Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Vulnerability List
Found 25 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2025-64425 Coolify has host header injection in forgot password coollabsiocoolify 高危 -2026-01-05 20:49:11 Deep Dive
CVE-2025-64424 Colify has command injection vulnerability in project git source coollabsiocoolify 高危 -2026-01-05 20:45:10 Deep Dive
CVE-2025-64423 Coolify has a Privilege Escalation - low privileged users can see and use admin invitation links coollabsiocoolify 高危 -2026-01-05 20:41:37 Deep Dive
CVE-2025-64422 Rate-limit bypass on login via X-Forwarded-Host header coollabsiocoolify 中危 -2026-01-05 20:29:35 Deep Dive
CVE-2025-64421 Coolify has a privilege escalation - low privileged user can invite themselves as an admin user coollabsiocoolify 高危 -2026-01-05 19:42:47 Deep Dive
CVE-2025-64420 Coolify members can see private key of root user coollabsiocoolify Critical 9.9 2026-01-05 19:20:24 Deep Dive
CVE-2025-64419 Coolify vulnerable to command injection via docker-compose.yaml parameters coollabsiocoolify Critical 9.6 2026-01-05 19:16:44 Deep Dive
CVE-2025-59955 Coolify leaksensitive information `email_change_code` in `/api/v1/teams/{team_id | current}/members` API endpoint coollabsiocoolify 中危 -2026-01-05 17:46:56 Deep Dive
CVE-2025-59158 Coolify has Stored XSS in Project Name coollabsiocoolify 高危 -2026-01-05 17:44:41 Deep Dive
CVE-2025-59157 Coolify has Git Repository RCE coollabsiocoolify Critical 9.9 2026-01-05 17:41:30 Deep Dive
CVE-2025-59156 Coolify has Docker Compose Injection issue coollabsiocoolify 高危 -2026-01-05 17:39:43 Deep Dive
CVE-2025-66213 Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in File Storage Directory Mount Path coollabsiocoolify--2025-12-23 22:06:39 Deep Dive
CVE-2025-66212 Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Dynamic Proxy Configuration Filename coollabsiocoolify--2025-12-23 22:04:19 Deep Dive
CVE-2025-66211 Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in PostgreSQL Init Script Filename coollabsiocoolify--2025-12-23 22:00:36 Deep Dive
CVE-2025-66210 Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database Import coollabsiocoolify--2025-12-23 21:49:45 Deep Dive
CVE-2025-66209 Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database Backup coollabsiocoolify Critical 9.9 2025-12-23 21:42:18 Deep Dive
CVE-2025-24025 Coolify Vulnerable to Reflected XSS on Tag Search coollabsiocoolify 中危 -2025-01-24 16:46:04 Deep Dive
CVE-2025-22612 Coolify Vulnerable to Private Key Enumeration on Onboarding resulting in Remote Command Execution (RCE) coollabsiocoolify Critical 10.0 2025-01-24 16:43:49 Deep Dive
CVE-2025-22611 Coolify vulnerable to Privilege Escalation resulting in Remote Command Execution (RCE) coollabsiocoolify Critical 9.9 2025-01-24 16:35:21 Deep Dive
CVE-2025-22610 Coolify Vulnerable to OAuth Secrets Leak coollabsiocoolify 中危 -2025-01-24 16:33:17 Deep Dive