CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
Docker Sandboxes UDS forwarder can reach arbitrary host Unix sockets through a symlink race
MCP Gateway: Argument injection via OCI image label YAML in Docker MCP Gateway
Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-fs stored-path fallback
Tar extraction in moby/go-archive can write outside the destination directory via link following
Docker Sandboxes read-only runtime mount writable through its shared-export alias
Docker Sandboxes ICMP egress restriction bypass after daemon restart
Docker Sandboxes network egress allowlist bypass via unfiltered DNS resolution
Moby: Race condition in docker cp allows bind mount redirection to host path
Moby: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap
Docker: `PUT /containers/{id}/archive` executes container binary on the host
Unbounded recursion in grpcfuse kernel module allows container to crash Docker Desktop VM
Docker Model Runner container-to-host code execution via MLX-LM model_file importlib loading
Docker Model Runner container-to-host code execution via unsandboxed trust_remote_code in Python inference backends
Docker Desktop Enhanced Container Isolation bypass via --use-api-socket CLI flag
Docker Model Runner OCI Registry Client Vulnerable to Server-Side Request Forgery (SSRF)
Moby: Off-by-one error in plugin privilege validation
Moby: AuthZ plugin bypass with oversized request body
Docker Desktop Docker Plugins Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
Docker Model Runner Unauthenticated Runtime Flag Injection via _configure Endpoint
Out of bounds read vulnerability in grpcfuse kernel module
Docker Desktop for Windows Incorrect Permission Assignment Privilege Escalation Vulnerabilities
Expired Personal Access Tokens (PATs) are recorded in Docker Desktop diagnostic logs
DNS Rebinding vulnerability present when running MCP Gateway in sse or streaming mode
Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations
Multiple DLL Search Order Hijacking Vulnerabilities in Docker Desktop Installer for Windows
Showing 1 to 25 CVEs · page 1 (more available)