Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Anchore

First CVE: Aug 1, 2018Active for: 8 yearsTotal CVEs: 9

Anchore develops container vulnerability scanning and supply-chain security tooling deployed across software development and artifact-management pipelines; its product line centers on tools such as Syft and Quill for software composition analysis and container inspection. Vulnerabilities affecting the vendor skew toward serious outcomes and concentrate in weakness classes related to resource management, information disclosure, exception handling, path traversal, and sensitive-data logging that reflect the parsing and filesystem-access demands of tools that must inspect and analyze untrusted container images and artifacts. Current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Anchore over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 1, 2018
7 years ago
Most Recent CVE
Mar 26, 2026
120 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-24579CRITICAL
stereoscope is a go library for processing container images and simulating a squash filesystem. Prior to version 0.0.1, it is possible to craft an OCI tar archive that, when stere
Jan 31, 20249.826NONO
CVE-2022-1766HIGH
Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add the credentials used to access Anchore E
Jul 20, 20227.525NONO
CVE-2020-11075CRITICAL
In Anchore Engine version 0.7.0, a specially crafted container image manifest, fetched from a registry, can be used to trigger a shell escape flaw in the anchore engine analyzer se
May 27, 20209.924NONO
CVE-2023-24827HIGH
syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. A password disclosure flaw was found in Syft versions
Feb 7, 20237.523NONO
CVE-2018-1999033MEDIUM
An exposure of sensitive information vulnerability exists in Jenkins Anchore Container Image Scanner Plugin 10.16 and earlier in AnchoreBuilder.java that allows attackers with Item
Aug 1, 20186.521NONO
CVE-2026-33481MEDIUM
Syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. Syft versions before v1.42.3 would not properly cleanu
Mar 26, 20265.320NONO
CVE-2026-31961MEDIUM
Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains an unbounded memory allocation vulnerability when parsing Mach-O b
Mar 11, 20265.520NONO
CVE-2026-31960MEDIUM
Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 has unbounded reads of HTTP response bodies during the Apple notarization p
Mar 11, 20265.320NONO
CVE-2026-31959MEDIUM
Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains a Server-Side Request Forgery (SSRF) vulnerability when attempting
Mar 11, 20265.320NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
56%
22%
22%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (11.1%)
Network6 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (22.2%)
Attack Complexity
Low7 (77.8%)
High2 (22.2%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (33.3%)
High0 (0.0%)
None6 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Anchore.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Anchore — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Anchore's Products

View all 3 CNAs →

Top CWEs