Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Vulnerability List - Page 59

Found 21070 results
CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-72866 🧪 WebSocket Terminal Auth Bypass Dokploy dokploy High 8.8 2026-08-10 18:34:34 Deep Dive
CVE-2026-72865 🧪 Dokploy: OS Command Injection via compose `composePath` Dokploy dokploy Critical 9.9 2026-08-10 18:33:05 Deep Dive
CVE-2026-72864 🧪 Dokploy Broken Access Control on docker-container-terminal WebSocket (Member -> Root in Arbitrary Containers) Dokploy dokploy Critical 9.9 2026-08-10 18:31:25 Deep Dive
CVE-2026-72863 🧪 Dokploy: Missing authorization in WebSocket handlers allows a low-privilege member to gain root on the Docker host Dokploy dokploy Critical 9.9 2026-08-10 18:28:22 Deep Dive
CVE-2026-72862 🧪 Dokploy: OS Command Injection via dockerImage field in database service deployment functions → HOST RCE Dokploy dokploy Critical 9.9 2026-08-10 17:59:47 Deep Dive
CVE-2026-72898 KEV 🧪 💣 Metabase SQL injection via password reset endpoint EPSS 0.19 Metabase Metabase Critical 10.0 2026-08-10 17:55:55 Deep Dive
CVE-2026-72740 🧪 Dokploy: OS Command Injection via SSH-form `customGitUrl` domain in `ssh-keyscan` Dokploy dokploy Critical 9.9 2026-08-10 17:55:47 Deep Dive
CVE-2026-48159 🧪 use-reducer-async was vulnerable to malicious code execution via compromised commits dai-shi use-reducer-async Critical 9.3 2026-08-10 17:55:46 Deep Dive
CVE-2026-72738 🧪 Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameter Dokploy dokploy Critical 9.9 2026-08-10 17:49:44 Deep Dive
CVE-2026-72737 🧪 Dokploy: Cross-organization IDOR in Dokploy backup destinations exposes another tenant's S3 credentials and backups Dokploy dokploy Critical 9.6 2026-08-10 17:47:50 Deep Dive
CVE-2026-72736 🧪 Dokploy: OS Command Injection in registry credential testing and Swarm cluster management → HOST RCE Dokploy dokploy Critical 9.9 2026-08-10 17:40:45 Deep Dive
CVE-2026-72735 🧪 Dokploy: Command injection in writeTraefikConfigRemote via shell interpolation of unescaped YAML in SSH remote execution Dokploy dokploy Critical 9.9 2026-08-10 17:34:36 Deep Dive
CVE-2026-72734 🧪 Dokploy: Cross-organization authorization bypass in server.remove allows deletion of another organization's server registration Dokploy dokploy High 8.4 2026-08-10 17:29:30 Deep Dive
CVE-2026-72733 🧪 Dokploy: OS Command Injection via `databaseName` / `backupFile` in database restore Dokploy dokploy Critical 9.9 2026-08-10 17:26:30 Deep Dive
CVE-2026-48158 🧪 use-context-selector was vulnerable to malicious code execution via compromised commits dai-shi use-context-selector Critical 9.3 2026-08-10 15:56:59 Deep Dive
CVE-2026-47754 🧪 unauthenticated path traversal in Metacat 2.x NCEAS metacat Critical 9.3 2026-08-10 15:26:04 Deep Dive
CVE-2026-19433 🧪 Authorization Bypass Through User-Controlled Key in Prospero Flow CRM contact save and vCard export Roskus Prospero Flow CRM High 8.6 2026-08-10 14:04:14 Deep Dive
CVE-2026-59233 🧪 Missing Authorization in Prospero Flow CRM permission save endpoint allows privilege escalation Roskus Prospero Flow CRM High 8.7 2026-08-10 12:14:40 Deep Dive
CVE-2026-72692 🧪 OpenSignLabs opensignserver - Missing Authorization OpenSignLabs opensignserver High 7.5 2026-08-10 11:59:15 Deep Dive
CVE-2026-72691 🧪 OpenSignLabs opensignserver - Authentication Bypass OpenSignLabs opensignserver High 7.5 2026-08-10 11:59:12 Deep Dive