34,335 Entries 2,249 Sources 5 Verticals Last sync 15 minutes Live
Dashboard/Security
Sicherheit

Security

All tracked CVEs and security advisories — sorted by date or severity. Each entry links to the official source. The plain-text explanations are generated automatically — the source remains authoritative.

Sort: Newest Severity
CVE / GHSAItemVerticalSeverityDate
CVE-2026-33997 Source
Docker Engine has a vulnerability in plugin installation where permission checks can be bypassed. The system incorrectly accepts different privileges than those approved by the user, potentially allowing plugins to gain extended system access.
Docker Engine OS & platform Medium 06.06.2026
CVE-2026-2287 Source
CrewAI fails to properly verify if Docker is still running during execution and falls back to insecure sandbox settings that allow attackers to execute arbitrary code.
Docker Engine OS & platform Critical 06.06.2026
CVE-2026-2275 Source
A flaw in CrewAI CodeInterpreter allows execution of arbitrary C functions when Docker is unavailable and the system falls back to SandboxPython, potentially leading to complete system compromise.
Docker Engine OS & platform Critical 06.06.2026
CVE-2026-34205 Source
A vulnerability in Home Assistant allows devices on the local network to access internal endpoints without authentication that should have been protected.
Docker Engine OS & platform Critical 06.06.2026
CVE-2025-15612 Source
Wazuh installation scripts and Docker files use insecure downloads without SSL certificate validation, allowing network attackers to inject malicious code and compromise the software supply chain.
Docker Engine OS & platform Medium 06.06.2026
CVE-2026-33748 Source
A vulnerability in Docker BuildKit allows attackers to access files outside the intended repository directory through manipulated Git URLs, potentially exposing sensitive data from the same filesystem.
Docker Engine OS & platform High 06.06.2026
CVE-2026-33744 Source
A vulnerability in the BentoML Python library allows attackers to execute arbitrary commands during Docker container creation by inserting malicious values into the configuration file.
Docker Engine OS & platform High 06.06.2026
CVE-2026-23924 Source
A vulnerability in the Zabbix Agent 2 Docker plugin allows attackers to read arbitrary files from running Docker containers by injecting malicious parameters into the Docker API.
Docker Engine OS & platform Medium 06.06.2026
CVE-2026-33075 Source
A vulnerability in FastGPT allows external contributors to execute malicious code and steal secrets by injecting manipulated Docker containers through pull requests.
Docker Engine OS & platform High 06.06.2026
CVE-2026-33037 Source
The AVideo video platform ships with the default admin password "password" that is automatically used during installation. Attackers can immediately gain full control over unprotected installations and steal user data or execute malicious code.
Docker Engine OS & platform High 06.06.2026
CVE-2026-32038 Source
A critical vulnerability in Docker Engine allows trusted users to bypass network isolation between containers and access services in other container networks.
Docker Engine OS & platform Critical 06.06.2026
CVE-2026-32749 Source
A vulnerability in SiYuan (not Docker Engine) allows administrators to write files to arbitrary system locations, potentially leading to data destruction or complete system compromise.
Docker Engine OS & platform High 06.06.2026
CVE-2026-32747 Source
SiYuan, a knowledge management system, allows administrators to copy and read sensitive files like Docker secrets or system files outside the intended workspace through an inadequately secured API.
Docker Engine OS & platform Medium 06.06.2026
CVE-2025-10461 Source
A vulnerability in Softing smartLinks software on Docker allows unauthorized access to system files through improper URL validation in the webserver component.
Docker Engine OS & platform Medium 06.06.2026
CVE-2026-32598 Source
OneUptime software logs password reset links containing secret tokens in standard log files, allowing attackers with log access to take over other users' accounts.
Docker Engine OS & platform Medium 06.06.2026
CVE-2026-31886 Source
A vulnerability in the Dagu workflow engine allows attackers to delete critical system files through manipulated path inputs, potentially causing complete system failure.
Docker Engine OS & platform Critical 06.06.2026
CVE-2026-30953 Source
LinkAce, a self-hosted link archiving software, allows attackers to access internal network resources and cloud metadata through the link creation feature due to missing validation of private IP addresses.
Docker Engine OS & platform High 06.06.2026
CVE-2026-30247 Source
WeKnora, an AI framework for document processing, has a security flaw in its URL import feature that allows attackers to access internal server services through redirects and potentially retrieve confidential data.
Docker Engine OS & platform Medium 06.06.2026
CVE-2026-29093 Source
A vulnerability in AVideo's Docker configuration exposes the Memcached service without authentication over the internet, allowing attackers to manipulate user sessions and hijack administrator accounts.
Docker Engine OS & platform High 06.06.2026
CVE-2026-28479 Source
A vulnerability in OpenClaw allows attackers to manipulate the cache through SHA-1 collisions, causing sandbox configurations to be swapped and enabling reuse of unsafe states.
Docker Engine OS & platform High 06.06.2026
CVE-2025-15558 Source
Docker CLI for Windows searches for plugin files in a directory that doesn't exist by default, allowing low-privileged attackers to place malicious plugins that get executed when using Docker, potentially enabling privilege escalation.
Docker Engine OS & platform High 06.06.2026
CVE-2026-28406 Source
A flaw in the kaniko container build tool allows attackers to write files outside the intended directory, which can lead to code execution in certain environments.
Docker Engine OS & platform High 06.06.2026
CVE-2026-28400 Source
Docker Model Runner has a vulnerability that allows attackers to overwrite or create arbitrary files without authentication. This can lead to destruction of all Docker containers and data, or in certain cases even enable container escapes.
Docker Engine OS & platform High 06.06.2026
CVE-2026-28355 Source
A vulnerability in Canarytokens allows attackers to inject malicious JavaScript code into PWA tokens that executes when someone visits the installation page, though no sensitive data is exposed.
Docker Engine OS & platform Low 06.06.2026
CVE-2026-27734 Source
A vulnerability in the Beszel server monitoring platform allows authenticated users to access arbitrary Docker API endpoints through manipulated parameters, potentially exposing sensitive infrastructure information.
Docker Engine OS & platform Medium 06.06.2026
CVE-2026-27899 Source
A vulnerability in WireGuard Portal allows regular users to grant themselves administrator privileges by modifying their profile data with a specific parameter.
Docker Engine OS & platform High 06.06.2026
CVE-2026-27208 Source
A security vulnerability in an API gateway deployment tool allows attackers to execute arbitrary commands with root privileges and potentially escape the container to compromise the underlying infrastructure.
Docker Engine OS & platform Critical 06.06.2026
CVE-2026-2664 Source
A vulnerability in Docker Desktop's grpcfuse kernel module allows local attackers to read memory outside intended boundaries by writing to specific system files, potentially causing unspecified damage to the system.
Docker Engine OS & platform High 06.06.2026
CVE-2026-27466 Source
BigBlueButton software contains flawed documentation that instructs administrators to unsafely configure an antivirus scanner service, allowing attackers to overload or crash the server.
Docker Engine OS & platform High 06.06.2026
CVE-2026-27007 Source
A vulnerability in OpenClaw (not Docker Engine) causes changes in configuration setting order to go undetected, potentially leading to continued use of outdated containers.
Docker Engine OS & platform Low 06.06.2026
CVE-2026-27002 Source
A vulnerability in OpenClaw (an AI assistant) allows attackers to inject dangerous Docker settings, enabling containers to escape their sandbox and access the host system.
Docker Engine OS & platform Critical 06.06.2026
CVE-2026-26189 Source
A security vulnerability in Trivy Action (GitHub tool for scanning Docker images) allows attackers to execute arbitrary commands when user-controlled inputs are improperly processed.
Docker Engine OS & platform Medium 06.06.2026
CVE-2026-2733 Source
A vulnerability in Keycloak allows disabled Docker registry clients to continue receiving authentication tokens, bypassing administrative controls and potentially enabling unintended access to container registry resources.
Docker Engine OS & platform Low 06.06.2026
CVE-2026-26217 Source
A security flaw in Crawl4AI before version 0.8.0 allows attackers to read arbitrary files from the server by sending special URLs to certain endpoints, potentially stealing sensitive data like passwords or API keys.
Docker Engine OS & platform High 06.06.2026
CVE-2026-26216 Source
A vulnerability in Crawl4AI (not Docker Engine) allows attackers to execute arbitrary Python code through a web interface, potentially leading to complete server takeover.
Docker Engine OS & platform Critical 06.06.2026
CVE-2026-24851 Source
OpenFGA, an authorization engine, has a flaw in versions 1.8.5 to 1.11.2 that causes improper policy enforcement, potentially allowing incorrect permission checks under specific conditions.
Docker Engine OS & platform High 06.06.2026
CVE-2025-5088 Source
A vulnerability in Redis allows authenticated attackers to gain full root access to all servers in a CVX cluster if they have network access and the Redis password.
Redis OS & platform High 06.06.2026
CVE-2026-45679 Source
A vulnerability in OpenTelemetry eBPF instrumentation for Redis causes error messages to be transmitted unfiltered to telemetry systems, potentially exposing confidential data or attacker-controlled content to monitoring backends.
Redis OS & platform Medium 06.06.2026
CVE-2026-46424 Source
In the Budibase low-code platform, user permissions are not immediately removed from Redis cache after role revocation, allowing users to retain access to functions they should no longer have privileges for up to one hour.
Redis OS & platform Medium 06.06.2026
CVE-2024-11399 Source
A vulnerability in the Redis server component of Synology BeeDrive for desktop allows local users to access certain files or directories to perform denial-of-service attacks and crash the service.
Redis OS & platform Medium 06.06.2026
CVE-2026-48847 Source
A vulnerability in Roundcube Webmail allows attackers to delete arbitrary files without authentication by manipulating session data in Redis or Memcache storage systems.
Redis OS & platform Low 06.06.2026
CVE-2026-9357 Source Redis OS & platform Low 06.06.2026
CVE-2026-48172 Source
A security vulnerability in the LiteSpeed User-End cPanel Plugin allows attackers to escalate their privileges and potentially gain full system control, which has already been actively exploited.
Redis OS & platform Critical 06.06.2026
CVE-2026-33233 Source
AutoGPT, an AI workflow platform, unsafely deserializes data from Redis cache without integrity checks. Attackers can execute arbitrary code by manipulating the cache.
Redis OS & platform High 06.06.2026
CVE-2026-44552 Source
A vulnerability in Open WebUI before version 0.9.0 causes configuration settings from different instances to overwrite each other when sharing Redis databases, potentially exposing users to incorrect server configurations from other instances.
Redis OS & platform High 06.06.2026
CVE-2026-42586 Source
A vulnerability in the Netty library allows attackers to inject malicious Redis commands by using special control characters in messages that are not properly filtered.
Redis OS & platform Medium 06.06.2026
CVE-2026-42865 Source
In the Inbox Zero email software, a Redis implementation flaw can cause email thread events from one user to be incorrectly delivered to another logged-in user, leading to unauthorized data access.
Redis OS & platform Medium 06.06.2026
CVE-2026-25589 Source
A vulnerability in the RedisBloom module for Redis allows authenticated attackers to trigger memory errors and potentially execute malicious code by providing crafted data through the RESTORE command.
affects: <2.8.20
Redis OS & platform High 06.06.2026
CVE-2026-25588 Source
A vulnerability in the RedisTimeSeries module for Redis allows authenticated attackers to trigger memory errors and potentially execute malicious code by providing crafted data through the RESTORE command.
affects: <1.12.14
Redis OS & platform High 06.06.2026
CVE-2026-25243 Source
Redis database has a vulnerability in the RESTORE command that doesn't properly validate incoming data. Attackers with access can send malicious data and potentially execute arbitrary code on the server.
affects: <8.6.3
Redis OS & platform High 06.06.2026