23 entries matching docker — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-69259 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Reco | CRITICAL | 9.4 | — | NVD | 2026-08-04 |
| CVE-2026-69096 | OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after | HIGH | 8.7 | 74%ile | NVD | 2026-08-03 |
| CVE-2026-52855 | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{ | CRITICAL | 9.9 | 20%ile | NVD | 2026-07-31 |
| CVE-2026-16503 | Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces | CRITICAL | 9.1 | 16%ile | NVD | 2026-07-31 |
| CVE-2026-67208 | Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to exec | CRITICAL | 9.3 | 62%ile | NVD | 2026-07-30 |
| CVE-2026-47882 | When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foun | HIGH | 8.3 | 7%ile | NVD | 2026-07-30 |
| CVE-2026-47873 | The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network int | HIGH | 8.0 | 8%ile | NVD | 2026-07-30 |
| CVE-2026-54574 | proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain ta | HIGH | 8.2 | 4%ile | NVD | 2026-07-29 |
| GHSA-vg6v-j97m-h5xq | @novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request | MEDIUM | 6.8 | — | GitHub | 2026-07-28 |
| CVE-2026-46595 | Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh | CRITICAL | 10.0 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-39830 | Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh | CRITICAL | 9.1 | 46%ile | Microsoft | 2026-05-12 |
| CVE-2026-39831 | Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh | CRITICAL | 9.1 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-39834 | Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh | CRITICAL | 9.1 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-39833 | Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent | CRITICAL | 9.1 | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-39832 | Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent | CRITICAL | 9.1 | 45%ile | Microsoft | 2026-05-12 |
| CVE-2026-39829 | Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh | HIGH | 7.5 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-46597 | Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh | HIGH | 7.5 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-39827 | Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh | MEDIUM | 6.5 | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-39828 | Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh | MEDIUM | 6.3 | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-39835 | Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh | MEDIUM | 5.3 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-46598 | Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent | MEDIUM | 5.3 | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-39882 | OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies | MEDIUM | 5.3 | 9%ile | Microsoft | 2026-04-14 |
| CVE-2023-45288 | HTTP/2 CONTINUATION flood in net/http | HIGH | 7.5 | 100%ile | Microsoft | 2024-04-09 |