Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-72901 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbi… Patch available Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72886 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/… Patch available Fix from $2,3002026-08-10 HIGH 8.7 CVE-2026-72884 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, sanitizeCommand in packages/server/src/utils/builders/compose.ts onl… Patch available Fix from $1,9502026-08-10 HIGH 8.8 CVE-2026-72883 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/server/wss/terminal.ts, apps/… Patch available Fix from $1,9502026-08-10 CRITICAL 9.9 CVE-2026-72882 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can create or update file mounts for … No fix yet Fix from $2,3002026-08-10 MEDIUM 6.4 CVE-2026-72881 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command builders in packages/server/src/… Patch available Fix from $1,6002026-08-10 CRITICAL 9.9 CVE-2026-72880 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in packages/server/src/db/schema/cer… Patch available Fix from $2,3002026-08-10 CRITICAL 9.4 CVE-2026-72879 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in packages/server/src/utils/clust… Patch available Fix from $2,3002026-08-10 CRITICAL 9.6 CVE-2026-72878 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's backup and restore pipeline constructs shell commands by d… Patch available Fix from $2,3002026-08-10 CRITICAL 9.6 CVE-2026-72877 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated without quoting into shell com… Patch available Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72876 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getA… Patch available Fix from $2,3002026-08-10 HIGH 8.8 CVE-2026-72875 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, settings.readTraefikFile in apps/dokploy/server/api/routers/settings… Patch available Fix from $1,9502026-08-10 HIGH 8.7 CVE-2026-72874 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, cloneGitRepository in packages/server/src/utils/providers/git.ts int… Patch available Fix from $1,9502026-08-10 MEDIUM 6.5 CVE-2026-72873 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/api/routers/application.ts re… Patch available Fix from $1,6002026-08-10 HIGH 8.8 CVE-2026-71966 CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated command injection vulnerability in the remote backup transfer feature that allow… Patch available Fix from $1,9502026-08-10 HIGH 8.8 CVE-2026-71965 CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote backup feature that allows aut… Patch available Fix from $1,9502026-08-10 HIGH 8.8 CVE-2026-69118 Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execut… No fix yet Fix from $1,9502026-08-10 MEDIUM 6.1 CVE-2026-69116 FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives. Attackers can inject malicio… Patch available Fix from $1,6002026-08-10 MEDIUM 6.5 CVE-2026-69114 Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and bulk-delete message handlers t… Patch available Fix from $1,6002026-08-10 HIGH 7.1 CVE-2026-69112 Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions… Patch available Fix from $1,9502026-08-10 HIGH 8.2 CVE-2026-14886 Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may allow an authenticated call… No fix yet Fix from $1,9502026-08-10 HIGH 8.8 CVE-2025-15683 TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An unauthenticated remote attack… No fix yet Fix from $1,9502026-08-10 HIGH 8.7 CVE-2025-15682 TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server. An unauthenticated remote attacker can… No fix yet Fix from $1,9502026-08-10 CRITICAL 9.2 CVE-2025-15681 TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authenticated to the device, an unauth… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.3 CVE-2025-13294 An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacke… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.3 CVE-2025-13293 A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level acces… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72872 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucke… Patch available Fix from $2,3002026-08-10 HIGH 7.5 CVE-2026-72871 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/github/setup route in apps/dokplo… Patch available Fix from $1,9502026-08-10 HIGH 8.7 CVE-2026-72870 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the buildRemoteDocker() function in packages/server/src/utils/provid… Patch available Fix from $1,9502026-08-10 CRITICAL 9.9 CVE-2026-72869 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databa… Patch available Fix from $2,3002026-08-10