Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.9
CVE-2026-72901

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbi…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72886

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/…

Patch available
Fix from $2,300 2026-08-10
Unclassified HIGH 8.7
CVE-2026-72884

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, sanitizeCommand in packages/server/src/utils/builders/compose.ts onl…

Patch available
Fix from $1,950 2026-08-10
Unclassified HIGH 8.8
CVE-2026-72883

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/server/wss/terminal.ts, apps/…

Patch available
Fix from $1,950 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72882

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can create or update file mounts for …

No fix yet
Fix from $2,300 2026-08-10
Unclassified MEDIUM 6.4
CVE-2026-72881

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command builders in packages/server/src/…

Patch available
Fix from $1,600 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72880

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in packages/server/src/db/schema/cer…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.4
CVE-2026-72879

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in packages/server/src/utils/clust…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.6
CVE-2026-72878

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's backup and restore pipeline constructs shell commands by d…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.6
CVE-2026-72877

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated without quoting into shell com…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72876

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getA…

Patch available
Fix from $2,300 2026-08-10
Unclassified HIGH 8.8
CVE-2026-72875

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, settings.readTraefikFile in apps/dokploy/server/api/routers/settings…

Patch available
Fix from $1,950 2026-08-10
Unclassified HIGH 8.7
CVE-2026-72874

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, cloneGitRepository in packages/server/src/utils/providers/git.ts int…

Patch available
Fix from $1,950 2026-08-10
Unclassified MEDIUM 6.5
CVE-2026-72873

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/api/routers/application.ts re…

Patch available
Fix from $1,600 2026-08-10
Unclassified HIGH 8.8
CVE-2026-71966

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated command injection vulnerability in the remote backup transfer feature that allow…

Patch available
Fix from $1,950 2026-08-10
Unclassified HIGH 8.8
CVE-2026-71965

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote backup feature that allows aut…

Patch available
Fix from $1,950 2026-08-10
Unclassified HIGH 8.8
CVE-2026-69118

Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execut…

No fix yet
Fix from $1,950 2026-08-10
Unclassified MEDIUM 6.1
CVE-2026-69116

FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives. Attackers can inject malicio…

Patch available
Fix from $1,600 2026-08-10
Unclassified MEDIUM 6.5
CVE-2026-69114

Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and bulk-delete message handlers t…

Patch available
Fix from $1,600 2026-08-10
Unclassified HIGH 7.1
CVE-2026-69112

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions…

Patch available
Fix from $1,950 2026-08-10
Unclassified HIGH 8.2
CVE-2026-14886

Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may allow an authenticated call…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 8.8
CVE-2025-15683

TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An unauthenticated remote attack…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 8.7
CVE-2025-15682

TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server. An unauthenticated remote attacker can…

No fix yet
Fix from $1,950 2026-08-10
Unclassified CRITICAL 9.2
CVE-2025-15681

TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authenticated to the device, an unauth…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.3
CVE-2025-13294

An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacke…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.3
CVE-2025-13293

A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level acces…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72872

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucke…

Patch available
Fix from $2,300 2026-08-10
Unclassified HIGH 7.5
CVE-2026-72871

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/github/setup route in apps/dokplo…

Patch available
Fix from $1,950 2026-08-10
Unclassified HIGH 8.7
CVE-2026-72870

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the buildRemoteDocker() function in packages/server/src/utils/provid…

Patch available
Fix from $1,950 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72869

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databa…

Patch available
Fix from $2,300 2026-08-10