Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Docker Inc.

First CVE: Jul 11, 2014Active for: 12 yearsTotal CVEs: 122
63.8
VTI Score
TOP TARGET

Docker Inc. maintains a focused but strategically central portfolio of containerization and orchestration products—including Docker Engine, Docker Desktop, and associated command-line tooling—that have become foundational to modern application deployment and development workflows. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the privileged runtime position these tools occupy in infrastructure stacks. The recurring exposure centers on improper input validation, insufficient link resolution and file-access controls, and missing authentication mechanisms for critical functions, patterns consistent with the complexity of container runtimes and the security-sensitive nature of file and network isolation in containerized environments. Defenders should prioritize updates to Docker's offerings, particularly in development and production orchestration contexts where a compromise can propagate across workloads. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
122
Total CVEs
More Total CVEs than 99% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.8%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Docker Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 11, 2014
12 years ago
Most Recent CVE
Jun 12, 2026
42 days ago

Self-Reporting Analysis

Of all the CVEs published by Docker Inc. as a CNA, 74.4% affect products that Docker Inc. develops as a vendor.

74.4%
25.6%
Self-reported: 29 (74.4%)
Third-party: 10 (25.6%)

Of all the CVEs published that affect products developed by Docker Inc., 23.8% are self-published by Docker Inc. as a CNA.

23.8%
76.2%
Self-published: 29 (23.8%)
Other CNAs: 93 (76.2%)

Products(27 total)

Top CVEs

Signals from CVEs in this vendor scope (122 CVEs).

122 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-5736HIGH
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveragi
Feb 11, 20198.691NOYES
CVE-2019-15752HIGH
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\ve
Aug 28, 20197.888YESYES
CVE-2025-9074CRITICAL
A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine API via the configured Docker subnet, at 192.168.65.7:2375 b
Aug 20, 20259.349NOYES
CVE-2019-14271CRITICAL
In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that
Jul 29, 20199.841NONO
CVE-2026-34040HIGH
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This
Mar 31, 20267.839NONO
CVE-2026-6406HIGH
The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket mounts from containers are denie
May 22, 20268.837NONO
CVE-2026-8936HIGH
Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested directories on a bind-mounted host folder and triggered a dentry
Jun 2, 20268.236NONO
CVE-2026-5817HIGH
The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes
May 22, 20268.636NONO
CVE-2026-5843HIGH
The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the
May 22, 20268.635NONO
CVE-2014-9357HIGH
Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in an LZMA (.xz) archive, related to the ch
Dec 16, 201410.034NONO
View all 122 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products122 CVEs
30%
48%
19%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local50 (41.0%)
Network61 (50.0%)
Unknown9 (7.4%)
Physical0 (0.0%)
Adjacent Network2 (1.6%)
Attack Complexity
Low103 (84.4%)
High10 (8.2%)
Unknown9 (7.4%)
User Interaction
None92 (75.4%)
Unknown9 (7.4%)
Required19 (15.6%)
Privileges Required
Low49 (40.2%)
High13 (10.7%)
None51 (41.8%)
Unknown9 (7.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (122 CVEs).

CISA KEV
1 CVE
0.8% of CVEs· 99th percentile
Metasploit
2 CVEs
1.6% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
2.5% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Docker Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Docker Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Docker Inc.'s Products

View all 7 CNAs →

Top CWEs