Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,217 CVEs

CVEs (30,217, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 401–425 of 30,217 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-72902 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to execute arbitrary commands on a local or SSH-connec…
CVE-2026-72880 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in packages/server/src/db/schema/certificate.ts accepts a c…
CVE-2026-72882 CRITICAL 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can create or update file mounts for a service can inject sh…
CVE-2026-72876 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getAppInfos in apps/dokploy…
CVE-2026-72872 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucketRepository without val…
CVE-2026-72864 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/server/wss/docker-container-…
CVE-2026-72865 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an unvalidated composePath that packages/server/src/uti…
CVE-2026-72867 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/server/src/db/schema/compose…
CVE-2026-72868 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the accessKey, secretAccessKey,…
CVE-2026-72869 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databaseName parameter to res…
CVE-2026-72863 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) authenticate the session …
CVE-2026-72862 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsql.ts Dokploy database s…
CVE-2026-72736 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell commands via unquoted template li…
CVE-2026-72738 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoint in apps/dokploy/server/api/routers/backup.ts passe…
CVE-2026-72740 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git.ts parses the user-controlled customGitUrl with san…
CVE-2026-72733 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription builds database restore shell pipelines …
CVE-2026-72735 CRITICAL Patched 9.9 2026-08-10 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/server/src/utils/traefik/application.ts serializes use…
CVE-2026-64637 CRITICAL Patched 9.9 2026-08-07 Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
CVE-2026-62830 CRITICAL 9.9 2026-08-07 Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
CVE-2026-59115 CRITICAL 9.9 2026-08-07 '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
CVE-2026-50515 CRITICAL 9.9 2026-08-07 Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
CVE-2026-50481 CRITICAL 9.9 2026-08-07 Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
CVE-2026-67622 CRITICAL 9.9 2026-08-06 Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credenti…
CVE-2026-48086 CRITICAL 9.9 2026-08-06 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to pl…
CVE-2026-65548 CRITICAL 9.9 2026-08-06 Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.