Desktop

Vendor:

First CVE: Mar 18, 2020 · Active for 6 years

13
Total CVEs
More Total CVEs than 91% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 59% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Desktop over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 18, 2020
6 years ago
Most Recent CVE
Feb 24, 2026
150 days ago

CVE Severity & Scoring

Desktop13 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local10 (76.9%)
Network3 (23.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (84.6%)
High2 (15.4%)
Unknown0 (0.0%)
User Interaction
None13 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low9 (69.2%)
High1 (7.7%)
None3 (23.1%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2.
Sep 12, 20249.831NONO
A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2.
Sep 12, 20249.831NONO
An out of bounds read vulnerability in the grpcfuse kernel module present in the Linux VM in Docker Desktop for Windows, Linux and macOS up to version 4.61.0 could allow a local at
Feb 24, 20267.827NONO
In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failed. A targeted network sniffing at
Apr 6, 20237.524NONO
Docker Desktop before 3.6.0 suffers from incorrect access control. If a low-privileged account is able to access the server running the Windows containers, it can lead to a full co
Aug 12, 20217.824NONO
A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-privileged attacker to escalate privileges to SYSTEM. During a
Apr 28, 20257.823NONO
Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 windowscontainers/start API by controlling the pidfile field ins
Apr 27, 20237.823NONO
In Docker Desktop before v4.29.0, an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the host by passing extensions and d
Jul 9, 20247.022NONO
Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 API via a symlink in the DataFolder parameter, a different vul
Apr 27, 20237.122NONO
Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/create dockerBackendV2 API by controlling the DataFolder param
Apr 27, 20237.121NONO

Exploit Exposure

Signals from CVEs in this product scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (13 CVEs).

Media Mentions

Signals from CVEs in this product scope (13 CVEs).

Top CNAs Publishing CVEs For Desktop

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.17.117.50.5%00
4.17.017.50.5%00