Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.7 CVE-2026-72874 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, cloneGitRepository in packages/server/src/utils/providers/git.ts int… No fix yet Fix from $4,9002026-08-10 HIGH 8.8 CVE-2026-72875 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, settings.readTraefikFile in apps/dokploy/server/api/routers/settings… No fix yet Fix from $4,9002026-08-10 CRITICAL 9.9 CVE-2026-72876 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getA… No fix yet Fix from $5,7502026-08-10 HIGH 8.8 CVE-2026-71966 CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated command injection vulnerability in the remote backup transfer feature that allow… No fix yet Fix from $4,9002026-08-10 CRITICAL 9.9 CVE-2026-72872 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucke… No fix yet Fix from $5,7502026-08-10 CRITICAL 9.9 CVE-2026-72865 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an unvalidated composePath that … No fix yet Fix from $5,7502026-08-10 CRITICAL 9.9 CVE-2026-72867 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/serve… No fix yet Fix from $5,7502026-08-10 CRITICAL 9.9 CVE-2026-72868 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the acce… No fix yet Fix from $5,7502026-08-10 CRITICAL 9.9 CVE-2026-72869 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databa… No fix yet Fix from $5,7502026-08-10 HIGH 8.7 CVE-2026-72870 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the buildRemoteDocker() function in packages/server/src/utils/provid… No fix yet Fix from $4,9002026-08-10 CRITICAL 9.9 CVE-2026-72862 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsq… No fix yet Fix from $5,7502026-08-10 CRITICAL 9.9 CVE-2026-72738 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoint in apps/dokploy/server/api/… No fix yet Fix from $5,7502026-08-10 MEDIUM 6.5 CVE-2026-72739 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs shell commands by interpolat… No fix yet Fix from $4,0002026-08-10 CRITICAL 9.9 CVE-2026-72740 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git.ts parses the user-controlle… No fix yet Fix from $5,7502026-08-10 CRITICAL 9.9 CVE-2026-72733 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription builds database r… No fix yet Fix from $5,7502026-08-10 CRITICAL 9.8 CVE-2026-13206 Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command … No fix yet Fix from $5,7502026-08-10 CRITICAL 9.8 CVE-2026-72589 An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to execute arbitrary system … No fix yet Fix from $5,7502026-08-10 HIGH 8.8 CVE-2026-72573 An OS command injection vulnerability in 4xmen/pm2panel (all versions) allows an authenticated remote attacker to execute arbitrary system commands o… No fix yet Fix from $4,9002026-08-10 HIGH 7.5 CVE-2026-72579 An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjacent attacker who can intercept or spoof responses from ocea… No fix yet Fix from $4,9002026-08-10 CRITICAL 9.8 CVE-2026-72580 An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to execute arbitrary system commands on X… No fix yet Fix from $5,7502026-08-10 HIGH 7.3 CVE-2026-19379 A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. Th… No fix yet Fix from $4,9002026-08-10 CRITICAL 9.8 CVE-2026-71990 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration tha… No fix yet Fix from $5,7502026-08-09 CRITICAL 9.8 CVE-2026-71991 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration … No fix yet Fix from $5,7502026-08-09 CRITICAL 9.8 CVE-2026-71992 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers t… No fix yet Fix from $5,7502026-08-09 CRITICAL 9.8 CVE-2026-71993 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to … No fix yet Fix from $5,7502026-08-09 CRITICAL 9.8 CVE-2026-71984 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers t… No fix yet Fix from $5,7502026-08-09 CRITICAL 9.8 CVE-2026-71985 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attacke… No fix yet Fix from $5,7502026-08-09 CRITICAL 9.8 CVE-2026-71986 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to exec… No fix yet Fix from $5,7502026-08-09 CRITICAL 9.8 CVE-2026-71987 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to exec… No fix yet Fix from $5,7502026-08-09 CRITICAL 9.8 CVE-2026-71988 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to e… No fix yet Fix from $5,7502026-08-09