Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48919
Total
3931
Critical
14503
High
14257
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-72900 | MEDIUM | 6.5 | Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database. | Aug 10, 2026 |
| CVE-2026-72899 | CRITICAL | 10.0 | Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter. | Aug 10, 2026 |
| CVE-2026-72898 | CRITICAL | 10.0 | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance. | Aug 10, 2026 |
| CVE-2026-72862 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsql.ts Dokploy database service deployment … | Aug 10, 2026 |
| CVE-2026-72740 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git.ts parses the user-controlled customGitUrl with sanitizeRepoPathSSH and interpolates its domain into … | Aug 10, 2026 |
| CVE-2026-72739 | MEDIUM | 6.5 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs shell commands by interpolating compose service names and … | Aug 10, 2026 |
| CVE-2026-72738 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoint in apps/dokploy/server/api/routers/backup.ts passes the search parameter through normalizeS3Path … | Aug 10, 2026 |
| CVE-2026-72737 | CRITICAL | 9.6 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs in apps/dokploy/server/api/routers/backup.ts accept a client-controlled destinationId and … | Aug 10, 2026 |
| CVE-2026-72736 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell commands via unquoted template literal … | Aug 10, 2026 |
| CVE-2026-72735 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/server/src/utils/traefik/application.ts serializes user-controlled Traefik configuration with yaml.stringify and interpolates the … | Aug 10, 2026 |
| CVE-2026-72734 | HIGH | 8.4 | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutation in apps/dokploy/server/api/routers/server.ts accepts a caller-controlled serverId and … | Aug 10, 2026 |
| CVE-2026-72733 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription builds database restore shell pipelines from the user-controlled … | Aug 10, 2026 |
| CVE-2026-72732 | MEDIUM | 4.3 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse_templates endpoint exposed hidden tag names because DiscourseTemplates::TemplatesSerializer in plugins/discourse-templates/app/serializers/discourse_templates/templates_serializer.rb did … | Aug 10, 2026 |
| CVE-2026-70622 | MEDIUM | 6.5 | tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root … | Aug 10, 2026 |
| CVE-2026-48159 | UNKNOWN | — | use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the default branch contained malicious commits da72edbde5705efcec6c62e0a3dcb73687b78dc8 through df07d5711458d8b46e11dd7afaaa21e88cafabfb that executed … | Aug 10, 2026 |
| CVE-2026-16626 | UNKNOWN | — | Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server. This issue affects JasperReports Server: from 9.0.0 before HF-9 and from 10.0.0 … | Aug 10, 2026 |
| CVE-2026-10754 | UNKNOWN | — | Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls. | Aug 10, 2026 |
| CVE-2026-72731 | HIGH | 7.1 | Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, anyone able to run a parameterized Data Explorer query, including non-staff … | Aug 10, 2026 |
| CVE-2026-72730 | HIGH | 8.7 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing stored … | Aug 10, 2026 |
| CVE-2026-72729 | UNKNOWN | — | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-local-dates plugin rendered crafted local-date format data as HTML on sites … | Aug 10, 2026 |
| CVE-2026-72728 | MEDIUM | 6.3 | Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed URLs that bypassed the Onebox allowlist and embedded malicious … | Aug 10, 2026 |
| CVE-2026-72727 | UNKNOWN | — | Discourse is an open-source discussion platform. Prior to 026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, a low-privileged user could place crafted content in the moderation review queue … | Aug 10, 2026 |
| CVE-2026-71577 | MEDIUM | 6.3 | A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows … | Aug 10, 2026 |
| CVE-2026-71576 | HIGH | 8.5 | A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after … | Aug 10, 2026 |
| CVE-2026-63623 | MEDIUM | 5.5 | A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the … | Aug 10, 2026 |