Skip to content
Noroxi

portainer records

26 published records for vendor portainer.

All records

26 records
  • Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution.

    CriticalCVSS 9.8No exploitEPSS 4%

    portainer · portainerMar 16, 2021

  • A vulnerability was found in Portainer before 1.20.0.

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    portainer · portainerMar 27, 2019

  • Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websocke

    CriticalCVSS 9.8No exploitEPSS 2%

    portainer · portainerJun 22, 2018

  • In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days.

    CriticalCVSS 9.8No exploitEPSS 2%

    portainer · portainerFeb 11, 2022

  • Portainer through 1.19.2 provides an API endpoint (/api/users/admin/check) to verify that the admin user is already created.

    CriticalCVSS 9.8No exploitEPSS 1%

    portainer · portainerNov 20, 2018

  • Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4).

    CriticalCVSS 9.9No exploitEPSS 1%

    portainer · portainerNov 7, 2019

  • Portainer: Endpoint security bypass via Swarm service create/update

    CriticalCVSS 9.4No exploitEPSS 0%

    portainer · portainerMay 28, 2026

  • Portainer: Missing authorization on Docker plugin endpoints allows host RCE

    CriticalCVSS 9.4Proof of conceptEPSS 0%

    portainer · portainerMay 28, 2026

  • Portainer before 2.20.0 allows redirects when the target is not index.yaml.

    CriticalCVSS 9.1No exploitEPSS 1%

    portainer · portainerApr 25, 2024

  • Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution.

    HighCVSS 8.8No exploitEPSS 2%

    portainer · portainerMar 16, 2021

  • Portainer before 1.22.1 has Incorrect Access Control (issue 4 of 4).

    HighCVSS 8.8No exploitEPSS 1%

    portainer · portainerNov 7, 2019

  • Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Update

    HighCVSS 8.5Proof of conceptEPSS 1%

    portainer · portainerMay 28, 2026

  • Portainer: Bind-mount restriction bypass via HostConfig.Mounts

    HighCVSS 8.5No exploitEPSS 0%

    portainer · portainerMay 28, 2026

  • Portainer: Kubernetes middleware continues after token validation failure, bypassing endpoint authorization

    HighCVSS 8.1No exploitEPSS 0%

    portainer · portainerMay 28, 2026

  • Portainer before 1.22.1 allows Directory Traversal.

    HighCVSS 7.5No exploitEPSS 1%

    portainer · portainerNov 7, 2019

  • Portainer: JWT accepted in URL query leaks tokens to logs and referers

    HighCVSS 7.7No exploitEPSS 0%

    portainer · portainerMay 28, 2026

  • Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.

    HighCVSS 7.5No exploitEPSS 0%

    portainer · portainerOct 2, 2024

  • Portainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitialised Portainer Instances

    HighCVSS 7.1No exploitEPSS 0%

    portainer · portainerJul 8, 2026

  • Portainer before 1.22.1 has Incorrect Access Control (issue 2 of 4).

    MediumCVSS 6.5No exploitEPSS 1%

    portainer · portainerNov 7, 2019

  • Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates.

    MediumCVSS 6.1No exploitEPSS 1%

    portainer · portainerOct 18, 2021

  • Portainer: Missing authorization on custom template file endpoint exposes template content

    MediumCVSS 6.0No exploitEPSS 0%

    portainer · portainerMay 28, 2026

  • Portainer: Path traversal in backup archive extraction allows arbitrary file write

    MediumCVSS 5.5No exploitEPSS 1%

    portainer · portainerMay 28, 2026

  • A user enumeration vulnerability was found in Portainer CE 2.19.4.

    MediumCVSS 5.3Proof of conceptEPSS 1%

    portainer · portainerApr 10, 2024

  • A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScri

    MediumCVSS 5.4No exploitEPSS 1%

    portainer · portainerSep 1, 2018

  • Portainer before 1.22.1 has XSS (issue 1 of 2).

    MediumCVSS 5.4No exploitEPSS 1%

    portainer · portainerNov 7, 2019