Перейти к содержимому
Noroxi

Записи portainer

26 опубликованных записей вендора portainer.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
1
С записью об исправлении
42,3 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

26 записей
  • CVE-2020-24264
    40В плане

    Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution.

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    portainer · portainer16 мар. 2021 г.

  • CVE-2018-19466
    40В плане

    A vulnerability was found in Portainer before 1.20.0.

    КритическаяCVSS 9,8Proof of conceptEPSS 4 %

    portainer · portainer27 мар. 2019 г.

  • CVE-2018-12678
    40В плане

    Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websocke

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    portainer · portainer22 июн. 2018 г.

  • CVE-2022-24961
    39Наблюдать

    In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    portainer · portainer11 февр. 2022 г.

  • CVE-2018-19367
    39Наблюдать

    Portainer through 1.19.2 provides an API endpoint (/api/users/admin/check) to verify that the admin user is already created.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    portainer · portainer20 нояб. 2018 г.

  • CVE-2019-16872
    39Наблюдать

    Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4).

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    portainer · portainer7 нояб. 2019 г.

  • CVE-2026-44849
    37Наблюдать

    Portainer: Endpoint security bypass via Swarm service create/update

    КритическаяCVSS 9,4Эксплойта нетEPSS 0 %

    portainer · portainer28 мая 2026 г.

  • CVE-2026-44848
    37Наблюдать

    Portainer: Missing authorization on Docker plugin endpoints allows host RCE

    КритическаяCVSS 9,4Proof of conceptEPSS 0 %

    portainer · portainer28 мая 2026 г.

  • CVE-2024-33661
    36Наблюдать

    Portainer before 2.20.0 allows redirects when the target is not index.yaml.

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    portainer · portainer25 апр. 2024 г.

  • CVE-2020-24263
    35Наблюдать

    Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    portainer · portainer16 мар. 2021 г.

  • CVE-2019-16877
    35Наблюдать

    Portainer before 1.22.1 has Incorrect Access Control (issue 4 of 4).

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    portainer · portainer7 нояб. 2019 г.

  • CVE-2026-44881
    34Наблюдать

    Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Update

    ВысокаяCVSS 8,5Proof of conceptEPSS 1 %

    portainer · portainer28 мая 2026 г.

  • CVE-2026-44850
    34Наблюдать

    Portainer: Bind-mount restriction bypass via HostConfig.Mounts

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    portainer · portainer28 мая 2026 г.

  • CVE-2026-44882
    32Наблюдать

    Portainer: Kubernetes middleware continues after token validation failure, bypassing endpoint authorization

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    portainer · portainer28 мая 2026 г.

  • CVE-2019-16876
    30Наблюдать

    Portainer before 1.22.1 allows Directory Traversal.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    portainer · portainer7 нояб. 2019 г.

  • CVE-2026-44883
    30Наблюдать

    Portainer: JWT accepted in URL query leaks tokens to logs and referers

    ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %

    portainer · portainer28 мая 2026 г.

  • CVE-2024-33662
    30Наблюдать

    Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    portainer · portainer2 окт. 2024 г.

  • CVE-2026-55761
    28Наблюдать

    Portainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitialised Portainer Instances

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    portainer · portainer8 июл. 2026 г.

  • CVE-2019-16874
    26Наблюдать

    Portainer before 1.22.1 has Incorrect Access Control (issue 2 of 4).

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    portainer · portainer7 нояб. 2019 г.

  • CVE-2021-42650
    24Наблюдать

    Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    portainer · portainer18 окт. 2021 г.

  • CVE-2026-44884
    24Наблюдать

    Portainer: Missing authorization on custom template file endpoint exposes template content

    СредняяCVSS 6,0Эксплойта нетEPSS 0 %

    portainer · portainer28 мая 2026 г.

  • CVE-2026-44885
    22Наблюдать

    Portainer: Path traversal in backup archive extraction allows arbitrary file write

    СредняяCVSS 5,5Эксплойта нетEPSS 1 %

    portainer · portainer28 мая 2026 г.

  • CVE-2024-29296
    21Наблюдать

    A user enumeration vulnerability was found in Portainer CE 2.19.4.

    СредняяCVSS 5,3Proof of conceptEPSS 1 %

    portainer · portainer10 апр. 2024 г.

  • CVE-2018-16316
    21Наблюдать

    A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScri

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    portainer · portainer1 сент. 2018 г.

  • CVE-2019-16873
    21Наблюдать

    Portainer before 1.22.1 has XSS (issue 1 of 2).

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    portainer · portainer7 нояб. 2019 г.