Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

48919
Total
3931
Critical
14503
High
14257
Medium
CVE ID Severity Score Description Published
CVE-2026-72900 MEDIUM 6.5 Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database. Aug 10, 2026
CVE-2026-72899 CRITICAL 10.0 Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter. Aug 10, 2026
CVE-2026-72898 CRITICAL 10.0 Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance. Aug 10, 2026
CVE-2026-72862 CRITICAL 9.9 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsql.ts Dokploy database service deployment … Aug 10, 2026
CVE-2026-72740 CRITICAL 9.9 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git.ts parses the user-controlled customGitUrl with sanitizeRepoPathSSH and interpolates its domain into … Aug 10, 2026
CVE-2026-72739 MEDIUM 6.5 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs shell commands by interpolating compose service names and … Aug 10, 2026
CVE-2026-72738 CRITICAL 9.9 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoint in apps/dokploy/server/api/routers/backup.ts passes the search parameter through normalizeS3Path … Aug 10, 2026
CVE-2026-72737 CRITICAL 9.6 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs in apps/dokploy/server/api/routers/backup.ts accept a client-controlled destinationId and … Aug 10, 2026
CVE-2026-72736 CRITICAL 9.9 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell commands via unquoted template literal … Aug 10, 2026
CVE-2026-72735 CRITICAL 9.9 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/server/src/utils/traefik/application.ts serializes user-controlled Traefik configuration with yaml.stringify and interpolates the … Aug 10, 2026
CVE-2026-72734 HIGH 8.4 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutation in apps/dokploy/server/api/routers/server.ts accepts a caller-controlled serverId and … Aug 10, 2026
CVE-2026-72733 CRITICAL 9.9 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription builds database restore shell pipelines from the user-controlled … Aug 10, 2026
CVE-2026-72732 MEDIUM 4.3 Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse_templates endpoint exposed hidden tag names because DiscourseTemplates::TemplatesSerializer in plugins/discourse-templates/app/serializers/discourse_templates/templates_serializer.rb did … Aug 10, 2026
CVE-2026-70622 MEDIUM 6.5 tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root … Aug 10, 2026
CVE-2026-48159 UNKNOWN use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the default branch contained malicious commits da72edbde5705efcec6c62e0a3dcb73687b78dc8 through df07d5711458d8b46e11dd7afaaa21e88cafabfb that executed … Aug 10, 2026
CVE-2026-16626 UNKNOWN Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server. This issue affects JasperReports Server: from 9.0.0 before HF-9 and from 10.0.0 … Aug 10, 2026
CVE-2026-10754 UNKNOWN Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls. Aug 10, 2026
CVE-2026-72731 HIGH 7.1 Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, anyone able to run a parameterized Data Explorer query, including non-staff … Aug 10, 2026
CVE-2026-72730 HIGH 8.7 Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing stored … Aug 10, 2026
CVE-2026-72729 UNKNOWN Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-local-dates plugin rendered crafted local-date format data as HTML on sites … Aug 10, 2026
CVE-2026-72728 MEDIUM 6.3 Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed URLs that bypassed the Onebox allowlist and embedded malicious … Aug 10, 2026
CVE-2026-72727 UNKNOWN Discourse is an open-source discussion platform. Prior to 026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, a low-privileged user could place crafted content in the moderation review queue … Aug 10, 2026
CVE-2026-71577 MEDIUM 6.3 A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows … Aug 10, 2026
CVE-2026-71576 HIGH 8.5 A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after … Aug 10, 2026
CVE-2026-63623 MEDIUM 5.5 A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the … Aug 10, 2026