Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-72866 — WebSocket Terminal Auth Bypass

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/server/wss/terminal.ts validates a session but does not authorize access to the …

dokploy | Remote | Authorization
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
9.9 CRITICAL
CVE-2026-72865 — Dokploy: OS Command Injection via compose `composePath`

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an unvalidated composePath that packages/server/src/utils/builders/compose.ts and …

dokploy | Remote | Injection
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
9.9 CRITICAL
CVE-2026-72864 — Dokploy Broken Access Control on docker-container-terminal WebSocket (Member -> Root in A…

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/server/wss/docker-container-terminal.ts authenticates w…

dokploy | Remote | Authorization
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
9.9 CRITICAL
CVE-2026-72863 — Dokploy: Missing authorization in WebSocket handlers allows a low-privilege member to gai…

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) authenticate the session but never authorize it. The…

dokploy | Remote | Authorization
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
8.4 HIGH
CVE-2026-71969 — OP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operations

OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt and decrypt operations within the mbedTLS software backend and SE050 hardware dr…

op-tee_os op-tee | Memory Corruption
Aug 10, 2026 Aug 17, 2026
Aug 10, 2026
Aug 17, 2026
8.4 HIGH
CVE-2026-71968 — OP-TEE OS 4.10.0 Use-After-Free via Trusted Application Loader TA_FLAG_CONCURRENT

OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers with the ability to load a signed Trusted Applicatio…

op-tee_os op-tee | Memory Corruption
Aug 10, 2026 Aug 17, 2026
Aug 10, 2026
Aug 17, 2026
5.7 MEDIUM
CVE-2026-71967 — OP-TEE OS 4.10.0 NULL Pointer Dereference DoS via Widevine PTA open_session

OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pseudo-TA open_session handler that allows Normal World clients to cause a denial …

op-tee_os op-tee | Denial of Service
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
7.1 HIGH
CVE-2026-71964 — CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Upload

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component that allows authenticated attackers to read sensitive system files by uploading …

cyberpanel | Remote | Path Traversal
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-71962 — Flowise 2.2.4 - 3.1.4 Missing Authorization via openai-assistants-file/download

Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that allows unauthenticated attackers to access private…

flowise | Remote | Authorization
Aug 10, 2026 Sep 04, 2026
Aug 10, 2026
Sep 04, 2026
6.6 MEDIUM
CVE-2026-6791 — Potential stack-based buffer clash during tilde expansion in wordexp

When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation allocates …

glibc | Remote | Memory Corruption
Aug 10, 2026 Sep 03, 2026
Aug 10, 2026
Sep 03, 2026
2.1 LOW
CVE-2026-6368 — wordexp with WRDE_APPEND can return or use invalid memory

Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may ab…

glibc | Memory Corruption
Aug 10, 2026 Sep 03, 2026
Aug 10, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-68872 — Apache Airflow Amazon provider: amazon SSM / Secrets Manager backends: team-scope guard b…

The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the tea…

apache-airflow-providers-amazon | Remote | Authorization
Aug 10, 2026 Aug 17, 2026
Aug 10, 2026
Aug 17, 2026
6.5 MEDIUM
CVE-2026-68871 — Apache Airflow Yandex provider: yandex Lockbox backend: team-scope guard bypass resolves …

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deplo…

apache-airflow-providers-apache-yandex | Remote | Authorization
Aug 10, 2026 Aug 17, 2026
Aug 10, 2026
Aug 17, 2026
5.3 MEDIUM
CVE-2026-68870 — Apache Airflow Microsoft Azure provider: microsoft.azure Key Vault backend: team-scope gu…

The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. …

Remote | Authorization
Aug 10, 2026 Aug 12, 2026
Aug 10, 2026
Aug 12, 2026
7.8 HIGH
CVE-2026-59091 — Gimp: gimp: multiple vulnerabilities in file format plugins via crafted image file

A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by tricking a user into opening a specially crafted image …

Aug 10, 2026 Aug 24, 2026
Aug 10, 2026
Aug 24, 2026
6.9 MEDIUM
CVE-2026-12339 — Authenticated Arbitrary File Write Vulnerability in multiple devices

A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrit…

Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
7.1 HIGH
CVE-2026-72900 — Metabase information exposure

Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.

metabase | Remote | Information Disclosure
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
10.0 CRITICAL
CVE-2026-72899 — Metabase SQL injection via public card or dashboard

Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter.

metabase | Remote | Injection
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
10.0 CRITICAL
CVE-2026-72898 — Metabase SQL Injection Vulnerability - [Actively Exploited]

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

metabase | CISA KEV Remote | Injection
Aug 10, 2026 Aug 12, 2026
Aug 10, 2026
Aug 12, 2026
9.9 CRITICAL
CVE-2026-72862 — Dokploy: OS Command Injection via dockerImage field in database service deployment functi…

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsql.ts Dokploy database service deployment functions…

dokploy | Remote | Injection
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
Showing 20 of 13968 Results