Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.1
CVE-2026-44758

SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected fu…

No fix yet
Fix from $2,300 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-34265

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corr…

No fix yet
Fix from $2,300 2026-08-11
Unclassified CRITICAL 9.3
CVE-2026-48161

react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contained malicious commits 7b79148d…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72911

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls i…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.3
CVE-2026-72904

Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in …

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.3
CVE-2026-48160

react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the default branch contained malicious…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-18948

A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'd…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-14450

A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP head…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72902

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to execute arbitrary commands o…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72901

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbi…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72886

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72882

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can create or update file mounts for …

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72880

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in packages/server/src/db/schema/cer…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.4
CVE-2026-72879

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in packages/server/src/utils/clust…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.6
CVE-2026-72878

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's backup and restore pipeline constructs shell commands by d…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.6
CVE-2026-72877

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated without quoting into shell com…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72876

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getA…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.2
CVE-2025-15681

TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authenticated to the device, an unauth…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.3
CVE-2025-13294

An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacke…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.3
CVE-2025-13293

A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level acces…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72872

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucke…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72869

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databa…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72868

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the acce…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72867

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/serve…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72865

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an unvalidated composePath that …

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72864

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/serve…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72863

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) au…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 10.0
CVE-2026-72899

Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) p…

No fix yet
Fix from $2,300 2026-08-10
Metabase CRITICAL 10.0
CVE-2026-72898 KEVEPSS 10%

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access …

Fix: 0.58.24 / 0.59.21+
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72862

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsq…

Patch available
Fix from $2,300 2026-08-10