Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Vulnerability List - Page 58

Found 21070 results
CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-72886 🧪 Dokploy: Non-admin member gains root on the host by bypassing the owner/admin check on server-level schedules (incomplete fix of CVE-2026-45632) Dokploy dokploy Critical 9.9 2026-08-10 19:38:24 Deep Dive
CVE-2026-72884 🧪 Dokploy: Command Injection via Compose Custom Command Dokploy dokploy High 8.7 2026-08-10 19:30:07 Deep Dive
CVE-2026-72883 🧪 Dokploy: WebSocket Terminal Missing Service-Level Access Control Dokploy dokploy High 8.8 2026-08-10 19:28:45 Deep Dive
CVE-2026-72882 🧪 Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed servers Dokploy dokploy Critical 9.9 2026-08-10 19:27:09 Deep Dive
CVE-2026-72880 🧪 Dokploy: Arbitrary File Write + Remote OS Command Injection via `certificatePath` Dokploy dokploy Critical 9.9 2026-08-10 19:19:40 Deep Dive
CVE-2026-72879 🧪 Dokploy: Command Injection via Registry Credentials in Swarm Upload Dokploy dokploy Critical 9.4 2026-08-10 19:14:53 Deep Dive
CVE-2026-72878 🧪 Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell arguments Dokploy dokploy Critical 9.6 2026-08-10 19:11:40 Deep Dive
CVE-2026-69112 🧪 Hugging Face Accelerate 1.14.0 Path Traversal and DoS via weight_map huggingface accelerate High 7.1 2026-08-10 19:05:41 Deep Dive
CVE-2026-72877 🧪 Dokploy: Command Injection via dockerImage in buildRemoteDocker Dokploy dokploy Critical 9.6 2026-08-10 19:02:29 Deep Dive
CVE-2026-72876 🧪 Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.* Dokploy dokploy Critical 9.9 2026-08-10 19:00:54 Deep Dive
CVE-2026-72875 🧪 Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFile Dokploy dokploy High 8.8 2026-08-10 18:59:33 Deep Dive
CVE-2026-72874 🧪 Dokploy: Command Injection via Unescaped Git URL in Clone Commands Dokploy dokploy High 8.7 2026-08-10 18:57:40 Deep Dive
CVE-2026-71966 🧪 CyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfer usmannasir cyberpanel High 8.8 2026-08-10 18:53:12 Deep Dive
CVE-2026-71965 🧪 CyberPanel 2.4.3 Authenticated RCE via Remote Backup Feature usmannasir cyberpanel High 8.8 2026-08-10 18:52:40 Deep Dive
CVE-2026-72872 🧪 Dokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone` Dokploy dokploy Critical 9.9 2026-08-10 18:50:24 Deep Dive
CVE-2026-72871 🧪 Dokploy: Unauthenticated Git Provider Injection via GitHub OAuth Callback Dokploy dokploy High 7.5 2026-08-10 18:47:58 Deep Dive
CVE-2026-72870 🧪 Dokploy: Command Injection via Docker Credentials in buildRemoteDocker Dokploy dokploy High 8.7 2026-08-10 18:45:18 Deep Dive
CVE-2026-72869 🧪 Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCE Dokploy dokploy Critical 9.9 2026-08-10 18:40:48 Deep Dive
CVE-2026-72868 🧪 Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injection Dokploy dokploy Critical 9.9 2026-08-10 18:39:09 Deep Dive
CVE-2026-72867 🧪 Dokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated Branch Fields in Compose Deployment Pipeline (server-side regex missing in compose.ts) Dokploy dokploy Critical 9.9 2026-08-10 18:36:54 Deep Dive