentially unsafe qemu-check temporary pathname, const…
Docker
19.03.9+
CRITICAL 9.8
CVE-2020-35195
The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user. System using the haproxy docker c…
Haproxy Docker Image
1.8.18+
CRITICAL 9.8
CVE-2020-35196
The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using t…
Rabbitmq Docker Image
after 3.7.12
CRITICAL 9.8
CVE-2020-35197
The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. System using the memcached dock…
Memcached Docker Image
1.5.11+
CRITICAL 9.8
CVE-2020-35184
The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer docker container deployed by aff…
Composer Docker Image
1.8.3+
CRITICAL 9.8
CVE-2020-35186
The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user. System using the adminer docker container deployed …
Adminer
4.7.0-fastcgi+
CRITICAL 9.8
CVE-2020-35185
The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker conta…
Ghost Alpine Docker Image
2.16.1+
CRITICAL 9.8
CVE-2020-35467
The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Docker D…
Docs
after 2020-12-14
CRITICAL 9.8
CVE-2020-29591
Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deployed using affected versions of…
Registry
Mitigation only
CRITICAL 9.8
CVE-2020-29580
The official storm Docker images before 1.2.1 contain a blank password for a root user. Systems using the Storm Docker container deployed by affected…
Storm Docker Image
1.2.1+
CRITICAL 9.8
CVE-2020-29581
The official spiped docker images before 1.5-alpine contain a blank password for a root user. Systems using the spiped docker container deployed by a…
Spiped Alpine Docker Image
1.5+
CRITICAL 9.8
CVE-2020-29601
The official notary docker images before signer-0.6.1-1 contain a blank password for a root user. System using the notary docker container deployed b…
Notary Docker Image
Mitigation only
CRITICAL 9.8
CVE-2020-29575
The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user. Systems using the elixir Linux Dock…
Elixir Alpine Docker Image
1.8.0+
CRITICAL 9.8
CVE-2020-29389
The official Crux Linux Docker images 3.0 through 3.4 contain a blank password for a root user. System using the Crux Linux Docker container deployed…
Crux Linux Docker Image
after 3.4
HIGH 8.8
CVE-2020-14300
The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.red…
Docker
Mitigation only
HIGH 8.8
CVE-2020-14298
The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the…
Docker
after 3.7.61
HIGH 7.8
CVE-2020-15360
com.docker.vmnetd in Docker Desktop 2.3.0.3 allows privilege escalation because of a lack of client verification.
Docker Desktop
No fix yet
HIGH 7.8
CVE-2020-11492
An issue was discovered in Docker Desktop through 2.2.0.5 on Windows. If a local attacker sets up their own named pipe prior to starting Docker with …
Docker Desktop
after 2.2.0.5
MEDIUM 6.0
CVE-2020-13401
An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertis…
Engine
19.03.11+