21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 1001-1050 of 21637 CVEs Page 21 of 433
CVE-2026-72740
Analyzed
9.9
Dokploy dokploy

An OS command injection vulnerability in Dokploy prior to 0.29.13 allows authenticated users with deployment permissions to execute arbitrary commands...

2026-08-11
CVE-2026-72738
Analyzed
9.9
Dokploy dokploy

An OS command injection vulnerability in the Dokploy backup endpoint allows authenticated users to execute arbitrary commands on the host server.

2026-08-11
CVE-2026-72737
Analyzed
9.6
Dokploy dokploy

A cross-tenant authorization bypass in Dokploy versions 0.29.8 and earlier allows authenticated users with backup permissions to access or poison back...

2026-08-11
CVE-2026-72736
Analyzed
9.9
Docker dokploy

Dokploy contains a command injection vulnerability in its registry credential and Docker Swarm management endpoints, allowing authenticated users to e...

2026-08-11
CVE-2026-72735
Analyzed
9.9
Dokploy dokploy

An incomplete fix for a previous vulnerability allows authenticated users to perform OS command injection on remote servers managed by Dokploy through...

2026-08-11
CVE-2026-72734
Analyzed
8.4
Dokploy dokploy

Dokploy is a free, self-hostable Platform as a Service (PaaS)

2026-08-11
CVE-2026-72733
Analyzed
9.9
Dokploy dokploy

Dokploy versions before 0.29.13 are vulnerable to OS command injection in the backup restore functionality, allowing authenticated users to execute ar...

2026-08-11
CVE-2026-72730
Analyzed
8.7
Discourse discourse

Discourse is an open-source discussion platform

2026-08-11
CVE-2026-7273
Analyzed
8.8
HP GS1900-48HPv2

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2

2026-06-16
CVE-2026-7270
7.8
Unknown Multiple Products

An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data to overwrite adjacent execve(2)...

2026-05-01
CVE-2026-72693
Analyzed
7.8
Red Hat Enterprise Linux

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context

2026-08-11
CVE-2026-72692
Analyzed
7.5
OpenSignLabs opensignserver

A missing authorization vulnerability in OpenSignLabs opensignserver through 2

2026-08-11
CVE-2026-72691
Analyzed
7.5
OpenSignLabs opensignserver

An authentication bypass vulnerability in OpenSignLabs opensignserver through 2

2026-08-11
CVE-2026-72689
Analyzed
7.5
OpenSignLabs opensignserver

A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2

2026-08-11
CVE-2026-72688
Analyzed
7.5
OpenSignLabs opensignserver

A missing authentication vulnerability in OpenSignLabs opensignserver through 2

2026-08-11
CVE-2026-72642
Analyzed
8.8
Elastic Elasticsearch

The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory add...

2026-08-14
CVE-2026-72603
Analyzed
9.9
Unknown wg-easy

An OS command injection vulnerability in wg-easy 15.3.0 allows authenticated users to execute arbitrary commands as root by injecting malicious direct...

2026-08-12
CVE-2026-72594
Analyzed
7.6
LobeHub Lobe-Chat

A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2

2026-08-11
CVE-2026-72593
Analyzed
9.8
HP phpfm

A missing authentication flaw in dulldusk phpfm through 1.8.0 allows unauthenticated remote attackers to gain full administrative access to the filesy...

2026-08-11
CVE-2026-72592
Analyzed
9.8
HP phpfm

An unrestricted file upload vulnerability in dulldusk phpfm through 1.8.0 allows unauthenticated attackers to execute arbitrary PHP code via the file...

2026-08-11
CVE-2026-72591
Analyzed
7.7
Unknown Koito

A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0

2026-08-11
CVE-2026-72590
Analyzed
9.8
Unknown crontab-ui

An OS command injection vulnerability in alseambusher/crontab-ui allows unauthenticated remote attackers to inject arbitrary cron jobs by sending a cr...

2026-08-11
CVE-2026-72589
Analyzed
9.8
Unknown crontab-ui

A critical OS command injection vulnerability in crontab-ui allows unauthenticated remote attackers to execute arbitrary system commands by importing...

2026-08-11
CVE-2026-72586
Analyzed
7.5
Frangoteam FUXA

A missing authentication vulnerability in frangoteam/FUXA through 1

2026-08-11
CVE-2026-72584
Analyzed
7.4
GitHub Fastschema

A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0

2026-08-11
CVE-2026-72582
Analyzed
7.5
GitHub Fastschema

A NULL pointer dereference vulnerability in fastschema through v0

2026-08-11
CVE-2026-72581
Analyzed
8.6
GitHub xiaoai-patch

A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to make the Xiaomi smart spea...

2026-08-11
CVE-2026-72580
Analyzed
9.8
Unknown xiaoai-patch

An OS command injection vulnerability in duhow/xiaoai-patch allows remote, unauthenticated attackers to execute arbitrary system commands via the sile...

2026-08-11
CVE-2026-72579
Analyzed
7.5
NASA HyperCP

An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjacent attacker who can intercept or spoof responses from ocean...

2026-08-11
CVE-2026-72578
Analyzed
8.8
FreePBX Framework FreePBX Framework

A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17

2026-08-11
CVE-2026-72577
Analyzed
9.8
NASA fprime-gds

The NASA fprime-gds application fails to implement authentication on its Flask-based endpoints, allowing unauthenticated remote attackers to execute a...

2026-08-11
CVE-2026-72573
Analyzed
8.8
GitHub pm2panel

An OS command injection vulnerability in 4xmen/pm2panel (all versions) allows an authenticated remote attacker to execute arbitrary system commands on...

2026-08-11
CVE-2026-72572
Analyzed
7.5
GitHub xmysql

A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated remote attacker to read and download arbitrary files from the...

2026-08-11
CVE-2026-72571
Analyzed
7.5
Unknown cast-localvideo

A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticated remote attacker to read arbitrary files from th...

2026-08-11
CVE-2026-72567
Analyzed
9.8
AsyncFuncAI deepwiki-open

The AsyncFuncAI deepwiki-open application is vulnerable to path traversal, allowing unauthenticated remote attackers to read, write, or delete arbitra...

2026-08-11
CVE-2026-72566
Analyzed
7.7
Automatisch Automatisch

A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a low-privileged authenticated user with 'manage Flow'...

2026-08-11
CVE-2026-72565
Analyzed
9.8
GitHub APIJSON

A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass access controls and read database con...

2026-08-11
CVE-2026-72564
Analyzed
9.6
Unknown Pangolin

An improper authorization vulnerability in fosrl Pangolin through v1.20.0 allows an authenticated remote attacker to access resources across organizat...

2026-08-11
CVE-2026-72562
Analyzed
8.8
Pimcore admin-ui-classic-bundle

An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2

2026-08-12
CVE-2026-72561
Analyzed
8.8
Peppermint Lab Peppermint

A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-administrative user to reconfig...

2026-08-12
CVE-2026-7256
Analyzed
8.8
Zyxel WRE6505 v2

** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1

2026-05-12
CVE-2026-72558
Analyzed
8.8
CiviCRM CiviCRM

An SQL injection vulnerability in CiviCRM through 6

2026-08-12
CVE-2026-72557
Analyzed
8.8
HP Cockpit CMS

An unrestricted file upload vulnerability in Cockpit CMS 2

2026-08-12
CVE-2026-72556
Analyzed
8.8
ZoneMinder ZoneMinder

A remote code execution vulnerability in ZoneMinder 1

2026-08-12
CVE-2026-72551
Analyzed
8.8
Apioo Fusio

A remote code execution vulnerability in Apioo Fusio 8

2026-08-12
CVE-2026-72537
Analyzed
8.8
Unknown authentik

A privilege escalation vulnerability in Authentik Security authentik through 2026

2026-08-12
CVE-2026-72534
Analyzed
8.8
Unknown authentik

A privilege escalation vulnerability in Authentik Security authentik through 2026

2026-08-12
CVE-2026-72533
Analyzed
8.8
Portainer Portainer CE

An authentication bypass vulnerability in Portainer CE through 2

2026-08-12
CVE-2026-72530
KEV Analyzed
9.5
TrueConf Server

TrueConf Server is affected by a code injection vulnerability that allows attackers to execute arbitrary code and escape isolated environments.

2026-08-21
CVE-2026-72529
KEV Analyzed
9.5
TrueConf Server

TrueConf Server contains a vulnerability involving missing authentication for critical functions, which allows unauthorized remote attackers to perfor...

2026-08-21