Search
30,217 CVEs
CVEs (30,217, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 30,217 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-72902 | CRITICAL | Patched | 9.9 | 2026-08-10 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to execute arbitrary commands on a local or SSH-connec… |
| CVE-2026-72880 | CRITICAL | Patched | 9.9 | 2026-08-10 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in packages/server/src/db/schema/certificate.ts accepts a c… |
| CVE-2026-72882 | CRITICAL | 9.9 | 2026-08-10 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can create or update file mounts for a service can inject sh… | |
| CVE-2026-72876 | CRITICAL | Patched | 9.9 | 2026-08-10 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getAppInfos in apps/dokploy… |
| CVE-2026-72872 | CRITICAL | Patched | 9.9 | 2026-08-10 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucketRepository without val… |
| CVE-2026-72864 | CRITICAL | Patched | 9.9 | 2026-08-10 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/server/wss/docker-container-… |
| CVE-2026-72865 | CRITICAL | Patched | 9.9 | 2026-08-10 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an unvalidated composePath that packages/server/src/uti… |
| CVE-2026-72867 | CRITICAL | Patched | 9.9 | 2026-08-10 | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/server/src/db/schema/compose… |
| CVE-2026-72868 | CRITICAL | Patched | 9.9 | 2026-08-10 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the accessKey, secretAccessKey,… |
| CVE-2026-72869 | CRITICAL | Patched | 9.9 | 2026-08-10 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databaseName parameter to res… |
| CVE-2026-72863 | CRITICAL | Patched | 9.9 | 2026-08-10 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) authenticate the session … |
| CVE-2026-72862 | CRITICAL | Patched | 9.9 | 2026-08-10 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsql.ts Dokploy database s… |
| CVE-2026-72736 | CRITICAL | Patched | 9.9 | 2026-08-10 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell commands via unquoted template li… |
| CVE-2026-72738 | CRITICAL | Patched | 9.9 | 2026-08-10 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoint in apps/dokploy/server/api/routers/backup.ts passe… |
| CVE-2026-72740 | CRITICAL | Patched | 9.9 | 2026-08-10 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git.ts parses the user-controlled customGitUrl with san… |
| CVE-2026-72733 | CRITICAL | Patched | 9.9 | 2026-08-10 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription builds database restore shell pipelines … |
| CVE-2026-72735 | CRITICAL | Patched | 9.9 | 2026-08-10 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/server/src/utils/traefik/application.ts serializes use… |
| CVE-2026-64637 | CRITICAL | Patched | 9.9 | 2026-08-07 | Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account. |
| CVE-2026-62830 | CRITICAL | 9.9 | 2026-08-07 | Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-59115 | CRITICAL | 9.9 | 2026-08-07 | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-50515 | CRITICAL | 9.9 | 2026-08-07 | Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. | |
| CVE-2026-50481 | CRITICAL | 9.9 | 2026-08-07 | Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-67622 | CRITICAL | 9.9 | 2026-08-06 | Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credenti… | |
| CVE-2026-48086 | CRITICAL | 9.9 | 2026-08-06 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to pl… | |
| CVE-2026-65548 | CRITICAL | 9.9 | 2026-08-06 | Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions. |