CVE Vulnerability Database
Search and browse 375,982 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-72874 | HIGH | 8.7 | 0.4% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, cloneGitRepository in packages/server/s... |
| CVE-2026-72873 | MEDIUM | 6.5 | 0.3% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/... |
| CVE-2026-71966 | HIGH | 8.8 | — | Aug 10, 2026 | CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated command injection vulnerability in the remote backu... |
| CVE-2026-71965 | HIGH | 8.8 | 0.3% | Aug 10, 2026 | CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote b... |
| CVE-2026-69118 | HIGH | 8.8 | 0.6% | Aug 10, 2026 | Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows ... |
| CVE-2026-69116 | MEDIUM | 6.1 | 0.2% | Aug 10, 2026 | FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives.... |
| CVE-2026-69114 | HIGH | 7.1 | 0.3% | Aug 10, 2026 | Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and b... |
| CVE-2026-69112 | HIGH | 7.1 | 0.1% | Aug 10, 2026 | Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_chec... |
| CVE-2026-44401 | MEDIUM | 4.8 | 0.2% | Aug 10, 2026 | Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that ... |
| CVE-2026-14886 | HIGH | 8.2 | 0.2% | Aug 10, 2026 | Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that ma... |
| CVE-2025-15683 | HIGH | 8.8 | 0.5% | Aug 10, 2026 | TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An ... |
| CVE-2025-15682 | HIGH | 8.7 | 0.4% | Aug 10, 2026 | TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server. An unauth... |
| CVE-2025-15681 | CRITICAL | 9.2 | 0.5% | Aug 10, 2026 | TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authentic... |
| CVE-2025-15680 | LOW | 2.4 | 0.2% | Aug 10, 2026 | TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A ph... |
| CVE-2025-13294 | CRITICAL | 9.3 | 0.4% | Aug 10, 2026 | An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP ... |
| CVE-2025-13293 | CRITICAL | 9.3 | 0.4% | Aug 10, 2026 | A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attack... |
| CVE-2026-72872 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider store... |
| CVE-2026-72871 | HIGH | 7.5 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/gith... |
| CVE-2026-72870 | HIGH | 8.7 | 0.3% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the buildRemoteDocker() function in pac... |
| CVE-2026-72869 | CRITICAL | 9.9 | 0.4% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC s... |
| CVE-2026-72868 | CRITICAL | 9.9 | 0.4% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destina... |
| CVE-2026-72867 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-202... |
| CVE-2026-72866 | HIGH | 8.8 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/s... |
| CVE-2026-72865 | CRITICAL | 9.9 | 0.4% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an ... |
| CVE-2026-72864 | CRITICAL | 9.9 | 0.3% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-t... |
