2026 CVE Vulnerabilities

47,841 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-72878CRITICAL9.6Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's backup and restore pipeline c...
CVE-2026-72877CRITICAL9.6Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated w...
CVE-2026-72876CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swar...
CVE-2026-72875HIGH8.8Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, settings.readTraefikFile in apps/dokplo...
CVE-2026-72874HIGH8.7Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, cloneGitRepository in packages/server/s...
CVE-2026-72873MEDIUM6.5Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/...
CVE-2026-71966HIGH8.8CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated command injection vulnerability in the remote backu...
CVE-2026-71965HIGH8.8CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote b...
CVE-2026-69118HIGH8.8Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows ...
CVE-2026-69116MEDIUM6.1FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives....
CVE-2026-69114HIGH7.1Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and b...
CVE-2026-69112HIGH7.1Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_chec...
CVE-2026-44401MEDIUM4.8Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that ...
CVE-2026-14886HIGH8.2Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that ma...
CVE-2026-72872CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider store...
CVE-2026-72871HIGH7.5Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/gith...
CVE-2026-72870HIGH8.7Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the buildRemoteDocker() function in pac...
CVE-2026-72869CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC s...
CVE-2026-72868CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destina...
CVE-2026-72867CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-202...
CVE-2026-72866HIGH8.8Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/s...
CVE-2026-72865CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an ...
CVE-2026-72864CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-t...
CVE-2026-72863CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app te...
CVE-2026-71969MEDIUM6.7OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now