CVE-2025-49593
- EPSS 0.07%
- Veröffentlicht 17.06.2025 21:27:38
- Zuletzt bearbeitet 18.06.2025 13:46:52
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. Prior to STS version 2.31.0 and LTS version 2.27.7, if a Portainer admini...
CVE-2024-33662
- EPSS 0.09%
- Veröffentlicht 02.10.2024 05:15:11
- Zuletzt bearbeitet 21.05.2025 18:07:02
Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.
CVE-2024-33661
- EPSS 0.09%
- Veröffentlicht 26.04.2024 00:15:08
- Zuletzt bearbeitet 21.05.2025 18:07:35
Portainer before 2.20.0 allows redirects when the target is not index.yaml.
CVE-2024-29296
- EPSS 10.28%
- Veröffentlicht 10.04.2024 15:16:05
- Zuletzt bearbeitet 05.06.2025 13:51:40
A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not.
CVE-2022-24961
- EPSS 0.75%
- Veröffentlicht 11.02.2022 06:15:06
- Zuletzt bearbeitet 21.11.2024 06:51:28
In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days.
CVE-2021-41874
- EPSS 0.38%
- Veröffentlicht 29.10.2021 18:15:08
- Zuletzt bearbeitet 27.08.2025 23:15:32
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2021-42650
- EPSS 0.22%
- Veröffentlicht 18.10.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:27:55
Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates.
- EPSS 5.24%
- Veröffentlicht 16.03.2021 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:14:32
Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. The restriction checks for bind mounts are applied only on the client-side and not the server-side, which can lead to spawning a co...
CVE-2020-24263
- EPSS 1.92%
- Veröffentlicht 16.03.2021 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:14:32
Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution. A non-admin user is allowed to spawn new containers with critical capabilities such as SYS_MODULE, which can be used t...
CVE-2019-16878
- EPSS 0.35%
- Veröffentlicht 07.11.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:31:15
Portainer before 1.22.1 has XSS (issue 2 of 2).