CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 449 of 500
CVE-2026-72884
HIGH

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, sanitizeCommand in packages/server/src/utils/builders/compose.ts only trims whitespace and strips s...

CVSS 8.7 2026-08-10
CVE-2026-72883
HIGH

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/server/wss/terminal.ts, apps/dokploy/server/wss/docker-conta...

CVSS 8.8 2026-08-10
CVE-2026-72875
HIGH

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, settings.readTraefikFile in apps/dokploy/server/api/routers/settings.ts passes a path accepted by a...

CVSS 8.8 2026-08-10
CVE-2026-72874
HIGH

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, cloneGitRepository in packages/server/src/utils/providers/git.ts interpolates customGitUrl and cust...

CVSS 8.7 2026-08-10
CVE-2026-71966
HIGH

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated command injection vulnerability in the remote backup transfer feature that allows authenticated attackers to ex...

CVSS 8.8 2026-08-10
CVE-2026-71965
HIGH

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote backup feature that allows authenticated attackers to gain ro...

CVSS 8.8 2026-08-10
CVE-2026-69118
HIGH

Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code. Attackers...

CVSS 8.8 2026-08-10
CVE-2026-69112
HIGH

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_m...

CVSS 7.1 2026-08-10
CVE-2026-14886
HIGH

Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may allow an authenticated caller in one namespace to permanen...

CVSS 8.2 2026-08-10
CVE-2025-15683
HIGH

TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An unauthenticated remote attacker can invoke specific HTTP end...

CVSS 8.8 2026-08-10
CVE-2025-15682
HIGH

TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server. An unauthenticated remote attacker can send PUT requests to the /tmp/...

CVSS 8.7 2026-08-10
CVE-2026-72871
HIGH

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/github/setup route in apps/dokploy/pages/api/providers/github/se...

CVSS 7.5 2026-08-10
CVE-2026-72870
HIGH

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the buildRemoteDocker() function in packages/server/src/utils/providers/docker.ts interpolates the ...

CVSS 8.7 2026-08-10
CVE-2026-72866
HIGH

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/server/wss/terminal.ts validates a session but does not autho...

CVSS 8.8 2026-08-10
CVE-2026-71962
HIGH

Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that allows unauthenticated attacker...

CVSS 7.5 Flowiseai flowise 2026-08-10
CVE-2026-59091
HIGH

A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by tricking a user into opening a speci...

CVSS 7.8 Redhat enterprise_linux 2026-08-10
CVE-2026-72734
HIGH

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutation in apps/dokploy/server/api/routers/server.ts accepts a cal...

CVSS 8.4 2026-08-10
CVE-2026-10754
HIGH

Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls.

CVSS 8.6 2026-08-10
CVE-2026-72731
HIGH

Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, anyone able to run a parameterized Data Explorer qu...

CVSS 7.1 2026-08-10
CVE-2026-72730
HIGH

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing sto...

CVSS 8.7 2026-08-10
1 447 448 449 450 451 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.