14 Total CVEs
12 AI Analyzed
0 CISA KEV
10 Critical
All Vendors
Showing 1-14 of 14 CVEs
CVE-2026-25142
Analyzed
10
Docker Multiple Products

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ which can be used to obtain protot...

2026-02-03
CVE-2026-24841
Analyzed
9.9
Docker Multiple Products

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a critical command injection vulnerability exists in Dokpl...

2026-01-28
CVE-2026-24129
Analyzed
8
Docker Multiple Products

Runtipi is a Docker-based, personal homeserver orchestrator that facilitates multiple services on a single server

2026-01-23
CVE-2026-23846
Analyzed
8.1
Docker Multiple Products

Tugtainer is a self-hosted app for automating updates of Docker containers

2026-01-20
CVE-2026-23520
9
Docker Multiple Products

Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane’s updater service supported l...

2026-01-16
CVE-2026-22709
Analyzed
9.8
Docker Multiple Products

vm2 is an open source vm/sandbox for Node.js. In vm2 prior to version 3.10.2, `Promise.prototype.then` `Promise.prototype.catch` callback sanitization...

2026-01-27
CVE-2026-0863
Analyzed
8.5
Docker Multiple Products

Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted...

2026-01-19
CVE-2025-69222
Analyzed
9.1
Docker Multiple Products

LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is prone to a server-side request forgery (SSRF) vulnerability due to missing...

2026-01-08
CVE-2025-66570
10
Docker Multiple Products

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allows attacker-controlled HTTP hea...

2025-12-06
CVE-2025-64419
Analyzed
9.6
Docker Multiple Products

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.445, parameters coming...

2026-01-06
CVE-2025-53909
Analyzed
9.1
Docker Multiple Products

mailcow: dockerized is an open source groupware/email suite based on docker. A Server-Side Template Injection (SSTI) vulnerability exists in versions...

2025-07-17
CVE-2025-49655
Analyzed
9.8
Docker Multiple Products

Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not including 3.11.3, enabling a mali...

2025-10-17
CVE-2025-14707
Analyzed
9.8
Docker Multiple Products

A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25. Affected is an unknown function of the file /usr/sbin/http_eshell_server of the co...

2025-12-15
CVE-2025-12970
Analyzed
8.8
Docker Multiple Products

The extract_name function in Fluent Bit in_docker input plugin copies container names into a fixed size stack buffer without validating length

2025-11-25