2026 CVE Vulnerabilities
47,701 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-72871 | HIGH | 7.5 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/gith... |
| CVE-2026-72870 | HIGH | 8.7 | 0.3% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the buildRemoteDocker() function in pac... |
| CVE-2026-72869 | CRITICAL | 9.9 | 0.4% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC s... |
| CVE-2026-72868 | CRITICAL | 9.9 | 0.4% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destina... |
| CVE-2026-72867 | CRITICAL | 9.9 | 0.5% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-202... |
| CVE-2026-72866 | HIGH | 8.8 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/s... |
| CVE-2026-72865 | CRITICAL | 9.9 | 0.4% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an ... |
| CVE-2026-72864 | CRITICAL | 9.9 | 0.3% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-t... |
| CVE-2026-72863 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app te... |
| CVE-2026-71969 | MEDIUM | 6.7 | 0.1% | Aug 10, 2026 | OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt a... |
| CVE-2026-71968 | MEDIUM | 6.7 | 0.1% | Aug 10, 2026 | OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application lo... |
| CVE-2026-71967 | MEDIUM | 5.7 | — | Aug 10, 2026 | OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pse... |
| CVE-2026-71964 | HIGH | 7.1 | 0.3% | Aug 10, 2026 | CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component t... |
| CVE-2026-71962 | HIGH | 7.5 | — | Aug 10, 2026 | Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants... |
| CVE-2026-6791 | MEDIUM | 6.6 | 0.2% | Aug 10, 2026 | When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the ... |
| CVE-2026-6368 | LOW | 2.1 | 0.1% | Aug 10, 2026 | Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return inva... |
| CVE-2026-68872 | MEDIUM | 6.5 | 0.2% | Aug 10, 2026 | The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team... |
| CVE-2026-68871 | MEDIUM | 6.5 | 0.2% | Aug 10, 2026 | The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id ... |
| CVE-2026-68870 | MEDIUM | 5.3 | 0.1% | Aug 10, 2026 | The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Va... |
| CVE-2026-59091 | HIGH | 7.8 | 0.2% | Aug 10, 2026 | A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit t... |
| CVE-2026-12339 | MEDIUM | 6.9 | 0.3% | Aug 10, 2026 | A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive contai... |
| CVE-2026-72900 | HIGH | 7.1 | — | Aug 10, 2026 | Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database. |
| CVE-2026-72899 | CRITICAL | 10 | — | Aug 10, 2026 | Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes... |
| CVE-2026-72898 | CRITICAL | 10 | 1.1% | Aug 10, 2026 | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint a... |
| CVE-2026-72862 | CRITICAL | 9.9 | 0.4% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, pos... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now