Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

25534
Total
1899
Critical
7798
High
8005
Medium
CVE ID Severity Score Description Published
CVE-2026-5386 CRITICAL 9.1 The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password … May 29, 2026
CVE-2026-47179 HIGH 7.7 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.GetProjectFileContent returns the contents of any Docker Compose include directive … May 29, 2026
CVE-2026-47125 HIGH 8.8 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/environments/{id}/templates/variables endpoint, which writes the system-wide .env.global file … May 29, 2026
CVE-2026-45668 UNKNOWN Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.102.2, a malicious ZIP archive imported with … May 29, 2026
CVE-2026-45661 CRITICAL 9.9 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows … May 29, 2026
CVE-2026-45660 MEDIUM 5.4 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image proxy's URL validation could be bypassed … May 29, 2026
CVE-2026-45633 CRITICAL 9.9 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. … May 29, 2026
CVE-2026-45632 CRITICAL 9.9 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, … May 29, 2026
CVE-2026-45631 CRITICAL 10.0 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-secret-123456789") lets an unauthenticated attacker forge … May 29, 2026
CVE-2026-45630 CRITICAL 9.0 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner … May 29, 2026
CVE-2026-45629 CRITICAL 9.9 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment WebSocket endpoint allows any … May 29, 2026
CVE-2026-45628 CRITICAL 9.6 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands using JavaScript template literals and executes them … May 29, 2026
CVE-2026-45627 HIGH 8.2 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint reflects a user-supplied color query … May 29, 2026
CVE-2026-45626 MEDIUM 6.3 Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /environments/{id}/volumes/{volumeName}/browse accepts a path query parameter that is … May 29, 2026
CVE-2026-45625 CRITICAL 9.9 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/customize/git-repositories and … May 29, 2026
CVE-2026-45577 UNKNOWN Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as local when the app … May 29, 2026
CVE-2026-44697 HIGH 8.6 Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/batch.go) allows any peer that … May 29, 2026
CVE-2026-43917 UNKNOWN Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.19.0 and earlier, the protectedProcedure middleware only verifies the user is authenticated - it … May 29, 2026
CVE-2026-10108 HIGH 7.5 xiaomusic v0.5.7 contains an unauthenticated path traversal vulnerability in the GET /music/{file_path:path} endpoint that allows unauthenticated attackers to read arbitrary files outside the intended music … May 29, 2026
CVE-2026-10107 HIGH 7.7 MoviePilot v2 contains a server-side request forgery vulnerability in the image proxy endpoint that allows authenticated attackers to request arbitrary URLs by supplying a resource_token … May 29, 2026
CVE-2026-10105 HIGH 8.3 agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inject arbitrary SQL expressions by supplying malicious metadata … May 29, 2026
CVE-2026-10070 MEDIUM 4.7 A vulnerability was found in macrozheng mall up to 1.0.3. This affects an unknown function of the file /admin/update/ of the component Super Admin Password … May 29, 2026
CVE-2026-9194 UNKNOWN Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this … May 29, 2026
CVE-2026-48501 HIGH 7.4 GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF repository mirrors … May 29, 2026
CVE-2026-45663 CRITICAL 9.9 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. … May 29, 2026