| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-5741 | suvarchal docker-mcp-server HTTP index.ts pull_image os command injection | suvarchal | docker-mcp-server | High | 7.3 | 2026-04-07 20:00:21 | Deep Dive |
| CVE-2026-33990 | Docker Model Runner OCI Registry Client Vulnerable to Server-Side Request Forgery (SSRF) | docker | model-runner | - | - | 2026-04-01 16:17:41 | Deep Dive |
| CVE-2023-27573 | netbox-docker 安全漏洞 | netbox-community | netbox-docker | Critical | 9.0 | 2026-03-11 00:00:00 | Deep Dive |
| CVE-2025-15558 | Docker Desktop Docker Plugins Uncontrolled Search Path Element Local Privilege Escalation Vulnerability | Docker | Docker CLI | 高危 | - | 2026-03-04 16:14:32 | Deep Dive |
| CVE-2026-28400 | Docker Model Runner Unauthenticated Runtime Flag Injection via _configure Endpoint | docker | model-runner | High | 7.5 | 2026-02-27 21:06:12 | Deep Dive |
| CVE-2026-2664 | Out of bounds read vulnerability in grpcfuse kernel module | Docker | Docker Desktop | - | - | 2026-02-24 10:09:19 | Deep Dive |
| CVE-2025-14740 | Docker Desktop for Windows Incorrect Permission Assignment Privilege Escalation Vulnerabilities | Docker Inc. | Docker Desktop | Medium | 6.7 | 2026-02-04 13:57:23 | Deep Dive |
| CVE-2025-13743 | Expired Personal Access Tokens (PATs) are recorded in Docker Desktop diagnostic logs | Docker | Docker Desktop | - | - | 2025-12-09 20:39:52 | Deep Dive |
| CVE-2025-64443 | DNS Rebinding vulnerability present when running MCP Gateway in sse or streaming mode | docker | mcp-gateway | - | - | 2025-12-03 17:41:59 | Deep Dive |
| CVE-2025-10703 | Progress多款产品 代码注入漏洞 | Progress | DataDirect Connect for JDBC for Amazon Redshift | - | - | 2025-11-19 15:47:08 | Deep Dive |
| CVE-2025-10702 | Progress多款产品 代码注入漏洞 | Progress | DataDirect Connect for JDBC for Amazon Redshift | - | - | 2025-11-19 15:46:27 | Deep Dive |
| CVE-2025-62725 | Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations | docker | compose | - | - | 2025-10-27 20:37:32 | Deep Dive |
| CVE-2025-9164 | Multiple DLL Search Order Hijacking Vulnerabilities in Docker Desktop Installer for Windows | Docker | Docker Desktop | - | - | 2025-10-27 13:53:40 | Deep Dive |
| CVE-2025-36354 | IBM Security Verify Access command execution | IBM | Security Verify Access Appliance | High | 7.3 | 2025-10-06 16:53:43 | Deep Dive |
| CVE-2025-36355 | IBM Security Verify Access code execution | IBM | Security Verify Access Appliance | High | 8.5 | 2025-10-06 16:52:31 | Deep Dive |
| CVE-2025-36356 | IBM Security Verify Access privilege escalation | IBM | Security Verify Access Appliance | Critical | 9.3 | 2025-10-06 16:50:49 | Deep Dive |
| CVE-2025-10657 | Docker Desktop with ECI Fails to Enforce Socket Command Restrictions | Docker | Docker Desktop | 中危 | - | 2025-09-26 21:05:19 | Deep Dive |
| CVE-2025-9074 | Docker Desktop allows unauthenticated access to Docker Engine API from containers | Docker | Docker Desktop | - | - | 2025-08-20 13:28:36 | Deep Dive |
| CVE-2025-7381 | Exposure of sensitive PHP information to an unauthorized control sphere in mautic/mautic images | mautic | Docker Mautic | Medium | 5.3 | 2025-07-09 15:16:37 | Deep Dive |
| CVE-2025-6587 | Exposure of system environment variables in Docker Desktop diagnostic logs | Docker | Docker Desktop | - | - | 2025-07-03 10:03:27 | Deep Dive |