Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.9
CVE-2026-72868

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the acce…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72867

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/serve…

Patch available
Fix from $2,300 2026-08-10
Unclassified HIGH 8.8
CVE-2026-72866

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/server/wss/terminal.ts validat…

Patch available
Fix from $1,950 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72865

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an unvalidated composePath that …

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72864

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/serve…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72863

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) au…

Patch available
Fix from $2,300 2026-08-10
Unclassified MEDIUM 6.7
CVE-2026-71969

OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt and decrypt operations within …

Patch available
Fix from $1,600 2026-08-10
Unclassified MEDIUM 6.7
CVE-2026-71968

OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers wi…

Patch available
Fix from $1,600 2026-08-10
Unclassified MEDIUM 5.5
CVE-2026-71967

OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pseudo-TA open_session handler t…

Patch available
Fix from $1,600 2026-08-10
Unclassified MEDIUM 6.5
CVE-2026-71964

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component that allows authenticated atta…

Patch available
Fix from $1,600 2026-08-10
Unclassified HIGH 7.5
CVE-2026-71962

Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that …

No fix yet
Fix from $1,950 2026-08-10
Apache Airflow Providers Apache Yandex MEDIUM 6.5
CVE-2026-68871

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic loo…

Fix: 4.5.1+
Fix from $1,600 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-68870

The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variable id through the team-ag…

Patch available
Fix from $1,600 2026-08-10
Apache Airflow Providers Amazon MEDIUM 6.5
CVE-2026-68872

The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variabl…

Fix: 9.34.0+
Fix from $1,600 2026-08-10
Unclassified MEDIUM 6.6
CVE-2026-6791

When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the use…

No fix yet
Fix from $1,600 2026-08-10
Enterprise Linux HIGH 7.8
CVE-2026-59091

A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by trick…

No fix yet
Fix from $1,950 2026-08-10
Unclassified MEDIUM 6.9
CVE-2026-12339

A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequ…

No fix yet
Fix from $1,600 2026-08-10
Unclassified MEDIUM 6.5
CVE-2026-72900

Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.

No fix yet
Fix from $1,600 2026-08-10
Unclassified CRITICAL 10.0
CVE-2026-72899

Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) p…

No fix yet
Fix from $2,300 2026-08-10
Metabase CRITICAL 10.0
CVE-2026-72898 KEVEPSS 10%

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access …

Fix: 0.58.24 / 0.59.21+
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72862

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsq…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72740

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git.ts parses the user-controlle…

Patch available
Fix from $2,300 2026-08-10
Unclassified MEDIUM 6.5
CVE-2026-72739

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs shell commands by interpolat…

Patch available
Fix from $1,600 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72738

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoint in apps/dokploy/server/api/…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.6
CVE-2026-72737

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs …

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72736

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell commands v…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72735

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/server/src/utils/traefik/applic…

Patch available
Fix from $2,300 2026-08-10
Unclassified HIGH 8.4
CVE-2026-72734

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutation in apps/dokploy/server/api/…

Patch available
Fix from $1,950 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72733

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription builds database r…

Patch available
Fix from $2,300 2026-08-10
Unclassified MEDIUM 6.5
CVE-2026-70622

tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read …

No fix yet
Fix from $1,600 2026-08-10