Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.2 HIGH
CVE-2026-14886 — Vault Enterprise vulnerable to cross-namespace entity deletion

Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may allow an authenticated caller in one namespace to permanently delete the stor…

vault | Remote | Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
8.8 HIGH
CVE-2025-15683 — Multiple Unauthenticated Denial-of-Service Conditions

TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An unauthenticated remote attacker can invoke specific HTTP endpoints to reboot or…

Remote | Denial of Service
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
8.7 HIGH
CVE-2025-15682 — Unauthenticated Resource Exhaustion

TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server. An unauthenticated remote attacker can send PUT requests to the /tmp/ endpoint, causing …

Remote | Denial of Service
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.2 CRITICAL
CVE-2025-15681 — Insufficient Webserver Authentication

TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authenticated to the device, an unauthenticated attacker can directly access protected f…

Remote | Authentication
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
2.4 LOW
CVE-2025-15680 — Information Disclosure via UART

TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A physically proximate attacker can connect to the UART interface and observe the d…

| Information Disclosure
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.3 CRITICAL
CVE-2025-13294 — Unauthenticated SQL Injection

An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacker-controlled parameters directly into SQLite queri…

Remote | Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.3 CRITICAL
CVE-2025-13293 — Backdoor / default root credentials

A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level access to the device via the exposed SSH service. The r…

Remote | Authentication
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.9 CRITICAL
CVE-2026-72872 — Dokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone`

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucketRepository without validation and cloneBitbucketR…

dokploy | Remote | Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
7.5 HIGH
CVE-2026-72871 — Dokploy: Unauthenticated Git Provider Injection via GitHub OAuth Callback

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/github/setup route in apps/dokploy/pages/api/providers/github/setup.ts trusts gh_in…

dokploy | Remote | Authentication
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
8.7 HIGH
CVE-2026-72870 — Dokploy: Command Injection via Docker Credentials in buildRemoteDocker

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the buildRemoteDocker() function in packages/server/src/utils/providers/docker.ts interpolates the application-control…

dokploy | Remote | Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.9 CRITICAL
CVE-2026-72869 — Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName…

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databaseName parameter to restore builders in packages/s…

dokploy | Remote | Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.9 CRITICAL
CVE-2026-72868 — Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injecti…

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the accessKey, secretAccessKey, region, endpoint, provider…

dokploy | Remote | Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.9 CRITICAL
CVE-2026-72867 — Dokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated Branch Field…

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/server/src/db/schema/compose.ts branch fields without s…

dokploy | Remote | Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
8.8 HIGH
CVE-2026-72866 — WebSocket Terminal Auth Bypass

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/server/wss/terminal.ts validates a session but does not authorize access to the …

dokploy | Remote | Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.9 CRITICAL
CVE-2026-72865 — Dokploy: OS Command Injection via compose `composePath`

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an unvalidated composePath that packages/server/src/utils/builders/compose.ts and …

dokploy | Remote | Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.9 CRITICAL
CVE-2026-72864 — Dokploy Broken Access Control on docker-container-terminal WebSocket (Member -> Root in A…

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/server/wss/docker-container-terminal.ts authenticates w…

dokploy | Remote | Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.9 CRITICAL
CVE-2026-72863 — Dokploy: Missing authorization in WebSocket handlers allows a low-privilege member to gai…

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) authenticate the session but never authorize it. The…

dokploy | Remote | Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
6.7 MEDIUM
CVE-2026-71969 — OP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operations

OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt and decrypt operations within the mbedTLS software backend and SE050 hardware dr…

op-tee | Memory Corruption
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
6.7 MEDIUM
CVE-2026-71968 — OP-TEE OS 4.10.0 Use-After-Free via Trusted Application Loader TA_FLAG_CONCURRENT

OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers with the ability to load a signed Trusted Applicatio…

op-tee | Memory Corruption
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
5.7 MEDIUM
CVE-2026-71967 — OP-TEE OS 4.10.0 NULL Pointer Dereference DoS via Widevine PTA open_session

OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pseudo-TA open_session handler that allows Normal World clients to cause a denial …

op-tee | Denial of Service
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
Showing 20 of 10134 Results