Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48919
Total
3931
Critical
14503
High
14257
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-72886 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/api/routers/schedule.ts derive serviceId from applicationId or composeId … | Aug 10, 2026 |
| CVE-2026-72885 | UNKNOWN | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, dockerContextPath accepted by apps/dokploy/components/dashboard/application/build/show.tsx flows through getDockerContextPath in packages/server/src/utils/filesystem/directory.ts into the unquoted … | Aug 10, 2026 |
| CVE-2026-72884 | UNKNOWN | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, sanitizeCommand in packages/server/src/utils/builders/compose.ts only trims whitespace and strips surrounding quotes from compose.command … | Aug 10, 2026 |
| CVE-2026-72883 | HIGH | 8.8 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/server/wss/terminal.ts, apps/dokploy/server/wss/docker-container-terminal.ts, apps/dokploy/server/wss/docker-container-logs.ts, and apps/dokploy/server/wss/docker-stats.ts validate organization membership … | Aug 10, 2026 |
| CVE-2026-72882 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can create or update file mounts for … | Aug 10, 2026 |
| CVE-2026-72881 | UNKNOWN | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command builders in packages/server/src/utils/backups/utils.ts and packages/server/src/utils/restore/utils.ts interpolate database … | Aug 10, 2026 |
| CVE-2026-72880 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in packages/server/src/db/schema/certificate.ts accepts a client-supplied certificatePath, and packages/server/src/services/certificate.ts joins … | Aug 10, 2026 |
| CVE-2026-72879 | UNKNOWN | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in packages/server/src/utils/cluster/upload.ts interpolates registry.password and registry.registryUrl directly into a … | Aug 10, 2026 |
| CVE-2026-72878 | CRITICAL | 9.6 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's backup and restore pipeline constructs shell commands by directly interpolating user-controlled … | Aug 10, 2026 |
| CVE-2026-72877 | CRITICAL | 9.6 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated without quoting into shell commands in buildRemoteDocker() … | Aug 10, 2026 |
| CVE-2026-72876 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getAppInfos in apps/dokploy/server/api/routers/swarm.ts accept another organization’s serverId without … | Aug 10, 2026 |
| CVE-2026-72875 | HIGH | 8.8 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, settings.readTraefikFile in apps/dokploy/server/api/routers/settings.ts passes a path accepted by apiReadTraefikConfig to readConfigInPath in … | Aug 10, 2026 |
| CVE-2026-72874 | UNKNOWN | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, cloneGitRepository in packages/server/src/utils/providers/git.ts interpolates customGitUrl and customGitBranch into a git clone command … | Aug 10, 2026 |
| CVE-2026-72873 | MEDIUM | 6.5 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/api/routers/application.ts returns provider relations loaded by findApplicationById in packages/server/src/services/application.ts without … | Aug 10, 2026 |
| CVE-2026-71966 | HIGH | 8.8 | CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated command injection vulnerability in the remote backup transfer feature that allows authenticated attackers to execute arbitrary … | Aug 10, 2026 |
| CVE-2026-71965 | HIGH | 8.8 | CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote backup feature that allows authenticated attackers to gain root-level … | Aug 10, 2026 |
| CVE-2026-69118 | HIGH | 8.8 | Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code. Attackers can create … | Aug 10, 2026 |
| CVE-2026-69116 | MEDIUM | 6.1 | FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives. Attackers can inject malicious scripts through … | Aug 10, 2026 |
| CVE-2026-69114 | MEDIUM | 6.5 | Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and bulk-delete message handlers that fail to scope message queries to … | Aug 10, 2026 |
| CVE-2026-69112 | HIGH | 7.1 | Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes. … | Aug 10, 2026 |
| CVE-2026-44401 | MEDIUM | 4.8 | Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that allows authenticated users with theme-configuration access to inject malicious … | Aug 10, 2026 |
| CVE-2026-14886 | HIGH | 8.2 | Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may allow an authenticated caller in one namespace to permanently delete … | Aug 10, 2026 |
| CVE-2025-15683 | UNKNOWN | — | TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An unauthenticated remote attacker can invoke specific HTTP endpoints to reboot or reset … | Aug 10, 2026 |
| CVE-2025-15682 | UNKNOWN | — | TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server. An unauthenticated remote attacker can send PUT requests to the /tmp/ endpoint, … | Aug 10, 2026 |
| CVE-2025-15681 | UNKNOWN | — | TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authenticated to the device, an unauthenticated attacker can directly … | Aug 10, 2026 |