OCImendby CloudTrace

Live data · updated as images are scanned

Container image security, measured

What OCImend finds in popular public images: how many vulnerabilities, how severe, how many actually matter, and how many can be fixed today. Only scans made without credentials are counted.

35public images measured
3,619known CVEs found
14%in code the app loads
27%fixable with an upgrade today

Most vulnerable images

ImageCVEsCriticalHighFixableBase OS
mcr.microsoft.com/oss/go/microsoft/golang5695880Debian
mariadb43681271Ubuntu
ruby3792140Debian
eclipse-temurin3380800Ubuntu
docker.io/vllm/vllm-openai2991515333Ubuntu
wordpress2904180Debian
traefik2101783202Alpine
php1663544166Debian
docker.io/ubuntu/go14794185Ubuntu
postgres1231068123Alpine

Based on the latest public scan of each image. Scans made with credentials are never included. Guides · All image reports · Scan an image