Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-72864 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/serve… Patch available Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72863 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) au… Patch available Fix from $2,3002026-08-10 CRITICAL 10.0 CVE-2026-72899 Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) p… No fix yet Fix from $2,3002026-08-10 CRITICAL 10.0 CVE-2026-72898 KEVEPSS 10% Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access … Metabase 0.58.24 / 0.59.21+ Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72862 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsq… Patch available Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72740 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git.ts parses the user-controlle… Patch available Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72738 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoint in apps/dokploy/server/api/… Patch available Fix from $2,3002026-08-10 CRITICAL 9.6 CVE-2026-72737 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs … No fix yet Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72736 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell commands v… Patch available Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72735 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/server/src/utils/traefik/applic… Patch available Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72733 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription builds database r… Patch available Fix from $2,3002026-08-10 CRITICAL 9.3 CVE-2026-48159 use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the default branch contained malicio… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.3 CVE-2026-16626 Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server. This issue affects JasperR… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.3 CVE-2026-48158 use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34, the default branch contained… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.3 CVE-2026-47754 Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions conta… Patch available Fix from $2,3002026-08-10 CRITICAL 9.1 CVE-2026-18412 OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 extension installer extracts these… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-63106 ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the pr… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-68426 In the Linux kernel, the following vulnerability has been resolved: xfrm: fix stale skb->prev after async crypto steals a GSO segment skb_gso_segme… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-68388 In the Linux kernel, the following vulnerability has been resolved: smb/client: handle overlapping allocated ranges in fallocate smb3_simple_falloc… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-68385 In the Linux kernel, the following vulnerability has been resolved: s390/checksum: Fix csum_partial() without vector facility Currently csum_partia… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-68381 In the Linux kernel, the following vulnerability has been resolved: ksmbd: pin conn during async oplock break notification smb2_oplock_break_noti()… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.1 CVE-2026-68343 In the Linux kernel, the following vulnerability has been resolved: smb: client: validate DFS referral PathConsumed parse_dfs_referrals() validates… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-68302 In the Linux kernel, the following vulnerability has been resolved: amt: re-read skb header pointers after every pull Several AMT receive and trans… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-68300 In the Linux kernel, the following vulnerability has been resolved: sctp: auth: verify auth requirement when auth_chunk is NULL sctp_auth_chunk_ver… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-68170 In the Linux kernel, the following vulnerability has been resolved: mptcp: fix stale skb->sk reference on subflow close The backlog list is updated… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-68161 In the Linux kernel, the following vulnerability has been resolved: sctp: close UDP tunnel sockets during netns teardown proc_sctp_do_udp_port() st… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-68160 In the Linux kernel, the following vulnerability has been resolved: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() ceph_h… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-68159 In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE __decode_… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-68158 In the Linux kernel, the following vulnerability has been resolved: libceph: Fix multiplication overflow in decode_new_up_state_weight() If a messa… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-68156 In the Linux kernel, the following vulnerability has been resolved: libceph: refresh auth->authorizer_buf{,_len} after authorizer update ceph_x_cre… No fix yet Fix from $2,3002026-08-10