2026 CVE Vulnerabilities
43,031 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-72878 | CRITICAL | 9.6 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's backup and restore pipeline c... |
| CVE-2026-72877 | CRITICAL | 9.6 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated w... |
| CVE-2026-72876 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swar... |
| CVE-2026-72872 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider store... |
| CVE-2026-72869 | CRITICAL | 9.9 | 0.4% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC s... |
| CVE-2026-72868 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destina... |
| CVE-2026-72867 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-202... |
| CVE-2026-72865 | CRITICAL | 9.9 | 0.4% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an ... |
| CVE-2026-72864 | CRITICAL | 9.9 | 0.3% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-t... |
| CVE-2026-72863 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app te... |
| CVE-2026-72899 | CRITICAL | 10 | — | Aug 10, 2026 | Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes... |
| CVE-2026-72898 | CRITICAL | 10 | 1.1% | Aug 10, 2026 | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint a... |
| CVE-2026-72862 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, pos... |
| CVE-2026-72740 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git... |
| CVE-2026-72738 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoin... |
| CVE-2026-72737 | CRITICAL | 9.6 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and ... |
| CVE-2026-72736 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values d... |
| CVE-2026-72735 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/se... |
| CVE-2026-72733 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC s... |
| CVE-2026-48159 | CRITICAL | 9.3 | — | Aug 10, 2026 | use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the def... |
| CVE-2026-16626 | CRITICAL | 9.3 | 0.3% | Aug 10, 2026 | Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server... |
| CVE-2026-48158 | CRITICAL | 9.3 | — | Aug 10, 2026 | use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34,... |
| CVE-2026-47754 | CRITICAL | 9.3 | — | Aug 10, 2026 | Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19... |
| CVE-2026-18412 | CRITICAL | 9.1 | 0.2% | Aug 10, 2026 | OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 exten... |
| CVE-2026-63106 | CRITICAL | 9.8 | — | Aug 10, 2026 | ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now