Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.9 CRITICAL
CVE-2026-72862 — Dokploy: OS Command Injection via dockerImage field in database service deployment functi…

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsql.ts Dokploy database service deployment functions…

Remote | Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.9 CRITICAL
CVE-2026-72740 — Dokploy: OS Command Injection via SSH-form `customGitUrl` domain in `ssh-keyscan`

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git.ts parses the user-controlled customGitUrl with sanitizeRepoPathSSH and interp…

Remote | Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
6.5 MEDIUM
CVE-2026-72739 — Dokploy: Command Injection via Compose Shell Execution

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs shell commands by interpolating compose service names and configuration into b…

Remote | Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.9 CRITICAL
CVE-2026-72738 — Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Paramet…

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoint in apps/dokploy/server/api/routers/backup.ts passes the search parameter thro…

Remote | Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.6 CRITICAL
CVE-2026-72737 — Dokploy: Cross-organization IDOR in Dokploy backup destinations exposes another tenant's …

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs in apps/dokploy/server/api/routers/backup.ts accep…

Remote | Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.9 CRITICAL
CVE-2026-72736 — Dokploy: OS Command Injection in registry credential testing and Swarm cluster management…

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell commands via unquoted template literal interpolation in the …

Remote | Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.9 CRITICAL
CVE-2026-72735 — Dokploy: Command injection in writeTraefikConfigRemote via shell interpolation of unescap…

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/server/src/utils/traefik/application.ts serializes user-controlled Traefik config…

Remote | Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
8.4 HIGH
CVE-2026-72734 — Dokploy: Cross-organization authorization bypass in server.remove allows deletion of anot…

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutation in apps/dokploy/server/api/routers/server.ts accepts a caller-controlled serv…

Remote | Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.9 CRITICAL
CVE-2026-72733 — Dokploy: OS Command Injection via `databaseName` / `backupFile` in database restore

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription builds database restore shell pipelines from the user-controlled da…

Remote | Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
4.3 MEDIUM
CVE-2026-72732 — Discourse: Templates endpoint exposes hidden tag names

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse_templates endpoint exposed hidden tag names because DiscourseTemplates::TemplatesSe…

Remote | Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
6.5 MEDIUM
CVE-2026-70622 — tar-rs 0.4.11 - 0.4.46 Symlink Escape via append_dir_all()

tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root directory b…

Remote | Path Traversal
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.3 CRITICAL
CVE-2026-48159 — use-reducer-async was vulnerable to malicious code execution via compromised commits

use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the default branch contained malicious commits da72edbde5705efcec6c62e0a3dcb73687b78dc…

Remote | Supply Chain
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.3 CRITICAL
CVE-2026-16626 — JasperReports Server: XXE Injection Vulnerability (Unauthenticated)

Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server. This issue affects JasperReports Server: from 9.0.0 before HF-9 and from 10.…

Remote | XML External Entity
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
8.6 HIGH
CVE-2026-10754 — Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cry…

Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls.

Remote | Cryptography
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
7.1 HIGH
CVE-2026-72731 — Discourse: Strip SQL comments and use non-recursive parameter interpolation in Data Explo…

Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, anyone able to run a parameterized Data Explorer query, including non-…

Remote | Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
8.7 HIGH
CVE-2026-72730 — Discourse: Stored XSS chat-transcript username unescaped in Rich Text Editor

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing stored cross-site scri…

Remote | Cross-Site Scripting
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
2.0 LOW
CVE-2026-72729 — Discourse: Stored XSS in discourse-local-dates plugin

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-local-dates plugin rendered crafted local-date format data as HTML on sites with a …

Remote | Cross-Site Scripting
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
6.3 MEDIUM
CVE-2026-72728 — Discourse: Onebox iframe origin allowlist enforces URL authority boundary

Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed URLs that bypassed the Onebox allowlist and embedded malicious content in a sit…

Remote | Misconfiguration
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
4.8 MEDIUM
CVE-2026-72727 — Discourse: Stored XSS in the moderation review queue

Discourse is an open-source discussion platform. Prior to 026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, a low-privileged user could place crafted content in the moderation review queue that executed sto…

Remote | Cross-Site Scripting
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
6.3 MEDIUM
CVE-2026-71577 — Multicluster-global-hub: multicluster-global-hub: spec-topic read acl leaks bootstrap kub…

A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows a compromised ma…

Remote | Information Disclosure
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
Showing 20 of 10040 Results