CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-79994 HIGH

Docker Sandboxes UDS forwarder can reach arbitrary host Unix sockets through a symlink race

CVSS 8.7 EPSS 0.14% Sep 15, 2026
CVE-2026-55887 HIGH

MCP Gateway: Argument injection via OCI image label YAML in Docker MCP Gateway

CVSS 8.7 EPSS 0.22% Sep 15, 2026
Go
CVE-2026-77179 CRITICAL

Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-fs stored-path fallback

CVSS 9.4 EPSS 0.20% Sep 15, 2026
CVE-2026-17106 HIGH

Tar extraction in moby/go-archive can write outside the destination directory via link following

CVSS 7.1 EPSS 0.44% Aug 18, 2026
Go
CVE-2026-18171 MEDIUM

Docker Sandboxes read-only runtime mount writable through its shared-export alias

CVSS 5.7 EPSS 0.14% Aug 12, 2026
CVE-2026-12539 MEDIUM

Docker Sandboxes ICMP egress restriction bypass after daemon restart

CVSS 5.7 EPSS 0.14% Jun 18, 2026
CVE-2026-12039 MEDIUM

Docker Sandboxes network egress allowlist bypass via unfiltered DNS resolution

CVSS 5.7 EPSS 0.10% Jun 18, 2026
CVE-2026-42306 HIGH

Moby: Race condition in docker cp allows bind mount redirection to host path

CVSS 7.2 EPSS 0.10% Jun 12, 2026
Go
CVE-2026-41568 MEDIUM

Moby: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap

CVSS 6.1 EPSS 0.10% Jun 12, 2026
Go
CVE-2026-41567 HIGH

Docker: `PUT /containers/{id}/archive` executes container binary on the host

CVSS 7.5 EPSS 0.17% Jun 5, 2026
Go
CVE-2026-8936 HIGH

Unbounded recursion in grpcfuse kernel module allows container to crash Docker Desktop VM

CVSS 8.2 EPSS 0.15% Jun 2, 2026
CVE-2026-5843 HIGH

Docker Model Runner container-to-host code execution via MLX-LM model_file importlib loading

CVSS 8.8 EPSS 0.18% May 22, 2026
CVE-2026-5817 HIGH

Docker Model Runner container-to-host code execution via unsandboxed trust_remote_code in Python inference backends

CVSS 8.8 EPSS 0.18% May 22, 2026
CVE-2026-6406 HIGH

Docker Desktop Enhanced Container Isolation bypass via --use-api-socket CLI flag

CVSS 8.8 EPSS 0.20% May 22, 2026
CVE-2026-33990 MEDIUM

Docker Model Runner OCI Registry Client Vulnerable to Server-Side Request Forgery (SSRF)

CVSS 6.8 EPSS 0.29% Apr 1, 2026
Go
CVE-2026-33997 HIGH

Moby: Off-by-one error in plugin privilege validation

CVSS 8.4 EPSS 0.51% Mar 31, 2026
Go
CVE-2026-34040 HIGH

Moby: AuthZ plugin bypass with oversized request body

CVSS 8.8 EPSS 0.16% Mar 31, 2026
Go
CVE-2025-15558 HIGH

Docker Desktop Docker Plugins Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

CVSS 7.0 EPSS 0.47% Mar 4, 2026
Go
CVE-2026-28400 HIGH

Docker Model Runner Unauthenticated Runtime Flag Injection via _configure Endpoint

CVSS 7.6 EPSS 0.17% Feb 27, 2026
CVE-2026-2664 MEDIUM

Out of bounds read vulnerability in grpcfuse kernel module

CVSS 6.8 EPSS 0.19% Feb 24, 2026
CVE-2025-14740 MEDIUM

Docker Desktop for Windows Incorrect Permission Assignment Privilege Escalation Vulnerabilities

CVSS 6.7 EPSS 0.21% Feb 4, 2026
CVE-2025-13743 LOW

Expired Personal Access Tokens (PATs) are recorded in Docker Desktop diagnostic logs

CVSS 2.4 EPSS 0.21% Dec 9, 2025
CVE-2025-64443 HIGH

DNS Rebinding vulnerability present when running MCP Gateway in sse or streaming mode

CVSS 7.3 EPSS 0.43% Dec 3, 2025
Go
CVE-2025-62725 HIGH

Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations

CVSS 8.9 EPSS 13.70% Oct 27, 2025
Go
CVE-2025-9164 HIGH

Multiple DLL Search Order Hijacking Vulnerabilities in Docker Desktop Installer for Windows

CVSS 8.8 EPSS 0.11% Oct 27, 2025

Showing 1 to 25 CVEs · page 1 (more available)