Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 29 May 2026

RSS

800 vulnerabilities published on 29 May 2026

Severity:
Dokploy PaaS: Hardcoded Secret Exposes Admin Access
CVE-2026-45631
Dokploy's self-hosted Platform as a Service is affected. An attacker without a login could gain full access to the system, including executing commands and signing in as an admin. Update to the latest...
10.0
NodeVM allows malicious code to run on host system
GHSA-rp36-8xq3-r6c4 CVE-2026-47140
A security issue affects NodeVM, a library that restricts certain Node.js functions. This allows malicious code to bypass those restrictions and execute on the host system, potentially leading to unau...
10.0
vm2: Unpatched Bypass Allows Full Remote Code Execution
GHSA-m4wx-m65x-ghrr CVE-2026-47137
A vulnerability in vm2 allows an attacker to run code on the host system if they create a nested sandbox without specifying the 'require' option. This could lead to full Remote Code Execution, allowin...
10.0
vm2 Sandbox Breakout Through Promise Species
GHSA-76w7-j9cq-rx2j CVE-2026-47208
The vm2 sandbox can be broken, allowing attackers to execute arbitrary commands on the host system. This vulnerability affects the vm2 JavaScript sandboxing library, which is used to safely run untrus...
10.0
vm2 Sandbox Escape allows Arbitrary Code Execution
GHSA-v6mx-mf47-r5wg CVE-2026-47131
A vulnerability in the vm2 library allows attackers to escape the sandbox and run arbitrary code on the host system. This could potentially lead to unauthorized access or data theft. To protect agains...
10.0
Suprema BioStar 2 allows public access to sensitive backup files
CVE-2026-9508
A security flaw in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) allows anyone on the network to download sensitive backup files without a password. This is a concern because the files contain imp...
10.0
Remote Spark SparkView Allows Arbitrary File Access as Root
CVE-2026-8326
Remote Spark's SparkView feature allows unauthorized access to files on the server, potentially leading to a complete takeover of the system. This is a serious issue because it could allow an attacker...
10.0
Firmware Backup Encryption Key Exposed in upload.cgi
CVE-2026-49201
An attacker can access and modify system backups on certain devices, potentially allowing them to install malicious software. This vulnerability affects the security of sensitive data stored on these ...
10.0
Acer Firmware: Cleartext Login Credentials Accessible via Web Interface
CVE-2026-49200
The Acer device's firmware stores login credentials in an unprotected log file. This means unauthorized users can access sensitive information and potentially gain control of the device. Users should ...
10.0
Mosquitto MQTT Command Injection Vulnerability
CVE-2026-49199
The Mosquitto MQTT server is vulnerable to a security risk that allows attackers to execute malicious code on devices connected to it. This could lead to unauthorized access or control of those device...
10.0
Acer Connect App Fails to Validate Authorization Header
CVE-2026-49197
The Acer Connect app's web endpoints are vulnerable to unauthorized access because they don't properly check the Authorization header. This could allow attackers to make requests as if they were autho...
10.0
PraisonAI vulnerable to arbitrary OS command execution
GHSA-4mr5-g6f9-cfrh CVE-2026-47392
PraisonAI's execute_code function in subprocess sandbox mode can be bypassed, allowing attackers to execute arbitrary OS commands on the host. This is a critical vulnerability that affects version 1.6...
9.9
stigmem-node: Anonymous access risk when auth is disabled outside local network
GHSA-fp6w-8wpg-74g5
If you're using stigmem-node and have disabled authentication, it's possible for anyone to access your data and settings from outside your local network. To fix this, update to the latest version of s...
9.9
FreeRDP Remote Desktop Protocol decoder has a memory safety issue.
DEBIAN-CVE-2026-45700
FreeRDP, a software that helps computers connect to each other over a network, has a bug that could allow an attacker to write data outside the safe area of memory. This could potentially lead to the ...
9.9
cpp-httplib: Malicious headers can cause server crashes
DEBIAN-CVE-2026-45372
A security issue was found in the cpp-httplib library, which is used for creating HTTP servers. This issue can allow an attacker to crash the server by sending a malicious HTTP request. To fix this, u...
9.9
cpp-httplib: Uncontrolled Data in Headers
CVE-2026-45372
A bug in cpp-httplib's server allowed malicious headers to be processed incorrectly, potentially leading to security issues. This vulnerability affects users of cpp-httplib before version 0.44.0. To f...
9.9
Shopper Headless e-commerce Admin Panel: Unauthorized Admin Access
CVE-2026-47744
Prior to version 2.8.0, any authenticated user could take over the Shopper Admin Panel, creating new administrator roles and deleting other users, including legitimate administrators. This allowed a l...
9.9
Dokploy 0.26.5 and Earlier: Authenticated Users Can Write Arbitrary Files
CVE-2026-45661
Dokploy's self-hosted service, used by administrators to deploy applications, has a security flaw that allows authorized users to create unwanted files on the server. This could lead to unauthorized a...
9.9
Dokploy command injection vulnerability in Docker logs endpoint
CVE-2026-45633
Dokploy's self-hosted PaaS platform has a security flaw in its Docker logs feature. This allows authenticated users to execute commands with root access, potentially leading to unauthorized changes or...
9.9
Dokploy PaaS allows unauthorized schedule creation
CVE-2026-45632
In Dokploy 0.26.7 and earlier, any authenticated user can create, update, or delete schedules belonging to other organizations. This could allow attackers to run malicious scripts on the Dokploy host ...
9.9
Dokploy PaaS allows authenticated server takeover via command injection
CVE-2026-45629
Dokploy's self-hosted Platform as a Service (PaaS) has a security issue that affects any organization member with authenticated access. This issue allows users to take control of remote servers manage...
9.9
Arcane Backend: Non-Admin Users Can Access Git Credentials
GHSA-7h26-hg47-p9hx CVE-2026-45625
A security issue in Arcane Backend's API allows non-admin users to access and potentially steal stored Git credentials. This is because the API does not require admin authentication for certain Git re...
9.9
Dokploy 0.29.1 and earlier: Unauthorized Docker File Uploads
CVE-2026-45663
Dokploy's Docker file upload feature has a security flaw that could allow an attacker to execute unauthorized commands on the server. This is a concern for any Dokploy user, as it could lead to data t...
9.9
Plesk APS Application Catalog Search Allows Unauthorized OS Commands
CVE-2026-44962
Plesk's search function in the Application Catalog can be tricked into executing system commands. This can happen if a low-privileged user knows what they're doing and has permission to use the search...
9.9
RAGFlow 0.24.0 and earlier: Unauthorized OS Command Execution
CVE-2026-45312
RAGFlow's open-source engine has a security flaw that allows authenticated users to run system commands on the server. This is a concern because any registered user can exploit this vulnerability. To ...
9.9