2026 CVE Vulnerabilities

47,770 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-72882CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can crea...
CVE-2026-72881MEDIUM6.4Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command bui...
CVE-2026-72880CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in pack...
CVE-2026-72879CRITICAL9.4Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in pa...
CVE-2026-72878CRITICAL9.6Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's backup and restore pipeline c...
CVE-2026-72877CRITICAL9.6Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated w...
CVE-2026-72876CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swar...
CVE-2026-72875HIGH8.8Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, settings.readTraefikFile in apps/dokplo...
CVE-2026-72874HIGH8.7Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, cloneGitRepository in packages/server/s...
CVE-2026-72873MEDIUM6.5Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/...
CVE-2026-71966HIGH8.8CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated command injection vulnerability in the remote backu...
CVE-2026-71965HIGH8.8CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote b...
CVE-2026-69118HIGH8.8Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows ...
CVE-2026-69116MEDIUM6.1FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives....
CVE-2026-69114HIGH7.1Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and b...
CVE-2026-69112HIGH7.1Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_chec...
CVE-2026-44401MEDIUM4.8Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that ...
CVE-2026-14886HIGH8.2Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that ma...
CVE-2026-72872CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider store...
CVE-2026-72871HIGH7.5Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/gith...
CVE-2026-72870HIGH8.7Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the buildRemoteDocker() function in pac...
CVE-2026-72869CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC s...
CVE-2026-72868CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destina...
CVE-2026-72867CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-202...
CVE-2026-72866HIGH8.8Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/s...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now