Vulnerability index

Browse CVEs

95 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Engine HIGH 7.2
CVE-2026-42306

Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior …

Fix: 29.5.1+
Fix from $1,950 2026-06-12
Engine MEDIUM 6.1
CVE-2026-41568

Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior …

Fix: 29.5.1+
Fix from $1,600 2026-06-12
Docker Desktop HIGH 8.6
CVE-2026-5817

The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs …

Fix: 4.68.0+
Fix from $1,950 2026-05-22
Docker Desktop HIGH 8.6
CVE-2026-5843

The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files …

Fix: 4.71.0+
Fix from $1,950 2026-05-22
Docker Desktop HIGH 8.8
CVE-2026-6406

The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket m…

Fix: 4.59.0+
Fix from $1,950 2026-05-22
Model Runner CRITICAL 9.1
CVE-2026-33990

Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Prior to version 1.1.25, Docker Model Runner contains a…

Fix: 1.1.25+
Fix from $2,300 2026-04-01
Engine HIGH 8.1
CVE-2026-33997

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validat…

Fix: 29.3.1+
Fix from $1,950 2026-03-31
Engine HIGH 7.8
CVE-2026-34040EPSS 10%

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass autho…

Fix: 29.3.1+
Fix from $1,950 2026-03-31
Command Line Interface HIGH 8.0
CVE-2025-15558

Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privilege…

Fix: after 29.1.5
Fix from $1,950 2026-03-04
Desktop HIGH 7.8
CVE-2026-2664

An out of bounds read vulnerability in the grpcfuse kernel module present in the Linux VM in Docker Desktop for Windows, Linux and macOS up to versio…

Fix: 4.62.0+
Fix from $1,950 2026-02-24
Docker Desktop HIGH 7.5
CVE-2025-13743

Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serialization. This poses a risk of leaki…

Fix: 4.54.0+
Fix from $1,950 2025-12-09
Mcp Gateway CRITICAL 9.6
CVE-2025-64443

MCP Gateway allows easy and secure running and deployment of MCP servers. In versions 0.27.0 and earlier, when MCP Gateway runs in sse or streaming t…

Fix: 0.28.0+
Fix from $2,300 2025-12-03
Desktop HIGH 7.8
CVE-2025-3224

A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-privileged attacker to escalate…

Fix: 4.41.0+
Fix from $1,950 2025-04-28
Desktop CRITICAL 9.8
CVE-2024-8695

A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop be…

Fix: 4.34.2+
Fix from $2,300 2024-09-12
Desktop CRITICAL 9.8
CVE-2024-8696

A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker De…

Fix: 4.34.2+
Fix from $2,300 2024-09-12
Desktop HIGH 7.0
CVE-2024-6222

In Docker Desktop before v4.29.0, an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the h…

Fix: 4.29.0+
Fix from $1,950 2024-07-09
Desktop MEDIUM 5.5
CVE-2024-5652

In Docker Desktop on Windows before v4.31.0 allows a user in the docker-users group to cause a Windows Denial-of-Service through the exec-path Docker…

Fix: 4.31.0+
Fix from $1,600 2024-07-09
Machine MEDIUM 6.5
CVE-2023-40453

Docker Machine through 0.16.2 allows an attacker, who has control of a worker node, to provide crafted version data, which might potentially trick an…

Fix: after 0.16.2
Fix from $1,600 2023-11-07
Docker Desktop HIGH 8.8
CVE-2023-5165

Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via the debug shell which remains …

Fix: 4.23.0+
Fix from $1,950 2023-09-25
Docker Desktop MEDIUM 6.5
CVE-2023-5166

Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL. This issue affects Docker Desktop: before 4.23.0.

Fix: 4.23.0+
Fix from $1,600 2023-09-25
Docker Desktop CRITICAL 9.8
CVE-2023-0625

Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0.

Fix: 4.12.0+
Fix from $2,300 2023-09-25
Docker Desktop CRITICAL 9.8
CVE-2023-0626

Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route. This issue affects Docker Desktop: before 4.12.0.

Fix: 4.12.0+
Fix from $2,300 2023-09-25
Docker Desktop HIGH 7.8
CVE-2023-0627

Docker Desktop 4.11.x allows --no-windows-containers flag bypass via IPC response spoofing which may lead to Local Privilege Escalation (LPE).This is…

Fix: 4.12.0+
Fix from $1,950 2023-09-25
Docker Desktop HIGH 7.8
CVE-2023-0633

In Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in local privilege escalation (LPE).This issue affects Docke…

Fix: 4.12.0+
Fix from $1,950 2023-09-25
Desktop HIGH 7.8
CVE-2022-37326

Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 windowscontainers/start API by co…

Fix: 4.6.0+
Fix from $1,950 2023-04-27
Desktop HIGH 7.1
CVE-2022-34292

Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/create dockerBackendV2 API by c…

Fix: 4.6.0+
Fix from $1,950 2023-04-27
Desktop MEDIUM 6.3
CVE-2022-38730

Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerBackendV2 API by controlling t…

Fix: 4.6.0+
Fix from $1,600 2023-04-27
Desktop HIGH 7.1
CVE-2022-31647

Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 API via a symlink in the DataFo…

Fix: 4.6.0+
Fix from $1,950 2023-04-27
Desktop HIGH 7.5
CVE-2023-1802

In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failed.…

No fix yet
Fix from $1,950 2023-04-06
Docker Desktop HIGH 7.1
CVE-2023-0629

Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions by setting the Docker host to dock…

Fix: 4.17.0+
Fix from $1,950 2023-03-13