Записи portainer
26 опубликованных записей вендора portainer.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 42,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-862 Missing Authorization3
- CWE-863 Incorrect Authorization3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-522 Insufficiently Protected Credentials1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
26 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-24264Эксплойта нет | Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution.portainer · portainer · CWE-863 | Критическая9,8 | — | 4,1 % | 16 мар. 2021 г. |
40В плане | CVE-2018-19466Proof of concept | A vulnerability was found in Portainer before 1.20.0.portainer · portainer · CWE-522 | Критическая9,8 | — | 3,7 % | 27 мар. 2019 г. |
40В плане | CVE-2018-12678Эксплойта нет | Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websockeportainer · portainer · CWE-918 | Критическая9,8 | — | 2,3 % | 22 июн. 2018 г. |
39Наблюдать | CVE-2022-24961Эксплойта нет | In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days.portainer · portainer | Критическая9,8 | — | 1,6 % | 11 февр. 2022 г. |
39Наблюдать | CVE-2018-19367Эксплойта нет | Portainer through 1.19.2 provides an API endpoint (/api/users/admin/check) to verify that the admin user is already created.portainer · portainer | Критическая9,8 | — | 1,5 % | 20 нояб. 2018 г. |
39Наблюдать | CVE-2019-16872Эксплойта нет | Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4).portainer · portainer | Критическая9,9 | — | 1,4 % | 7 нояб. 2019 г. |
37Наблюдать | CVE-2026-44849Эксплойта нет | Portainer: Endpoint security bypass via Swarm service create/updateportainer · portainer · CWE-862 | Критическая9,4 | — | 0,4 % | 28 мая 2026 г. |
37Наблюдать | CVE-2026-44848Proof of concept | Portainer: Missing authorization on Docker plugin endpoints allows host RCEportainer · portainer · CWE-862 | Критическая9,4 | — | 0,4 % | 28 мая 2026 г. |
36Наблюдать | CVE-2024-33661Эксплойта нет | Portainer before 2.20.0 allows redirects when the target is not index.yaml.portainer · portainer · CWE-601 | Критическая9,1 | — | 0,6 % | 25 апр. 2024 г. |
35Наблюдать | CVE-2020-24263Эксплойта нет | Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution.portainer · portainer · CWE-732 | Высокая8,8 | — | 1,6 % | 16 мар. 2021 г. |
35Наблюдать | CVE-2019-16877Эксплойта нет | Portainer before 1.22.1 has Incorrect Access Control (issue 4 of 4).portainer · portainer | Высокая8,8 | — | 1,0 % | 7 нояб. 2019 г. |
34Наблюдать | CVE-2026-44881Proof of concept | Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Updateportainer · portainer · CWE-59 | Высокая8,5 | — | 0,6 % | 28 мая 2026 г. |
34Наблюдать | CVE-2026-44850Эксплойта нет | Portainer: Bind-mount restriction bypass via HostConfig.Mountsportainer · portainer · CWE-863 | Высокая8,5 | — | 0,3 % | 28 мая 2026 г. |
32Наблюдать | CVE-2026-44882Эксплойта нет | Portainer: Kubernetes middleware continues after token validation failure, bypassing endpoint authorizationportainer · portainer · CWE-863 | Высокая8,1 | — | 0,5 % | 28 мая 2026 г. |
30Наблюдать | CVE-2019-16876Эксплойта нет | Portainer before 1.22.1 allows Directory Traversal.portainer · portainer · CWE-22 | Высокая7,5 | — | 1,4 % | 7 нояб. 2019 г. |
30Наблюдать | CVE-2026-44883Эксплойта нет | Portainer: JWT accepted in URL query leaks tokens to logs and referersportainer · portainer · CWE-598 | Высокая7,7 | — | 0,5 % | 28 мая 2026 г. |
30Наблюдать | CVE-2024-33662Эксплойта нет | Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.portainer · portainer · CWE-326 | Высокая7,5 | — | 0,3 % | 2 окт. 2024 г. |
28Наблюдать | CVE-2026-55761Эксплойта нет | Portainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitialised Portainer Instancesportainer · portainer · CWE-287 | Высокая7,1 | — | 0,5 % | 8 июл. 2026 г. |
26Наблюдать | CVE-2019-16874Эксплойта нет | Portainer before 1.22.1 has Incorrect Access Control (issue 2 of 4).portainer · portainer | Средняя6,5 | — | 0,9 % | 7 нояб. 2019 г. |
24Наблюдать | CVE-2021-42650Эксплойта нет | Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates.portainer · portainer · CWE-79 | Средняя6,1 | — | 0,6 % | 18 окт. 2021 г. |
24Наблюдать | CVE-2026-44884Эксплойта нет | Portainer: Missing authorization on custom template file endpoint exposes template contentportainer · portainer · CWE-862 | Средняя6,0 | — | 0,4 % | 28 мая 2026 г. |
22Наблюдать | CVE-2026-44885Эксплойта нет | Portainer: Path traversal in backup archive extraction allows arbitrary file writeportainer · portainer · CWE-22 | Средняя5,5 | — | 0,8 % | 28 мая 2026 г. |
21Наблюдать | CVE-2024-29296Proof of concept | A user enumeration vulnerability was found in Portainer CE 2.19.4.portainer · portainer · CWE-286 | Средняя5,3 | — | 1,3 % | 10 апр. 2024 г. |
21Наблюдать | CVE-2018-16316Эксплойта нет | A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScriportainer · portainer · CWE-79 | Средняя5,4 | — | 0,8 % | 1 сент. 2018 г. |
21Наблюдать | CVE-2019-16873Эксплойта нет | Portainer before 1.22.1 has XSS (issue 1 of 2).portainer · portainer · CWE-79 | Средняя5,4 | — | 0,5 % | 7 нояб. 2019 г. |
- CVE-2020-2426440В плане
Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %portainer · portainer16 мар. 2021 г.
- CVE-2018-1946640В плане
A vulnerability was found in Portainer before 1.20.0.
КритическаяCVSS 9,8Proof of conceptEPSS 4 %portainer · portainer27 мар. 2019 г.
- CVE-2018-1267840В плане
Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websocke
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %portainer · portainer22 июн. 2018 г.
- CVE-2022-2496139Наблюдать
In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %portainer · portainer11 февр. 2022 г.
- CVE-2018-1936739Наблюдать
Portainer through 1.19.2 provides an API endpoint (/api/users/admin/check) to verify that the admin user is already created.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %portainer · portainer20 нояб. 2018 г.
- CVE-2019-1687239Наблюдать
Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4).
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %portainer · portainer7 нояб. 2019 г.
- CVE-2026-4484937Наблюдать
Portainer: Endpoint security bypass via Swarm service create/update
КритическаяCVSS 9,4Эксплойта нетEPSS 0 %portainer · portainer28 мая 2026 г.
- CVE-2026-4484837Наблюдать
Portainer: Missing authorization on Docker plugin endpoints allows host RCE
КритическаяCVSS 9,4Proof of conceptEPSS 0 %portainer · portainer28 мая 2026 г.
- CVE-2024-3366136Наблюдать
Portainer before 2.20.0 allows redirects when the target is not index.yaml.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %portainer · portainer25 апр. 2024 г.
- CVE-2020-2426335Наблюдать
Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %portainer · portainer16 мар. 2021 г.
- CVE-2019-1687735Наблюдать
Portainer before 1.22.1 has Incorrect Access Control (issue 4 of 4).
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %portainer · portainer7 нояб. 2019 г.
- CVE-2026-4488134Наблюдать
Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Update
ВысокаяCVSS 8,5Proof of conceptEPSS 1 %portainer · portainer28 мая 2026 г.
- CVE-2026-4485034Наблюдать
Portainer: Bind-mount restriction bypass via HostConfig.Mounts
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %portainer · portainer28 мая 2026 г.
- CVE-2026-4488232Наблюдать
Portainer: Kubernetes middleware continues after token validation failure, bypassing endpoint authorization
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %portainer · portainer28 мая 2026 г.
- CVE-2019-1687630Наблюдать
Portainer before 1.22.1 allows Directory Traversal.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %portainer · portainer7 нояб. 2019 г.
- CVE-2026-4488330Наблюдать
Portainer: JWT accepted in URL query leaks tokens to logs and referers
ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %portainer · portainer28 мая 2026 г.
- CVE-2024-3366230Наблюдать
Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %portainer · portainer2 окт. 2024 г.
- CVE-2026-5576128Наблюдать
Portainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitialised Portainer Instances
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %portainer · portainer8 июл. 2026 г.
- CVE-2019-1687426Наблюдать
Portainer before 1.22.1 has Incorrect Access Control (issue 2 of 4).
СредняяCVSS 6,5Эксплойта нетEPSS 1 %portainer · portainer7 нояб. 2019 г.
- CVE-2021-4265024Наблюдать
Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %portainer · portainer18 окт. 2021 г.
- CVE-2026-4488424Наблюдать
Portainer: Missing authorization on custom template file endpoint exposes template content
СредняяCVSS 6,0Эксплойта нетEPSS 0 %portainer · portainer28 мая 2026 г.
- CVE-2026-4488522Наблюдать
Portainer: Path traversal in backup archive extraction allows arbitrary file write
СредняяCVSS 5,5Эксплойта нетEPSS 1 %portainer · portainer28 мая 2026 г.
- CVE-2024-2929621Наблюдать
A user enumeration vulnerability was found in Portainer CE 2.19.4.
СредняяCVSS 5,3Proof of conceptEPSS 1 %portainer · portainer10 апр. 2024 г.
- CVE-2018-1631621Наблюдать
A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScri
СредняяCVSS 5,4Эксплойта нетEPSS 1 %portainer · portainer1 сент. 2018 г.
- CVE-2019-1687321Наблюдать
Portainer before 1.22.1 has XSS (issue 1 of 2).
СредняяCVSS 5,4Эксплойта нетEPSS 1 %portainer · portainer7 нояб. 2019 г.