Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-72873 — Dokploy: Cross-tenant Git provider secrets are disclosed to low-privileged service reader…

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/api/routers/application.ts returns provider relations loaded by findApplication…

dokploy | Remote | Information Disclosure
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
8.8 HIGH
CVE-2026-71966 — CyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfer

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated command injection vulnerability in the remote backup transfer feature that allows authenticated attackers to execute arbitrary OS …

cyberpanel | Remote | Injection
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
8.8 HIGH
CVE-2026-71965 — CyberPanel 2.4.3 Authenticated RCE via Remote Backup Feature

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote backup feature that allows authenticated attackers to gain root-level SSH access…

cyberpanel | Remote | Authentication
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
8.8 HIGH
CVE-2026-69118 — Cachet 2.4.1 Authenticated Server-Side Template Injection RCE

Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code. Attackers can create malicio…

cachet | Remote | Injection
Aug 10, 2026 Aug 11, 2026
Aug 10, 2026
Aug 11, 2026
6.1 MEDIUM
CVE-2026-69116 — FlyEnv < 4.18.0 Cross-Site Scripting via v-html

FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives. Attackers can inject malicious scripts through markdown sources or chat messag…

Remote | Cross-Site Scripting
Aug 10, 2026 Aug 11, 2026
Aug 10, 2026
Aug 11, 2026
7.1 HIGH
CVE-2026-69114 — Spacebar Server Cross-Channel Message Deletion via Permission Check Bypass

Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and bulk-delete message handlers that fail to scope message queries to the requested…

Remote | Authorization
Aug 10, 2026 Aug 11, 2026
Aug 10, 2026
Aug 11, 2026
7.1 HIGH
CVE-2026-69112 — Hugging Face Accelerate 1.14.0 Path Traversal and DoS via weight_map

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sha…

| Path Traversal
Aug 10, 2026 Aug 11, 2026
Aug 10, 2026
Aug 11, 2026
4.8 MEDIUM
CVE-2026-44401 — Typemill CMS 2.x Persistent XSS via Markdown javascript URI

Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that allows authenticated users with theme-configuration access to inject malicious …

typemill | Remote | Cross-Site Scripting
Aug 10, 2026 Aug 11, 2026
Aug 10, 2026
Aug 11, 2026
8.2 HIGH
CVE-2026-14886 — Vault Enterprise vulnerable to cross-namespace entity deletion

Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may allow an authenticated caller in one namespace to permanently delete the stor…

vault | Authorization
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
8.8 HIGH
CVE-2025-15683 — Multiple Unauthenticated Denial-of-Service Conditions

TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An unauthenticated remote attacker can invoke specific HTTP endpoints to reboot or…

Remote | Denial of Service
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
8.7 HIGH
CVE-2025-15682 — Unauthenticated Resource Exhaustion

TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server. An unauthenticated remote attacker can send PUT requests to the /tmp/ endpoint, causing …

Remote | Denial of Service
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
9.2 CRITICAL
CVE-2025-15681 — Insufficient Webserver Authentication

TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authenticated to the device, an unauthenticated attacker can directly access protected f…

Remote | Authentication
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
2.4 LOW
CVE-2025-15680 — Information Disclosure via UART

TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A physically proximate attacker can connect to the UART interface and observe the d…

| Information Disclosure
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
9.3 CRITICAL
CVE-2025-13294 — Unauthenticated SQL Injection

An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacker-controlled parameters directly into SQLite queri…

Remote | Injection
Aug 10, 2026 Sep 03, 2026
Aug 10, 2026
Sep 03, 2026
9.3 CRITICAL
CVE-2025-13293 — Backdoor / default root credentials

A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level access to the device via the exposed SSH service. The r…

Remote | Authentication
Aug 10, 2026 Sep 03, 2026
Aug 10, 2026
Sep 03, 2026
9.9 CRITICAL
CVE-2026-72872 — Dokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone`

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucketRepository without validation and cloneBitbucketR…

dokploy | Remote | Injection
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
7.5 HIGH
CVE-2026-72871 — Dokploy: Unauthenticated Git Provider Injection via GitHub OAuth Callback

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/github/setup route in apps/dokploy/pages/api/providers/github/setup.ts trusts gh_in…

dokploy | Remote | Authentication
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-72870 — Dokploy: Command Injection via Docker Credentials in buildRemoteDocker

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the buildRemoteDocker() function in packages/server/src/utils/providers/docker.ts interpolates the application-control…

dokploy | Remote | Injection
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
9.9 CRITICAL
CVE-2026-72869 — Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName…

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databaseName parameter to restore builders in packages/s…

dokploy | Remote | Injection
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
9.9 CRITICAL
CVE-2026-72868 — Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injecti…

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the accessKey, secretAccessKey, region, endpoint, provider…

dokploy | Remote | Injection
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
Showing 20 of 13969 Results