Sicherheit
Security
All tracked CVEs and security advisories — sorted by date or severity. Each entry links to the official source. The plain-text explanations are generated automatically — the source remains authoritative.
| CVE / GHSA | Item | Vertical | Severity | Date |
|---|---|---|---|---|
| CVE-2026-33997 Source Docker Engine has a vulnerability in plugin installation where permission checks can be bypassed. The system incorrectly accepts different privileges than those approved by the user, potentially allowing plugins to gain extended system access. |
Docker Engine | OS & platform | Medium | 06.06.2026 |
| CVE-2026-2287 Source CrewAI fails to properly verify if Docker is still running during execution and falls back to insecure sandbox settings that allow attackers to execute arbitrary code. |
Docker Engine | OS & platform | Critical | 06.06.2026 |
| CVE-2026-2275 Source A flaw in CrewAI CodeInterpreter allows execution of arbitrary C functions when Docker is unavailable and the system falls back to SandboxPython, potentially leading to complete system compromise. |
Docker Engine | OS & platform | Critical | 06.06.2026 |
| CVE-2026-34205 Source A vulnerability in Home Assistant allows devices on the local network to access internal endpoints without authentication that should have been protected. |
Docker Engine | OS & platform | Critical | 06.06.2026 |
| CVE-2025-15612 Source Wazuh installation scripts and Docker files use insecure downloads without SSL certificate validation, allowing network attackers to inject malicious code and compromise the software supply chain. |
Docker Engine | OS & platform | Medium | 06.06.2026 |
| CVE-2026-33748 Source A vulnerability in Docker BuildKit allows attackers to access files outside the intended repository directory through manipulated Git URLs, potentially exposing sensitive data from the same filesystem. |
Docker Engine | OS & platform | High | 06.06.2026 |
| CVE-2026-33744 Source A vulnerability in the BentoML Python library allows attackers to execute arbitrary commands during Docker container creation by inserting malicious values into the configuration file. |
Docker Engine | OS & platform | High | 06.06.2026 |
| CVE-2026-23924 Source A vulnerability in the Zabbix Agent 2 Docker plugin allows attackers to read arbitrary files from running Docker containers by injecting malicious parameters into the Docker API. |
Docker Engine | OS & platform | Medium | 06.06.2026 |
| CVE-2026-33075 Source A vulnerability in FastGPT allows external contributors to execute malicious code and steal secrets by injecting manipulated Docker containers through pull requests. |
Docker Engine | OS & platform | High | 06.06.2026 |
| CVE-2026-33037 Source The AVideo video platform ships with the default admin password "password" that is automatically used during installation. Attackers can immediately gain full control over unprotected installations and steal user data or execute malicious code. |
Docker Engine | OS & platform | High | 06.06.2026 |
| CVE-2026-32038 Source A critical vulnerability in Docker Engine allows trusted users to bypass network isolation between containers and access services in other container networks. |
Docker Engine | OS & platform | Critical | 06.06.2026 |
| CVE-2026-32749 Source A vulnerability in SiYuan (not Docker Engine) allows administrators to write files to arbitrary system locations, potentially leading to data destruction or complete system compromise. |
Docker Engine | OS & platform | High | 06.06.2026 |
| CVE-2026-32747 Source SiYuan, a knowledge management system, allows administrators to copy and read sensitive files like Docker secrets or system files outside the intended workspace through an inadequately secured API. |
Docker Engine | OS & platform | Medium | 06.06.2026 |
| CVE-2025-10461 Source A vulnerability in Softing smartLinks software on Docker allows unauthorized access to system files through improper URL validation in the webserver component. |
Docker Engine | OS & platform | Medium | 06.06.2026 |
| CVE-2026-32598 Source OneUptime software logs password reset links containing secret tokens in standard log files, allowing attackers with log access to take over other users' accounts. |
Docker Engine | OS & platform | Medium | 06.06.2026 |
| CVE-2026-31886 Source A vulnerability in the Dagu workflow engine allows attackers to delete critical system files through manipulated path inputs, potentially causing complete system failure. |
Docker Engine | OS & platform | Critical | 06.06.2026 |
| CVE-2026-30953 Source LinkAce, a self-hosted link archiving software, allows attackers to access internal network resources and cloud metadata through the link creation feature due to missing validation of private IP addresses. |
Docker Engine | OS & platform | High | 06.06.2026 |
| CVE-2026-30247 Source WeKnora, an AI framework for document processing, has a security flaw in its URL import feature that allows attackers to access internal server services through redirects and potentially retrieve confidential data. |
Docker Engine | OS & platform | Medium | 06.06.2026 |
| CVE-2026-29093 Source A vulnerability in AVideo's Docker configuration exposes the Memcached service without authentication over the internet, allowing attackers to manipulate user sessions and hijack administrator accounts. |
Docker Engine | OS & platform | High | 06.06.2026 |
| CVE-2026-28479 Source A vulnerability in OpenClaw allows attackers to manipulate the cache through SHA-1 collisions, causing sandbox configurations to be swapped and enabling reuse of unsafe states. |
Docker Engine | OS & platform | High | 06.06.2026 |
| CVE-2025-15558 Source Docker CLI for Windows searches for plugin files in a directory that doesn't exist by default, allowing low-privileged attackers to place malicious plugins that get executed when using Docker, potentially enabling privilege escalation. |
Docker Engine | OS & platform | High | 06.06.2026 |
| CVE-2026-28406 Source A flaw in the kaniko container build tool allows attackers to write files outside the intended directory, which can lead to code execution in certain environments. |
Docker Engine | OS & platform | High | 06.06.2026 |
| CVE-2026-28400 Source Docker Model Runner has a vulnerability that allows attackers to overwrite or create arbitrary files without authentication. This can lead to destruction of all Docker containers and data, or in certain cases even enable container escapes. |
Docker Engine | OS & platform | High | 06.06.2026 |
| CVE-2026-28355 Source A vulnerability in Canarytokens allows attackers to inject malicious JavaScript code into PWA tokens that executes when someone visits the installation page, though no sensitive data is exposed. |
Docker Engine | OS & platform | Low | 06.06.2026 |
| CVE-2026-27734 Source A vulnerability in the Beszel server monitoring platform allows authenticated users to access arbitrary Docker API endpoints through manipulated parameters, potentially exposing sensitive infrastructure information. |
Docker Engine | OS & platform | Medium | 06.06.2026 |
| CVE-2026-27899 Source A vulnerability in WireGuard Portal allows regular users to grant themselves administrator privileges by modifying their profile data with a specific parameter. |
Docker Engine | OS & platform | High | 06.06.2026 |
| CVE-2026-27208 Source A security vulnerability in an API gateway deployment tool allows attackers to execute arbitrary commands with root privileges and potentially escape the container to compromise the underlying infrastructure. |
Docker Engine | OS & platform | Critical | 06.06.2026 |
| CVE-2026-2664 Source A vulnerability in Docker Desktop's grpcfuse kernel module allows local attackers to read memory outside intended boundaries by writing to specific system files, potentially causing unspecified damage to the system. |
Docker Engine | OS & platform | High | 06.06.2026 |
| CVE-2026-27466 Source BigBlueButton software contains flawed documentation that instructs administrators to unsafely configure an antivirus scanner service, allowing attackers to overload or crash the server. |
Docker Engine | OS & platform | High | 06.06.2026 |
| CVE-2026-27007 Source A vulnerability in OpenClaw (not Docker Engine) causes changes in configuration setting order to go undetected, potentially leading to continued use of outdated containers. |
Docker Engine | OS & platform | Low | 06.06.2026 |
| CVE-2026-27002 Source A vulnerability in OpenClaw (an AI assistant) allows attackers to inject dangerous Docker settings, enabling containers to escape their sandbox and access the host system. |
Docker Engine | OS & platform | Critical | 06.06.2026 |
| CVE-2026-26189 Source A security vulnerability in Trivy Action (GitHub tool for scanning Docker images) allows attackers to execute arbitrary commands when user-controlled inputs are improperly processed. |
Docker Engine | OS & platform | Medium | 06.06.2026 |
| CVE-2026-2733 Source A vulnerability in Keycloak allows disabled Docker registry clients to continue receiving authentication tokens, bypassing administrative controls and potentially enabling unintended access to container registry resources. |
Docker Engine | OS & platform | Low | 06.06.2026 |
| CVE-2026-26217 Source A security flaw in Crawl4AI before version 0.8.0 allows attackers to read arbitrary files from the server by sending special URLs to certain endpoints, potentially stealing sensitive data like passwords or API keys. |
Docker Engine | OS & platform | High | 06.06.2026 |
| CVE-2026-26216 Source A vulnerability in Crawl4AI (not Docker Engine) allows attackers to execute arbitrary Python code through a web interface, potentially leading to complete server takeover. |
Docker Engine | OS & platform | Critical | 06.06.2026 |
| CVE-2026-24851 Source OpenFGA, an authorization engine, has a flaw in versions 1.8.5 to 1.11.2 that causes improper policy enforcement, potentially allowing incorrect permission checks under specific conditions. |
Docker Engine | OS & platform | High | 06.06.2026 |
| CVE-2025-5088 Source A vulnerability in Redis allows authenticated attackers to gain full root access to all servers in a CVX cluster if they have network access and the Redis password. |
Redis | OS & platform | High | 06.06.2026 |
| CVE-2026-45679 Source A vulnerability in OpenTelemetry eBPF instrumentation for Redis causes error messages to be transmitted unfiltered to telemetry systems, potentially exposing confidential data or attacker-controlled content to monitoring backends. |
Redis | OS & platform | Medium | 06.06.2026 |
| CVE-2026-46424 Source In the Budibase low-code platform, user permissions are not immediately removed from Redis cache after role revocation, allowing users to retain access to functions they should no longer have privileges for up to one hour. |
Redis | OS & platform | Medium | 06.06.2026 |
| CVE-2024-11399 Source A vulnerability in the Redis server component of Synology BeeDrive for desktop allows local users to access certain files or directories to perform denial-of-service attacks and crash the service. |
Redis | OS & platform | Medium | 06.06.2026 |
| CVE-2026-48847 Source A vulnerability in Roundcube Webmail allows attackers to delete arbitrary files without authentication by manipulating session data in Redis or Memcache storage systems. |
Redis | OS & platform | Low | 06.06.2026 |
| CVE-2026-9357 Source | Redis | OS & platform | Low | 06.06.2026 |
| CVE-2026-48172 Source A security vulnerability in the LiteSpeed User-End cPanel Plugin allows attackers to escalate their privileges and potentially gain full system control, which has already been actively exploited. |
Redis | OS & platform | Critical | 06.06.2026 |
| CVE-2026-33233 Source AutoGPT, an AI workflow platform, unsafely deserializes data from Redis cache without integrity checks. Attackers can execute arbitrary code by manipulating the cache. |
Redis | OS & platform | High | 06.06.2026 |
| CVE-2026-44552 Source A vulnerability in Open WebUI before version 0.9.0 causes configuration settings from different instances to overwrite each other when sharing Redis databases, potentially exposing users to incorrect server configurations from other instances. |
Redis | OS & platform | High | 06.06.2026 |
| CVE-2026-42586 Source A vulnerability in the Netty library allows attackers to inject malicious Redis commands by using special control characters in messages that are not properly filtered. |
Redis | OS & platform | Medium | 06.06.2026 |
| CVE-2026-42865 Source In the Inbox Zero email software, a Redis implementation flaw can cause email thread events from one user to be incorrectly delivered to another logged-in user, leading to unauthorized data access. |
Redis | OS & platform | Medium | 06.06.2026 |
| CVE-2026-25589 Source A vulnerability in the RedisBloom module for Redis allows authenticated attackers to trigger memory errors and potentially execute malicious code by providing crafted data through the RESTORE command. affects: <2.8.20 |
Redis | OS & platform | High | 06.06.2026 |
| CVE-2026-25588 Source A vulnerability in the RedisTimeSeries module for Redis allows authenticated attackers to trigger memory errors and potentially execute malicious code by providing crafted data through the RESTORE command. affects: <1.12.14 |
Redis | OS & platform | High | 06.06.2026 |
| CVE-2026-25243 Source Redis database has a vulnerability in the RESTORE command that doesn't properly validate incoming data. Attackers with access can send malicious data and potentially execute arbitrary code on the server. affects: <8.6.3 |
Redis | OS & platform | High | 06.06.2026 |