Amirraminfar's vulnerability profile centers on Dozzle, a container log-viewing application, with a durable signal around access-control and authorization weaknesses including improper access control, inadequate encryption strength, incorrect authorization checks, origin validation errors, and server-side request forgery. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Amirraminfar over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-45298HIGH Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications | May 26, 2026 | 8.6 | 48 | NO | YES |
CVE-2026-44985CRITICAL Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach endpoints uses CheckOrigin: func(r *http.Request) bool { ret | May 26, 2026 | 9.6 | 38 | NO | NO |
CVE-2026-24740CRITICAL Dozzle is a realtime log viewer for docker containers. Prior to version 9.0.3, a flaw in Dozzle’s agent-backed shell endpoints allows a user restricted by label filters (for exampl | Jan 27, 2026 | 9.9 | 28 | NO | NO |
CVE-2024-47182HIGH Dozzle is a realtime log viewer for docker containers. Before version 8.5.3, the app uses sha-256 as the hash for passwords, which leaves users susceptible to rainbow table attacks | Sep 27, 2024 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Amirraminfar.
Media articles that mention a CVE ID that affects a product developed by Amirraminfar — matched by CVE ID, not by vendor name.