Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

13,088 CVEs

CVEs (13,088, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 251–275 of 13,088 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-72603 CRITICAL 9.9 2026-08-11 An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited…
CVE-2026-72911 CRITICAL Patched 9.9 2026-08-10 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doct…
CVE-2026-18948 CRITICAL 9.9 2026-08-10 A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allo…
CVE-2026-14450 CRITICAL 9.9 2026-08-10 A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-Ma…
CVE-2026-72886 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/api/routers/schedule.ts…
CVE-2026-72901 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbitrary commands on the c…
CVE-2026-72902 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to execute arbitrary commands on a local or SSH-connec…
CVE-2026-72880 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in packages/server/src/db/schema/certificate.ts accepts a c…
CVE-2026-72882 CRITICAL 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can create or update file mounts for a service can inject sh…
CVE-2026-72876 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getAppInfos in apps/dokploy…
CVE-2026-72872 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucketRepository without val…
CVE-2026-72864 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/server/wss/docker-container-…
CVE-2026-72865 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an unvalidated composePath that packages/server/src/uti…
CVE-2026-72867 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/server/src/db/schema/compose…
CVE-2026-72868 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the accessKey, secretAccessKey,…
CVE-2026-72869 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databaseName parameter to res…
CVE-2026-72863 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) authenticate the session …
CVE-2026-72862 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsql.ts Dokploy database s…
CVE-2026-72736 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell commands via unquoted template li…
CVE-2026-72738 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoint in apps/dokploy/server/api/routers/backup.ts passe…
CVE-2026-72740 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git.ts parses the user-controlled customGitUrl with san…
CVE-2026-72733 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription builds database restore shell pipelines …
CVE-2026-72735 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/server/src/utils/traefik/application.ts serializes use…
CVE-2026-61516 CRITICAL 9.8 2026-09-08 Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password…
CVE-2026-12744 CRITICAL Patched 9.8 2026-09-08 A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.