Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-72868 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the acce… Patch available Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72867 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/serve… Patch available Fix from $2,3002026-08-10 HIGH 8.8 CVE-2026-72866 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/server/wss/terminal.ts validat… Patch available Fix from $1,9502026-08-10 CRITICAL 9.9 CVE-2026-72865 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an unvalidated composePath that … Patch available Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72864 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/serve… Patch available Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72863 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) au… Patch available Fix from $2,3002026-08-10 MEDIUM 6.7 CVE-2026-71969 OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt and decrypt operations within … Patch available Fix from $1,6002026-08-10 MEDIUM 6.7 CVE-2026-71968 OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers wi… Patch available Fix from $1,6002026-08-10 MEDIUM 5.5 CVE-2026-71967 OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pseudo-TA open_session handler t… Patch available Fix from $1,6002026-08-10 MEDIUM 6.5 CVE-2026-71964 CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component that allows authenticated atta… Patch available Fix from $1,6002026-08-10 HIGH 7.5 CVE-2026-71962 Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that … No fix yet Fix from $1,9502026-08-10 MEDIUM 6.5 CVE-2026-68871 The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic loo… Apache Airflow Providers Apache Yandex 4.5.1+ Fix from $1,6002026-08-10 MEDIUM 5.3 CVE-2026-68870 The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variable id through the team-ag… Patch available Fix from $1,6002026-08-10 MEDIUM 6.5 CVE-2026-68872 The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variabl… Apache Airflow Providers Amazon 9.34.0+ Fix from $1,6002026-08-10 MEDIUM 6.6 CVE-2026-6791 When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the use… No fix yet Fix from $1,6002026-08-10 HIGH 7.8 CVE-2026-59091 A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by trick… Enterprise Linux No fix yet Fix from $1,9502026-08-10 MEDIUM 6.9 CVE-2026-12339 A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequ… No fix yet Fix from $1,6002026-08-10 MEDIUM 6.5 CVE-2026-72900 Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database. No fix yet Fix from $1,6002026-08-10 CRITICAL 10.0 CVE-2026-72899 Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) p… No fix yet Fix from $2,3002026-08-10 CRITICAL 10.0 CVE-2026-72898 KEVEPSS 10% Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access … Metabase 0.58.24 / 0.59.21+ Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72862 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsq… Patch available Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72740 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git.ts parses the user-controlle… Patch available Fix from $2,3002026-08-10 MEDIUM 6.5 CVE-2026-72739 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs shell commands by interpolat… Patch available Fix from $1,6002026-08-10 CRITICAL 9.9 CVE-2026-72738 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoint in apps/dokploy/server/api/… Patch available Fix from $2,3002026-08-10 CRITICAL 9.6 CVE-2026-72737 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs … No fix yet Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72736 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell commands v… Patch available Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72735 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/server/src/utils/traefik/applic… Patch available Fix from $2,3002026-08-10 HIGH 8.4 CVE-2026-72734 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutation in apps/dokploy/server/api/… Patch available Fix from $1,9502026-08-10 CRITICAL 9.9 CVE-2026-72733 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription builds database r… Patch available Fix from $2,3002026-08-10 MEDIUM 6.5 CVE-2026-70622 tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read … No fix yet Fix from $1,6002026-08-10