Skip to main content

Vendor/product archive

docker / desktop CVEs

Beta · best-effort

13 CVEs tagged to docker / desktop1 Critical, 7 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-2664

Published Feb 24, 2026

An out of bounds read vulnerability in the grpcfuse kernel module present in the Linux VM in Docker Desktop for Windows, Linux and macOS up to version 4.61.0 could allow a local a…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-3224

Published Apr 28, 2025

A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-privileged attacker to escalate privileges to SYSTEM. During…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-8696

Published Sep 12, 2024

A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2.

CVSS 8.9 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8695

Published Sep 12, 2024

A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2.

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-5652

Published Jul 9, 2024

In Docker Desktop on Windows before v4.31.0 allows a user in the docker-users group to cause a Windows Denial-of-Service through the exec-path Docker daemon config option in Windo…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38730

Published Apr 27, 2023

Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerBackendV2 API by controlling the data-root field inside the…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-37326

Published Apr 27, 2023

Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 windowscontainers/start API by controlling the pidfile field in…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34292

Published Apr 27, 2023

Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/create dockerBackendV2 API by controlling the DataFolder para…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31647

Published Apr 27, 2023

Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 API via a symlink in the DataFolder parameter, a different vu…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1802

Published Apr 6, 2023

In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failed. A targeted network sniffing a…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37841

Published Aug 12, 2021

Docker Desktop before 3.6.0 suffers from incorrect access control. If a low-privileged account is able to access the server running the Windows containers, it can lead to a full c…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10665

Published Mar 18, 2020

Docker Desktop allows local privilege escalation to NT AUTHORITY\SYSTEM because it mishandles the collection of diagnostics with Administrator privileges, leading to arbitrary DAC…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1