portainer kayıtları
portainer üreticisine ait 26 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %38,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-862 Missing Authorization3
- CWE-863 Incorrect Authorization3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-522 Insufficiently Protected Credentials1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
26 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-24264İstismar yok | Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution.portainer · portainer · CWE-863 | Kritik9,8 | — | %4,1 | 16 Mar 2021 |
40Planlayın | CVE-2018-19466Kavram kanıtı | A vulnerability was found in Portainer before 1.20.0.portainer · portainer · CWE-522 | Kritik9,8 | — | %3,7 | 27 Mar 2019 |
40Planlayın | CVE-2018-12678İstismar yok | Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websockeportainer · portainer · CWE-918 | Kritik9,8 | — | %2,3 | 22 Haz 2018 |
39İzleyin | CVE-2022-24961İstismar yok | In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days.portainer · portainer | Kritik9,8 | — | %1,6 | 11 Şub 2022 |
39İzleyin | CVE-2018-19367İstismar yok | Portainer through 1.19.2 provides an API endpoint (/api/users/admin/check) to verify that the admin user is already created.portainer · portainer | Kritik9,8 | — | %1,5 | 20 Kas 2018 |
39İzleyin | CVE-2019-16872İstismar yok | Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4).portainer · portainer | Kritik9,9 | — | %1,4 | 7 Kas 2019 |
37İzleyin | CVE-2026-44849İstismar yok | Portainer: Endpoint security bypass via Swarm service create/updateportainer · portainer · CWE-862 | Kritik9,4 | — | %0,4 | 28 May 2026 |
37İzleyin | CVE-2026-44848Kavram kanıtı | Portainer: Missing authorization on Docker plugin endpoints allows host RCEportainer · portainer · CWE-862 | Kritik9,4 | — | %0,4 | 28 May 2026 |
36İzleyin | CVE-2024-33661İstismar yok | Portainer before 2.20.0 allows redirects when the target is not index.yaml.portainer · portainer · CWE-601 | Kritik9,1 | — | %0,6 | 25 Nis 2024 |
35İzleyin | CVE-2020-24263İstismar yok | Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution.portainer · portainer · CWE-732 | Yüksek8,8 | — | %1,6 | 16 Mar 2021 |
35İzleyin | CVE-2019-16877İstismar yok | Portainer before 1.22.1 has Incorrect Access Control (issue 4 of 4).portainer · portainer | Yüksek8,8 | — | %1,0 | 7 Kas 2019 |
34İzleyin | CVE-2026-44881Kavram kanıtı | Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Updateportainer · portainer · CWE-59 | Yüksek8,5 | — | %0,6 | 28 May 2026 |
34İzleyin | CVE-2026-44850İstismar yok | Portainer: Bind-mount restriction bypass via HostConfig.Mountsportainer · portainer · CWE-863 | Yüksek8,5 | — | %0,3 | 28 May 2026 |
32İzleyin | CVE-2026-44882İstismar yok | Portainer: Kubernetes middleware continues after token validation failure, bypassing endpoint authorizationportainer · portainer · CWE-863 | Yüksek8,1 | — | %0,5 | 28 May 2026 |
30İzleyin | CVE-2019-16876İstismar yok | Portainer before 1.22.1 allows Directory Traversal.portainer · portainer · CWE-22 | Yüksek7,5 | — | %1,4 | 7 Kas 2019 |
30İzleyin | CVE-2026-44883İstismar yok | Portainer: JWT accepted in URL query leaks tokens to logs and referersportainer · portainer · CWE-598 | Yüksek7,7 | — | %0,5 | 28 May 2026 |
30İzleyin | CVE-2024-33662İstismar yok | Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.portainer · portainer · CWE-326 | Yüksek7,5 | — | %0,3 | 2 Eki 2024 |
28İzleyin | CVE-2026-55761İstismar yok | Portainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitialised Portainer Instancesportainer · portainer · CWE-287 | Yüksek7,1 | — | %0,5 | 8 Tem 2026 |
26İzleyin | CVE-2019-16874İstismar yok | Portainer before 1.22.1 has Incorrect Access Control (issue 2 of 4).portainer · portainer | Orta6,5 | — | %0,9 | 7 Kas 2019 |
24İzleyin | CVE-2021-42650İstismar yok | Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates.portainer · portainer · CWE-79 | Orta6,1 | — | %0,6 | 18 Eki 2021 |
24İzleyin | CVE-2026-44884İstismar yok | Portainer: Missing authorization on custom template file endpoint exposes template contentportainer · portainer · CWE-862 | Orta6,0 | — | %0,4 | 28 May 2026 |
22İzleyin | CVE-2026-44885İstismar yok | Portainer: Path traversal in backup archive extraction allows arbitrary file writeportainer · portainer · CWE-22 | Orta5,5 | — | %0,8 | 28 May 2026 |
21İzleyin | CVE-2024-29296Kavram kanıtı | A user enumeration vulnerability was found in Portainer CE 2.19.4.portainer · portainer · CWE-286 | Orta5,3 | — | %1,3 | 10 Nis 2024 |
21İzleyin | CVE-2018-16316İstismar yok | A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScriportainer · portainer · CWE-79 | Orta5,4 | — | %0,8 | 1 Eyl 2018 |
21İzleyin | CVE-2019-16873İstismar yok | Portainer before 1.22.1 has XSS (issue 1 of 2).portainer · portainer · CWE-79 | Orta5,4 | — | %0,5 | 7 Kas 2019 |
- CVE-2020-2426440Planlayın
Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution.
KritikCVSS 9,8İstismar yokEPSS %4portainer · portainer16 Mar 2021
- CVE-2018-1946640Planlayın
A vulnerability was found in Portainer before 1.20.0.
KritikCVSS 9,8Kavram kanıtıEPSS %4portainer · portainer27 Mar 2019
- CVE-2018-1267840Planlayın
Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websocke
KritikCVSS 9,8İstismar yokEPSS %2portainer · portainer22 Haz 2018
- CVE-2022-2496139İzleyin
In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days.
KritikCVSS 9,8İstismar yokEPSS %2portainer · portainer11 Şub 2022
- CVE-2018-1936739İzleyin
Portainer through 1.19.2 provides an API endpoint (/api/users/admin/check) to verify that the admin user is already created.
KritikCVSS 9,8İstismar yokEPSS %1portainer · portainer20 Kas 2018
- CVE-2019-1687239İzleyin
Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4).
KritikCVSS 9,9İstismar yokEPSS %1portainer · portainer7 Kas 2019
- CVE-2026-4484937İzleyin
Portainer: Endpoint security bypass via Swarm service create/update
KritikCVSS 9,4İstismar yokEPSS %0portainer · portainer28 May 2026
- CVE-2026-4484837İzleyin
Portainer: Missing authorization on Docker plugin endpoints allows host RCE
KritikCVSS 9,4Kavram kanıtıEPSS %0portainer · portainer28 May 2026
- CVE-2024-3366136İzleyin
Portainer before 2.20.0 allows redirects when the target is not index.yaml.
KritikCVSS 9,1İstismar yokEPSS %1portainer · portainer25 Nis 2024
- CVE-2020-2426335İzleyin
Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution.
YüksekCVSS 8,8İstismar yokEPSS %2portainer · portainer16 Mar 2021
- CVE-2019-1687735İzleyin
Portainer before 1.22.1 has Incorrect Access Control (issue 4 of 4).
YüksekCVSS 8,8İstismar yokEPSS %1portainer · portainer7 Kas 2019
- CVE-2026-4488134İzleyin
Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Update
YüksekCVSS 8,5Kavram kanıtıEPSS %1portainer · portainer28 May 2026
- CVE-2026-4485034İzleyin
Portainer: Bind-mount restriction bypass via HostConfig.Mounts
YüksekCVSS 8,5İstismar yokEPSS %0portainer · portainer28 May 2026
- CVE-2026-4488232İzleyin
Portainer: Kubernetes middleware continues after token validation failure, bypassing endpoint authorization
YüksekCVSS 8,1İstismar yokEPSS %0portainer · portainer28 May 2026
- CVE-2019-1687630İzleyin
Portainer before 1.22.1 allows Directory Traversal.
YüksekCVSS 7,5İstismar yokEPSS %1portainer · portainer7 Kas 2019
- CVE-2026-4488330İzleyin
Portainer: JWT accepted in URL query leaks tokens to logs and referers
YüksekCVSS 7,7İstismar yokEPSS %0portainer · portainer28 May 2026
- CVE-2024-3366230İzleyin
Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.
YüksekCVSS 7,5İstismar yokEPSS %0portainer · portainer2 Eki 2024
- CVE-2026-5576128İzleyin
Portainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitialised Portainer Instances
YüksekCVSS 7,1İstismar yokEPSS %0portainer · portainer8 Tem 2026
- CVE-2019-1687426İzleyin
Portainer before 1.22.1 has Incorrect Access Control (issue 2 of 4).
OrtaCVSS 6,5İstismar yokEPSS %1portainer · portainer7 Kas 2019
- CVE-2021-4265024İzleyin
Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates.
OrtaCVSS 6,1İstismar yokEPSS %1portainer · portainer18 Eki 2021
- CVE-2026-4488424İzleyin
Portainer: Missing authorization on custom template file endpoint exposes template content
OrtaCVSS 6,0İstismar yokEPSS %0portainer · portainer28 May 2026
- CVE-2026-4488522İzleyin
Portainer: Path traversal in backup archive extraction allows arbitrary file write
OrtaCVSS 5,5İstismar yokEPSS %1portainer · portainer28 May 2026
- CVE-2024-2929621İzleyin
A user enumeration vulnerability was found in Portainer CE 2.19.4.
OrtaCVSS 5,3Kavram kanıtıEPSS %1portainer · portainer10 Nis 2024
- CVE-2018-1631621İzleyin
A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScri
OrtaCVSS 5,4İstismar yokEPSS %1portainer · portainer1 Eyl 2018
- CVE-2019-1687321İzleyin
Portainer before 1.22.1 has XSS (issue 1 of 2).
OrtaCVSS 5,4İstismar yokEPSS %1portainer · portainer7 Kas 2019