Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.9
CVE-2026-72864

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/serve…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72863

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) au…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 10.0
CVE-2026-72899

Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) p…

No fix yet
Fix from $2,300 2026-08-10
Metabase CRITICAL 10.0
CVE-2026-72898 KEVEPSS 10%

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access …

Fix: 0.58.24 / 0.59.21+
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72862

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsq…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72740

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git.ts parses the user-controlle…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72738

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoint in apps/dokploy/server/api/…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.6
CVE-2026-72737

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs …

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72736

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell commands v…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72735

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/server/src/utils/traefik/applic…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72733

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription builds database r…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.3
CVE-2026-48159

use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the default branch contained malicio…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.3
CVE-2026-16626

Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server. This issue affects JasperR…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.3
CVE-2026-48158

use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34, the default branch contained…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.3
CVE-2026-47754

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions conta…

Patch available
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.1
CVE-2026-18412

OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 extension installer extracts these…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-63106

ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the pr…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-68426

In the Linux kernel, the following vulnerability has been resolved: xfrm: fix stale skb->prev after async crypto steals a GSO segment skb_gso_segme…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-68388

In the Linux kernel, the following vulnerability has been resolved: smb/client: handle overlapping allocated ranges in fallocate smb3_simple_falloc…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-68385

In the Linux kernel, the following vulnerability has been resolved: s390/checksum: Fix csum_partial() without vector facility Currently csum_partia…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-68381

In the Linux kernel, the following vulnerability has been resolved: ksmbd: pin conn during async oplock break notification smb2_oplock_break_noti()…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.1
CVE-2026-68343

In the Linux kernel, the following vulnerability has been resolved: smb: client: validate DFS referral PathConsumed parse_dfs_referrals() validates…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-68302

In the Linux kernel, the following vulnerability has been resolved: amt: re-read skb header pointers after every pull Several AMT receive and trans…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-68300

In the Linux kernel, the following vulnerability has been resolved: sctp: auth: verify auth requirement when auth_chunk is NULL sctp_auth_chunk_ver…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-68170

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix stale skb->sk reference on subflow close The backlog list is updated…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-68161

In the Linux kernel, the following vulnerability has been resolved: sctp: close UDP tunnel sockets during netns teardown proc_sctp_do_udp_port() st…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-68160

In the Linux kernel, the following vulnerability has been resolved: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() ceph_h…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-68159

In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE __decode_…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-68158

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix multiplication overflow in decode_new_up_state_weight() If a messa…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-68156

In the Linux kernel, the following vulnerability has been resolved: libceph: refresh auth->authorizer_buf{,_len} after authorizer update ceph_x_cre…

No fix yet
Fix from $2,300 2026-08-10