2026 CVE Vulnerabilities

47,798 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-72885NONE0Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, dockerContextPath accepted by apps/dokp...
CVE-2026-72884HIGH8.7Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, sanitizeCommand in packages/server/src/...
CVE-2026-72883HIGH8.8Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/...
CVE-2026-72882CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can crea...
CVE-2026-72881MEDIUM6.4Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command bui...
CVE-2026-72880CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in pack...
CVE-2026-72879CRITICAL9.4Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in pa...
CVE-2026-72878CRITICAL9.6Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's backup and restore pipeline c...
CVE-2026-72877CRITICAL9.6Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated w...
CVE-2026-72876CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swar...
CVE-2026-72875HIGH8.8Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, settings.readTraefikFile in apps/dokplo...
CVE-2026-72874HIGH8.7Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, cloneGitRepository in packages/server/s...
CVE-2026-72873MEDIUM6.5Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/...
CVE-2026-71966HIGH8.8CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated command injection vulnerability in the remote backu...
CVE-2026-71965HIGH8.8CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote b...
CVE-2026-69118HIGH8.8Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows ...
CVE-2026-69116MEDIUM6.1FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives....
CVE-2026-69114HIGH7.1Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and b...
CVE-2026-69112HIGH7.1Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_chec...
CVE-2026-44401MEDIUM4.8Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that ...
CVE-2026-14886HIGH8.2Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that ma...
CVE-2026-72872CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider store...
CVE-2026-72871HIGH7.5Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/gith...
CVE-2026-72870HIGH8.7Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the buildRemoteDocker() function in pac...
CVE-2026-72869CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC s...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now