Export limit exceeded: 377079 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (377079 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-72877 | 1 Dokploy | 1 Dokploy | 2026-08-13 | 9.6 Critical |
| Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated without quoting into shell commands in buildRemoteDocker() in packages/server/src/utils/providers/docker.ts and is validated only as an optional string. An authenticated user with application create or update permission can use shell command substitution in dockerImage to execute arbitrary commands on the local build host or a remote SSH build target, exposing host secrets and other projects. This issue is fixed in version 0.29.13. | ||||
| CVE-2026-72737 | 1 Dokploy | 1 Dokploy | 2026-08-13 | 9.6 Critical |
| Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs in apps/dokploy/server/api/routers/backup.ts accept a client-controlled destinationId and use the referenced destination without verifying that destination.organizationId equals ctx.session.activeOrganizationId. An authenticated member with backup permissions for a service in one organization can cause another organization's S3 accessKey and secretAccessKey to be materialized by packages/server/src/utils/backups/utils.ts getS3Credentials on the attacker's service host, read that organization's backup objects, or redirect and poison backups across tenant boundaries. | ||||
| CVE-2026-70547 | 1 Jfrog | 1 Artifactory | 2026-08-13 | 4.3 Medium |
| An authenticated user without repository read permission may access package metadata under specific conditions. | ||||
| CVE-2026-70467 | 1 Fortinet | 1 Fortisiem | 2026-08-13 | 3.4 Low |
| A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here> | ||||
| CVE-2026-70458 | 2026-08-13 | 8.2 High | ||
| rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED flag set while the hard-link preservation option is inactive. Attackers can exploit the missing F_SUM field in the file_struct layout to access memory past the end of the allocated structure, corrupting adjacent heap or stack data. | ||||
| CVE-2026-70454 | 2026-08-13 | 8 High | ||
| rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to validate server TLS certificates against a trusted CA or verify certificate hostname matching to decrypt or tamper with rsync session content without detection by the client. | ||||
| CVE-2026-6821 | 1 Gitlab | 1 Gitlab | 2026-08-13 | 4.3 Medium |
| GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to bypass IP-based access restrictions and read limited merge request information from a private project due to missing authorization checks in a merge requests API endpoint. | ||||
| CVE-2026-6469 | 1 Postgresql | 1 Postgresql | 2026-08-13 | 3.8 Low |
| Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. | ||||
| CVE-2026-6464 | 1 Postgresql | 1 Postgresql | 2026-08-13 | 8.1 High |
| Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. | ||||
| CVE-2026-69105 | 1 Jfrog | 1 Artifactory | 2026-08-13 | 8.1 High |
| An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability. | ||||
| CVE-2026-66878 | 1 Redhat | 2 Acm, Advanced Cluster Management For Kubernetes | 2026-08-13 | 7.7 High |
| A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Namespace field, the user can cause the system to copy sensitive Secret contents from other namespaces into their own, leading to information disclosure. | ||||
| CVE-2026-66704 | 2026-08-13 | 7.2 High | ||
| Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions. | ||||
| CVE-2026-66697 | 2026-08-13 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions. | ||||
| CVE-2026-66691 | 2026-08-13 | 9.8 Critical | ||
| Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions. | ||||
| CVE-2026-66689 | 2026-08-13 | 6.3 Medium | ||
| Unauthenticated Broken Access Control in Anti Spam and list cleaner – AcyChecker <= 2.0.0 versions. | ||||
| CVE-2026-66661 | 2026-08-13 | 7.7 High | ||
| Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions. | ||||
| CVE-2026-66658 | 2026-08-13 | 8.5 High | ||
| Subscriber SQL Injection in Reviewer <= 3.14.2 versions. | ||||
| CVE-2026-66657 | 2026-08-13 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions. | ||||
| CVE-2026-66656 | 2026-08-13 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions. | ||||
| CVE-2026-66654 | 2026-08-13 | 6 Medium | ||
| Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions. | ||||