Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48919
Total
3931
Critical
14503
High
14257
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-15680 | UNKNOWN | — | TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A physically proximate attacker can connect to the UART interface … | Aug 10, 2026 |
| CVE-2025-13294 | UNKNOWN | — | An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacker-controlled parameters directly into SQLite queries without … | Aug 10, 2026 |
| CVE-2025-13293 | UNKNOWN | — | A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level access to the device via the … | Aug 10, 2026 |
| CVE-2026-72872 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucketRepository without validation and cloneBitbucketRepository in packages/server/src/utils/providers/bitbucket.ts interpolates … | Aug 10, 2026 |
| CVE-2026-72871 | HIGH | 7.5 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/github/setup route in apps/dokploy/pages/api/providers/github/setup.ts trusts gh_init organizationId and userId values … | Aug 10, 2026 |
| CVE-2026-72870 | UNKNOWN | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the buildRemoteDocker() function in packages/server/src/utils/providers/docker.ts interpolates the application-controlled dockerImage value directly into … | Aug 10, 2026 |
| CVE-2026-72869 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databaseName parameter to restore builders in … | Aug 10, 2026 |
| CVE-2026-72868 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the accessKey, secretAccessKey, region, endpoint, provider, and bucket fields from … | Aug 10, 2026 |
| CVE-2026-72867 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/server/src/db/schema/compose.ts branch fields without server-side … | Aug 10, 2026 |
| CVE-2026-72866 | HIGH | 8.8 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/server/wss/terminal.ts validates a session but does not authorize … | Aug 10, 2026 |
| CVE-2026-72865 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an unvalidated composePath that packages/server/src/utils/builders/compose.ts and packages/server/src/services/compose.ts interpolate … | Aug 10, 2026 |
| CVE-2026-72864 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/server/wss/docker-container-terminal.ts authenticates with validateRequest but does … | Aug 10, 2026 |
| CVE-2026-72863 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) authenticate the session but … | Aug 10, 2026 |
| CVE-2026-71969 | MEDIUM | 6.7 | OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt and decrypt operations within the mbedTLS software … | Aug 10, 2026 |
| CVE-2026-71968 | MEDIUM | 6.7 | OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers with the ability to load … | Aug 10, 2026 |
| CVE-2026-71967 | MEDIUM | 5.5 | OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pseudo-TA open_session handler that allows Normal World clients … | Aug 10, 2026 |
| CVE-2026-71964 | MEDIUM | 6.5 | CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component that allows authenticated attackers to read sensitive system … | Aug 10, 2026 |
| CVE-2026-71962 | HIGH | 7.5 | Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that allows unauthenticated attackers to access private files by exploiting … | Aug 10, 2026 |
| CVE-2026-6791 | UNKNOWN | — | When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home … | Aug 10, 2026 |
| CVE-2026-6368 | UNKNOWN | — | Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv … | Aug 10, 2026 |
| CVE-2026-68872 | MEDIUM | 6.5 | The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic … | Aug 10, 2026 |
| CVE-2026-68871 | UNKNOWN | — | The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup … | Aug 10, 2026 |
| CVE-2026-68870 | UNKNOWN | — | The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the … | Aug 10, 2026 |
| CVE-2026-59091 | HIGH | 7.3 | A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by tricking … | Aug 10, 2026 |
| CVE-2026-12339 | UNKNOWN | — | A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator … | Aug 10, 2026 |