28,678 Entries 2,229 Sources 5 Verticals Last sync 3 minutes Live
Dashboard/ OS & platform/ Docker Engine
OS & platform

Docker Engine

Docker
CVE-2026-40871 latest release
06.06.2026
Specsattributes
eol_productdocker-engine
Timelinealle Einträge
Type Ereignis · Quelle Value · Time
CVE
OS & platform High

A vulnerability in the Mailcow email software allows attackers to inject malicious code into the database that gets executed later during quarantine notifications, potentially exposing sensitive data like administrator credentials.

CVE-2026-40871
06.06.2026
CVE
OS & platform High

A vulnerability in Neko software (virtual browser running in Docker) allows any authenticated user to immediately gain full administrative control over the entire instance, resulting in complete compromise of the system.

CVE-2026-39386
06.06.2026
CVE
OS & platform Medium

A security vulnerability in OpenClaw allows attackers to bypass security controls by overriding environment variables, thereby circumventing proxy settings, TLS verification, and Docker restrictions.

CVE-2026-41330
06.06.2026
CVE
OS & platform Critical

A critical security vulnerability in Flowsint, an OSINT analysis tool, allows attackers to execute arbitrary system commands as administrator by injecting special characters into organization nodes and escaping from Docker containers.

CVE-2026-32311
06.06.2026
CVE
OS & platform High

A vulnerability in Arcane, a Docker management interface, allows attackers to make the server send HTTP requests to arbitrary URLs and receive the responses without requiring authentication.

CVE-2026-40242
06.06.2026
CVE
OS & platform Medium

A vulnerability in the Docker management application Dockyard allows attackers to start or stop containers through malicious links when clicked by an administrator.

CVE-2026-39848
06.06.2026
CVE
OS & platform Critical

A vulnerability in Sonicverse Radio software allows authenticated users to make arbitrary HTTP requests from the server to internal or external systems, potentially exposing sensitive data or attacking internal services.

CVE-2026-40089
06.06.2026
CVE
OS & platform High

A vulnerability in suvarchal docker-mcp-server allows attackers to inject and execute malicious operating system commands through the HTTP interface. This can lead to complete system compromise.

CVE-2026-5741
06.06.2026
CVE
OS & platform High

A vulnerability in the BentoML Python library allows attackers to execute malicious code on the host system when users import a manipulated bento archive and containerize it.

CVE-2026-35044
06.06.2026
CVE
OS & platform Critical

A vulnerability in Aperi'Solve allows attackers to execute arbitrary code and gain full server control through unsanitized password inputs when uploading JPEG files.

CVE-2026-34977
06.06.2026
CVE
OS & platform Critical

A vulnerability in the Kestra orchestration platform allows authenticated users to execute arbitrary commands on the server by visiting a crafted link.

CVE-2026-34612
06.06.2026
CVE
OS & platform Critical

Docker Model Runner has a vulnerability that allows attackers to target internal network services and steal their data by using malicious container registries.

CVE-2026-33990
06.06.2026
CVE
OS & platform Medium

A vulnerability in the Claude SDK for Python stored files with insecure permissions, allowing local attackers on shared systems to read sensitive data or manipulate AI model behavior in Docker environments.

CVE-2026-34450
06.06.2026
CVE
OS & platform High

A security vulnerability in Admidio (not Docker Engine) allows attackers to access uploaded documents without authentication via HTTP, because the Apache configuration in the Docker image ignores access restrictions.

CVE-2026-34381
06.06.2026
CVE
OS & platform High

A security vulnerability in the act software (not Docker Engine) allows network attackers to create malicious cache files and retrieve existing caches, potentially leading to malicious code execution within Docker containers.

CVE-2026-34042
06.06.2026
CVE
OS & platform Medium

Docker Engine has a vulnerability in plugin installation where permission checks can be bypassed. The system incorrectly accepts different privileges than those approved by the user, potentially allowing plugins to gain extended system access.

CVE-2026-33997
06.06.2026
CVE
OS & platform Critical

CrewAI fails to properly verify if Docker is still running during execution and falls back to insecure sandbox settings that allow attackers to execute arbitrary code.

CVE-2026-2287
06.06.2026
CVE
OS & platform Critical

A flaw in CrewAI CodeInterpreter allows execution of arbitrary C functions when Docker is unavailable and the system falls back to SandboxPython, potentially leading to complete system compromise.

CVE-2026-2275
06.06.2026
CVE
OS & platform Critical

A vulnerability in Home Assistant allows devices on the local network to access internal endpoints without authentication that should have been protected.

CVE-2026-34205
06.06.2026
CVE
OS & platform Medium

Wazuh installation scripts and Docker files use insecure downloads without SSL certificate validation, allowing network attackers to inject malicious code and compromise the software supply chain.

CVE-2025-15612
06.06.2026
CVE
OS & platform High

A vulnerability in Docker BuildKit allows attackers to access files outside the intended repository directory through manipulated Git URLs, potentially exposing sensitive data from the same filesystem.

CVE-2026-33748
06.06.2026
CVE
OS & platform High

A vulnerability in the BentoML Python library allows attackers to execute arbitrary commands during Docker container creation by inserting malicious values into the configuration file.

CVE-2026-33744
06.06.2026
CVE
OS & platform Medium

A vulnerability in the Zabbix Agent 2 Docker plugin allows attackers to read arbitrary files from running Docker containers by injecting malicious parameters into the Docker API.

CVE-2026-23924
06.06.2026
CVE
OS & platform High

A vulnerability in FastGPT allows external contributors to execute malicious code and steal secrets by injecting manipulated Docker containers through pull requests.

CVE-2026-33075
06.06.2026
CVE
OS & platform High

The AVideo video platform ships with the default admin password "password" that is automatically used during installation. Attackers can immediately gain full control over unprotected installations and steal user data or execute malicious code.

CVE-2026-33037
06.06.2026
CVE
OS & platform Critical

A critical vulnerability in Docker Engine allows trusted users to bypass network isolation between containers and access services in other container networks.

CVE-2026-32038
06.06.2026
CVE
OS & platform High

A vulnerability in SiYuan (not Docker Engine) allows administrators to write files to arbitrary system locations, potentially leading to data destruction or complete system compromise.

CVE-2026-32749
06.06.2026
CVE
OS & platform Medium

SiYuan, a knowledge management system, allows administrators to copy and read sensitive files like Docker secrets or system files outside the intended workspace through an inadequately secured API.

CVE-2026-32747
06.06.2026
CVE
OS & platform Medium

A vulnerability in Softing smartLinks software on Docker allows unauthorized access to system files through improper URL validation in the webserver component.

CVE-2025-10461
06.06.2026
CVE
OS & platform Medium

OneUptime software logs password reset links containing secret tokens in standard log files, allowing attackers with log access to take over other users' accounts.

CVE-2026-32598
06.06.2026
CVE
OS & platform Critical

A vulnerability in the Dagu workflow engine allows attackers to delete critical system files through manipulated path inputs, potentially causing complete system failure.

CVE-2026-31886
06.06.2026
CVE
OS & platform High

LinkAce, a self-hosted link archiving software, allows attackers to access internal network resources and cloud metadata through the link creation feature due to missing validation of private IP addresses.

CVE-2026-30953
06.06.2026
CVE
OS & platform Medium

WeKnora, an AI framework for document processing, has a security flaw in its URL import feature that allows attackers to access internal server services through redirects and potentially retrieve confidential data.

CVE-2026-30247
06.06.2026
CVE
OS & platform High

A vulnerability in AVideo's Docker configuration exposes the Memcached service without authentication over the internet, allowing attackers to manipulate user sessions and hijack administrator accounts.

CVE-2026-29093
06.06.2026
CVE
OS & platform High

A vulnerability in OpenClaw allows attackers to manipulate the cache through SHA-1 collisions, causing sandbox configurations to be swapped and enabling reuse of unsafe states.

CVE-2026-28479
06.06.2026
CVE
OS & platform High

Docker CLI for Windows searches for plugin files in a directory that doesn't exist by default, allowing low-privileged attackers to place malicious plugins that get executed when using Docker, potentially enabling privilege escalation.

CVE-2025-15558
06.06.2026
CVE
OS & platform High

A flaw in the kaniko container build tool allows attackers to write files outside the intended directory, which can lead to code execution in certain environments.

CVE-2026-28406
06.06.2026
CVE
OS & platform High

Docker Model Runner has a vulnerability that allows attackers to overwrite or create arbitrary files without authentication. This can lead to destruction of all Docker containers and data, or in certain cases even enable container escapes.

CVE-2026-28400
06.06.2026
CVE
OS & platform Low

A vulnerability in Canarytokens allows attackers to inject malicious JavaScript code into PWA tokens that executes when someone visits the installation page, though no sensitive data is exposed.

CVE-2026-28355
06.06.2026
CVE
OS & platform Medium

A vulnerability in the Beszel server monitoring platform allows authenticated users to access arbitrary Docker API endpoints through manipulated parameters, potentially exposing sensitive infrastructure information.

CVE-2026-27734
06.06.2026
CVE
OS & platform High

A vulnerability in WireGuard Portal allows regular users to grant themselves administrator privileges by modifying their profile data with a specific parameter.

CVE-2026-27899
06.06.2026
CVE
OS & platform Critical

A security vulnerability in an API gateway deployment tool allows attackers to execute arbitrary commands with root privileges and potentially escape the container to compromise the underlying infrastructure.

CVE-2026-27208
06.06.2026
CVE
OS & platform High

A vulnerability in Docker Desktop's grpcfuse kernel module allows local attackers to read memory outside intended boundaries by writing to specific system files, potentially causing unspecified damage to the system.

CVE-2026-2664
06.06.2026
CVE
OS & platform High

BigBlueButton software contains flawed documentation that instructs administrators to unsafely configure an antivirus scanner service, allowing attackers to overload or crash the server.

CVE-2026-27466
06.06.2026
CVE
OS & platform Low

A vulnerability in OpenClaw (not Docker Engine) causes changes in configuration setting order to go undetected, potentially leading to continued use of outdated containers.

CVE-2026-27007
06.06.2026
CVE
OS & platform Critical

A vulnerability in OpenClaw (an AI assistant) allows attackers to inject dangerous Docker settings, enabling containers to escape their sandbox and access the host system.

CVE-2026-27002
06.06.2026
CVE
OS & platform Medium

A security vulnerability in Trivy Action (GitHub tool for scanning Docker images) allows attackers to execute arbitrary commands when user-controlled inputs are improperly processed.

CVE-2026-26189
06.06.2026
CVE
OS & platform Low

A vulnerability in Keycloak allows disabled Docker registry clients to continue receiving authentication tokens, bypassing administrative controls and potentially enabling unintended access to container registry resources.

CVE-2026-2733
06.06.2026
CVE
OS & platform High

A security flaw in Crawl4AI before version 0.8.0 allows attackers to read arbitrary files from the server by sending special URLs to certain endpoints, potentially stealing sensitive data like passwords or API keys.

CVE-2026-26217
06.06.2026
CVE
OS & platform Critical

A vulnerability in Crawl4AI (not Docker Engine) allows attackers to execute arbitrary Python code through a web interface, potentially leading to complete server takeover.

CVE-2026-26216
06.06.2026
CVE
OS & platform High

OpenFGA, an authorization engine, has a flaw in versions 1.8.5 to 1.11.2 that causes improper policy enforcement, potentially allowing incorrect permission checks under specific conditions.

CVE-2026-24851
06.06.2026
EOL
OS & platform

Current / stable

29
10.11.2025
EOL
OS & platform

EOL 2026-05-13

28
20.02.2025
EOL
OS & platform

EOL 2025-05-03

27
25.06.2024
EOL
OS & platform

EOL 2025-02-17

26.1
22.04.2024
EOL
OS & platform

EOL 2024-06-08

26.0
20.03.2024
EOL
OS & platform

Current / stable

25.0
19.01.2024
EOL
OS & platform

EOL 2024-06-08

24.0
16.05.2023
EOL
OS & platform

EOL 2025-05-19

23.0
02.02.2023
EOL
OS & platform

EOL 2023-12-10

20.10
09.12.2020
EOL
OS & platform

EOL 2021-01-08

19.03
22.07.2019
EOL
OS & platform

EOL 2019-08-22

18.09
08.11.2018
EOL
OS & platform

EOL 2018-12-08

18.06
18.07.2018
EOL
OS & platform

EOL 2018-08-18

18.05
25.04.2018
EOL
OS & platform

EOL 2018-06-09

18.04
27.03.2018
EOL
OS & platform

EOL 2018-05-10

18.03
14.03.2018
EOL
OS & platform

EOL 2018-04-21

18.02
26.01.2018
EOL
OS & platform

EOL 2018-02-10

17.12
15.12.2017
EOL
OS & platform

EOL 2018-03-07

18.01
12.12.2017
EOL
OS & platform

EOL 2018-01-27

17.11
17.11.2017
EOL
OS & platform

EOL 2017-12-20

17.10
13.10.2017
EOL
OS & platform

EOL 2017-11-17

17.09
22.09.2017
EOL
OS & platform

EOL 2017-10-26

17.07
28.08.2017
EOL
OS & platform

EOL 2017-09-29

17.06
20.06.2017
EOL
OS & platform

EOL 2017-07-28

17.05
04.05.2017
EOL
OS & platform

EOL 2017-06-04

17.04
03.04.2017
EOL
OS & platform

EOL 2017-05-05

17.03
23.02.2017