İçeriğe atla
Noroxi

portainer kayıtları

portainer üreticisine ait 26 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%38,5
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

26 kayıt
  • CVE-2020-24264
    40Planlayın

    Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution.

    KritikCVSS 9,8İstismar yokEPSS %4

    portainer · portainer16 Mar 2021

  • CVE-2018-19466
    40Planlayın

    A vulnerability was found in Portainer before 1.20.0.

    KritikCVSS 9,8Kavram kanıtıEPSS %4

    portainer · portainer27 Mar 2019

  • CVE-2018-12678
    40Planlayın

    Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websocke

    KritikCVSS 9,8İstismar yokEPSS %2

    portainer · portainer22 Haz 2018

  • CVE-2022-24961
    39İzleyin

    In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days.

    KritikCVSS 9,8İstismar yokEPSS %2

    portainer · portainer11 Şub 2022

  • CVE-2018-19367
    39İzleyin

    Portainer through 1.19.2 provides an API endpoint (/api/users/admin/check) to verify that the admin user is already created.

    KritikCVSS 9,8İstismar yokEPSS %1

    portainer · portainer20 Kas 2018

  • CVE-2019-16872
    39İzleyin

    Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4).

    KritikCVSS 9,9İstismar yokEPSS %1

    portainer · portainer7 Kas 2019

  • CVE-2026-44849
    37İzleyin

    Portainer: Endpoint security bypass via Swarm service create/update

    KritikCVSS 9,4İstismar yokEPSS %0

    portainer · portainer28 May 2026

  • CVE-2026-44848
    37İzleyin

    Portainer: Missing authorization on Docker plugin endpoints allows host RCE

    KritikCVSS 9,4Kavram kanıtıEPSS %0

    portainer · portainer28 May 2026

  • CVE-2024-33661
    36İzleyin

    Portainer before 2.20.0 allows redirects when the target is not index.yaml.

    KritikCVSS 9,1İstismar yokEPSS %1

    portainer · portainer25 Nis 2024

  • CVE-2020-24263
    35İzleyin

    Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution.

    YüksekCVSS 8,8İstismar yokEPSS %2

    portainer · portainer16 Mar 2021

  • CVE-2019-16877
    35İzleyin

    Portainer before 1.22.1 has Incorrect Access Control (issue 4 of 4).

    YüksekCVSS 8,8İstismar yokEPSS %1

    portainer · portainer7 Kas 2019

  • CVE-2026-44881
    34İzleyin

    Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Update

    YüksekCVSS 8,5Kavram kanıtıEPSS %1

    portainer · portainer28 May 2026

  • CVE-2026-44850
    34İzleyin

    Portainer: Bind-mount restriction bypass via HostConfig.Mounts

    YüksekCVSS 8,5İstismar yokEPSS %0

    portainer · portainer28 May 2026

  • CVE-2026-44882
    32İzleyin

    Portainer: Kubernetes middleware continues after token validation failure, bypassing endpoint authorization

    YüksekCVSS 8,1İstismar yokEPSS %0

    portainer · portainer28 May 2026

  • CVE-2019-16876
    30İzleyin

    Portainer before 1.22.1 allows Directory Traversal.

    YüksekCVSS 7,5İstismar yokEPSS %1

    portainer · portainer7 Kas 2019

  • CVE-2026-44883
    30İzleyin

    Portainer: JWT accepted in URL query leaks tokens to logs and referers

    YüksekCVSS 7,7İstismar yokEPSS %0

    portainer · portainer28 May 2026

  • CVE-2024-33662
    30İzleyin

    Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.

    YüksekCVSS 7,5İstismar yokEPSS %0

    portainer · portainer2 Eki 2024

  • CVE-2026-55761
    28İzleyin

    Portainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitialised Portainer Instances

    YüksekCVSS 7,1İstismar yokEPSS %0

    portainer · portainer8 Tem 2026

  • CVE-2019-16874
    26İzleyin

    Portainer before 1.22.1 has Incorrect Access Control (issue 2 of 4).

    OrtaCVSS 6,5İstismar yokEPSS %1

    portainer · portainer7 Kas 2019

  • CVE-2021-42650
    24İzleyin

    Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates.

    OrtaCVSS 6,1İstismar yokEPSS %1

    portainer · portainer18 Eki 2021

  • CVE-2026-44884
    24İzleyin

    Portainer: Missing authorization on custom template file endpoint exposes template content

    OrtaCVSS 6,0İstismar yokEPSS %0

    portainer · portainer28 May 2026

  • CVE-2026-44885
    22İzleyin

    Portainer: Path traversal in backup archive extraction allows arbitrary file write

    OrtaCVSS 5,5İstismar yokEPSS %1

    portainer · portainer28 May 2026

  • CVE-2024-29296
    21İzleyin

    A user enumeration vulnerability was found in Portainer CE 2.19.4.

    OrtaCVSS 5,3Kavram kanıtıEPSS %1

    portainer · portainer10 Nis 2024

  • CVE-2018-16316
    21İzleyin

    A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScri

    OrtaCVSS 5,4İstismar yokEPSS %1

    portainer · portainer1 Eyl 2018

  • CVE-2019-16873
    21İzleyin

    Portainer before 1.22.1 has XSS (issue 1 of 2).

    OrtaCVSS 5,4İstismar yokEPSS %1

    portainer · portainer7 Kas 2019