CVE Vulnerability Database
Search and browse 375,982 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18618 | HIGH | 7.5 | 0.5% | Aug 10, 2026 | A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to kn... |
| CVE-2026-18617 | HIGH | 8.8 | 0.4% | Aug 10, 2026 | A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the sp... |
| CVE-2026-18611 | HIGH | 7.5 | 0.4% | Aug 10, 2026 | A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive... |
| CVE-2026-18608 | HIGH | 8.7 | 0.4% | Aug 10, 2026 | A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permission... |
| CVE-2026-16456 | MEDIUM | 6.5 | 0.3% | Aug 10, 2026 | A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can ex... |
| CVE-2026-15581 | HIGH | 8 | 0.2% | Aug 10, 2026 | A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to b... |
| CVE-2026-15467 | HIGH | 8.1 | 0.4% | Aug 10, 2026 | A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can e... |
| CVE-2026-14450 | CRITICAL | 9.9 | 0.4% | Aug 10, 2026 | A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy... |
| CVE-2026-13717 | HIGH | 8.8 | 0.3% | Aug 10, 2026 | A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serv... |
| CVE-2026-11810 | HIGH | 7.5 | 0.3% | Aug 10, 2026 | The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub.c) pars... |
| CVE-2026-11809 | LOW | 3.7 | 0.3% | Aug 10, 2026 | The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z... |
| CVE-2026-72902 | CRITICAL | 9.9 | 0.5% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to... |
| CVE-2026-72901 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-pri... |
| CVE-2026-72886 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.u... |
| CVE-2026-72885 | NONE | 0 | 0.6% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, dockerContextPath accepted by apps/dokp... |
| CVE-2026-72884 | HIGH | 8.7 | 0.4% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, sanitizeCommand in packages/server/src/... |
| CVE-2026-72883 | HIGH | 8.8 | 0.4% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/... |
| CVE-2026-72882 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can crea... |
| CVE-2026-72881 | MEDIUM | 6.4 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command bui... |
| CVE-2026-72880 | CRITICAL | 9.9 | 0.3% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in pack... |
| CVE-2026-72879 | CRITICAL | 9.4 | 0.3% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in pa... |
| CVE-2026-72878 | CRITICAL | 9.6 | 0.3% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's backup and restore pipeline c... |
| CVE-2026-72877 | CRITICAL | 9.6 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated w... |
| CVE-2026-72876 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swar... |
| CVE-2026-72875 | HIGH | 8.8 | 0.5% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, settings.readTraefikFile in apps/dokplo... |
