Docker / Desktop
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-2664 | Out of bounds read vulnerability in grpcfuse kernel module | MEDIUM | 6.8 | Feb 24, 2026 |
| CVE-2025-3224 | Elevation of Privilege in Docker Desktop for Windows during Upgrade due to Insecure Directory Deletion | HIGH | 7.3 | Apr 28, 2025 |
| CVE-2024-9348 | Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view | HIGH | 8.9 | Oct 16, 2024 |
| CVE-2024-8696 | A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop befo… | HIGH | 8.9 | Sep 12, 2024 |
| CVE-2024-8695 | A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.… | CRITICAL | 9.0 | Sep 12, 2024 |
| CVE-2024-6222 | In Docker Desktop before v4.29.0 an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the host by pass… | HIGH | 7.3 | Jul 9, 2024 |
| CVE-2024-5652 | In Docker Desktop on Windows before v4.31.0 allows a user in the docker-users group to cause a Windows Denial-of-Service through the exec-path Docker daemon co… | MEDIUM | 6.1 | Jul 9, 2024 |
| CVE-2022-38730 | Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerBackendV2 API by controlling the data-ro… | MEDIUM | 6.3 | Apr 27, 2023 |
| CVE-2022-37326 | Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 windowscontainers/start API by controlling… | HIGH | 7.8 | Apr 27, 2023 |
| CVE-2022-34292 | Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/create dockerBackendV2 API by controlling… | HIGH | 7.1 | Apr 27, 2023 |
| CVE-2022-31647 | Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 API via a symlink in the DataFolder param… | HIGH | 7.1 | Apr 27, 2023 |
| CVE-2023-1802 | In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failed | HIGH | 7.5 | Apr 6, 2023 |
| CVE-2021-37841 | Docker Desktop before 3.6.0 suffers from incorrect access control. If a low-privileged account is able to access the server running the Windows containers, it… | HIGH | 7.8 | Aug 12, 2021 |
| CVE-2020-10665 | Docker Desktop allows local privilege escalation to NT AUTHORITY\SYSTEM because it mishandles the collection of diagnostics with Administrator privileges, lead… | MEDIUM | 6.7 | Mar 18, 2020 |
Showing 1 to 14 of 14 CVEs