Skip to content
  • GDPR-compliant
  • 100% hosting in Germany
  • Personal contact
  • Support included
  • Provisioning within 24 hours
Operations & plan 4 min read

Security tab: vulnerabilities of all containers at a glance

We check every version of an image for known vulnerabilities before it starts for the first time (Security in Container Hosting). The Security tab of your project summarises the results of all containers. You see at a glance where action is needed and which vulnerabilities can already be fixed. The number on the tab shows the critical findings in the whole project.

The overview

At the top you see how many containers your project has and how many of them have been checked. Three cards follow below:

  • Total vulnerabilities - all known vulnerabilities of your containers, split by severity: critical, high, medium and low. The text above states how many critical and high findings already have a fix.
  • Containers with the most findings - the containers with the most critical and high findings. Clicking the name opens the container page.
  • Most dangerous vulnerabilities - the vulnerabilities with the highest rating, with severity, CVSS score, affected package and the containers that contain them. The name of the vulnerability (for example CVE-2025-12345) links to the public description.
Security tab of a project with total vulnerabilities, the containers with the most findings and the most dangerous vulnerabilities
The overview: vulnerabilities by severity, the containers with the most findings and the most dangerous vulnerabilities.

All critical and high findings

The list below shows every critical and high finding individually: the vulnerability with a short description, the container, the severity, the CVSS score, the affected package with its version and the version in which the vulnerability is fixed. Use the filters to narrow down the list:

  • Severity - only critical or only high findings.
  • Container - only the findings of one container.
  • Search - for a CVE number, a package or a container.
  • Only with fix - only findings that already have a fix. This is the best place to start.

With many findings you browse page by page and choose whether 25, 50 or 100 findings appear per page.

List of critical and high findings with filters for severity and container, search and the column Fixed in
The list of findings, here filtered to critical findings, with the affected package and the column “Fixed in”.

Assessing and fixing findings

The findings come from packages in the image, often from the bundled operating system. Whether your application is affected depends on whether it uses the package. Proceed as follows:

  1. Findings with a fix first - if the column Fixed in shows a version, a newer state of the image usually helps. Create a snapshot beforehand (Backup and snapshot).
  2. New state of the same version - click Recreate on the container page. The container then takes over the most recently checked state of its version.
  3. New version - if the vulnerability remains, enter a newer version in the container settings (Updating containers). If there is a checked version with fewer findings, the Security tab points this out and the container page suggests it.

Findings marked no fix yet have not yet been fixed by the vendor. They usually disappear with one of the next states. Until then, reduce the risk by publishing only the services you need and running databases in an internal network (Networks and firewall).

Where do I start?

  1. Critical findings with a fix in containers that can be reached from the internet.
  2. High findings with a fix in these containers.
  3. Findings in containers that can only be reached internally, such as databases.

A medium or low finding is rarely urgent. It is usually fixed along with the next update.

Why does my container have so many findings even though I use a current version?
Images include many packages, such as operating system libraries. New vulnerabilities become known every day, and it often takes some time until vendors publish a new state. Many findings concern packages that your application does not use at all.
How often are my containers checked?
We check every version before it starts for the first time. Versions used by your containers are checked again once a week. This way, new vulnerabilities also appear for images that have not changed, and for moving versions such as latest we fetch the current state.
What does “not checked” mean?
There is no check result for these containers yet, for example because the check of a new version is still running. They appear in the overview as soon as the check is complete.
Why does it say “Details follow after the next check”?
For older checks we only know the number of findings, not the individual vulnerabilities. They appear in the list after the next check.
Are containers stopped because of findings?
No. We do not change running containers because of findings. Only before a version with critical or high findings starts for the first time do you confirm the risk.

Was this article helpful?

New to SpeedIT Solutions?

Hosting where you know someone.

What you are reading here is what we put into practice for our customers every day. Based in Isernhagen since 2009 - with dedicated contact persons rather than a call centre.

  • 100% hosted in Germany
  • GDPR-compliant
  • Dedicated contact person
  • Provisioning within 24 hours
4.9 88 reviews on Expeero

Bester Hoster Überhaupt

Ich bin mit allem zu 100% zufrieden. Ich nutze diesen Anbietern schon jahrelang! Nie Probleme gehabt.
Michael G.Recommends us · 08/07/2026

100 % recommend us · Expeero

All reviews on HOSTtest (opens in a new window)

You might also be interested in:

Personal support

Of course, our support team is also happy to assist you personally. If you cannot find what you are looking for in our knowledge base or require personalised support, please do not hesitate to contact us. We’re here to help you and to ensure that your experience with our products and services is as smooth and enjoyable as possible.