Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 10 August 2026
RSS993 vulnerabilities published on 10 August 2026
Severity:
Unauthenticated SQL Injection in Metabase
CVE-2026-72899
An attacker can inject malicious SQL code into a shared Metabase card or dashboard, potentially allowing them to access sensitive data or disrupt the system. This is a serious risk because it can happ...
10.0
Metabase: Unauthenticated SQL Injection via Reset Password
CVE-2026-72898
Metabase's reset password feature can be exploited by an attacker to inject malicious SQL code, potentially gaining administrator access to the connected database. This vulnerability allows an attacke...
10.0
KEV
Joomla Fabrik Extension < 4.6.7 Allows Unauthenticated Code Execution
CVE-2026-66915
The Fabrik extension for Joomla, available from fabrikar.com, has a vulnerability that allows an attacker to run malicious code without needing a login. This could potentially allow an attacker to acc...
10.0
Feast: Malicious UDFs Can Execute Code Remotely
CVE-2026-18948
Feast, a data management system, has a security flaw that allows a hacker to store malicious code on its servers. This code can then be executed remotely, potentially allowing the hacker to access sen...
9.9
ERPNext: Malicious Code Can Execute on Server
CVE-2026-72911
ERPNext users need to update to version 15.118.0 or 16.29.0 to prevent malicious code execution. This issue allowed an authenticated user to execute arbitrary server-side code and read sensitive data,...
9.9
MaaS API: Unauthorized Access via Fake User IDs
CVE-2026-14450
The MaaS API has a security flaw that allows attackers to pretend to be a valid user and gain access to sensitive information. This can lead to unauthorized access to other users' data and the ability...
9.9
Dokploy: Authenticated User Can Execute Commands on Server
CVE-2026-72902
Dokploy, a self-hosted Platform as a Service, had a security issue that allowed an authenticated user to execute commands on a server. This means an attacker could gain access to sensitive information...
9.9
Dokploy: Attacker Can Run Commands on Managed Servers
CVE-2026-72882
Dokploy's web interface allows attackers to run commands on remote servers if they have the ability to create or update file mounts. This can happen if an attacker has an account on the Dokploy server...
9.9
Dokploy: Unsecured File Writes and Unauthorized OS Commands
CVE-2026-72880
Dokploy's self-hosted Platform as a Service (PaaS) has a security issue that allows an authenticated user to write files outside the intended directory or run unauthorized system commands. This is fix...
9.9
Dokploy: Authenticated User Can Run Commands on Server
CVE-2026-72901
An authenticated user can run commands on the Dokploy server with root privileges. This is a serious security risk because it allows an attacker to take control of the server. To fix this issue, updat...
9.9
Dokploy: Unauthorized users gain root access on the host
CVE-2026-72886
A security flaw in Dokploy allowed non-admin users to gain root access on the host by exploiting a scheduling feature. This could have allowed unauthorized users to execute malicious scripts with elev...
9.9
Dokploy: Malicious Git Commands Executed on Host or Server
CVE-2026-72872
Dokploy's self-hosted Platform as a Service allows unauthorized users with deployment permissions to run arbitrary system commands on the host or target server. This is fixed in version 0.29.13. To pr...
9.9
Dokploy: Malicious Database Name Can Execute Host Commands
CVE-2026-72869
A security issue in Dokploy allows an authenticated user to execute arbitrary commands on the host machine. This can happen if the user has permission to restore backups and supplies a specially craft...
9.9
Dokploy: Malicious data can execute commands as host root
CVE-2026-72868
Dokploy users are at risk of a security breach if an attacker gains access to a low-privileged organization member's account. This can happen if an attacker is able to manipulate certain settings in D...
9.9
Dokploy: Malicious Branches Can Execute Arbitrary Commands
CVE-2026-72867
Dokploy users who haven't updated to version 0.29.13 are at risk of malicious branch names being used to execute arbitrary commands on their server. This could allow an attacker to take control of the...
9.9
Dokploy: Unvalidated Input Allows Malicious Docker Commands
CVE-2026-72865
An authenticated user with certain permissions can execute arbitrary system commands on the Dokploy server. This can allow them to delete or modify files, or even take control of the server. To fix th...
9.9
Dokploy: Attacker Can Access Any Container on Your Server
CVE-2026-72864
Dokploy, a self-hosted Platform as a Service, has a security issue that allows any authenticated user to access and control any container on your server. This is a serious risk because it could lead t...
9.9
Dokploy: Malicious Tenant Can Access Another's Server
CVE-2026-72876
Dokploy's self-hosted servers allow a malicious tenant with server access to execute arbitrary commands on another tenant's server. This is a serious security risk, as it could allow unauthorized acce...
9.9
Dokploy: Unprivileged users can access Docker host as root
CVE-2026-72863
Dokploy's in-app terminals and log streamers don't check user permissions. This allows a user with limited access to gain full control of the Docker host, including becoming the root user. Update to v...
9.9
Dokploy PaaS allows unauthorized Docker image downloads
CVE-2026-72862
Dokploy's database service deployment function in versions prior to 0.29.13 allows attackers to download any Docker image without authorization. This is a security risk because it allows unauthorized ...
9.9
Dokploy: Malicious Code Can Run on Host Server
CVE-2026-72736
Dokploy, a self-hosted Platform as a Service, had a security issue where an attacker could potentially run malicious code on the host server. This was fixed in version 0.29.13, so update to the latest...
9.9
Dokploy: Unauthorized commands can be executed on remote servers
CVE-2026-72735
Dokploy's remote server management feature allows unauthorized commands to be executed on remote servers with the configured SSH user's privileges. This is due to an incomplete fix for a previous secu...
9.9
Dokploy allows malicious code execution during deployment
CVE-2026-72740
Dokploy users with deployment permission and SSH keys can execute arbitrary commands on the Dokploy server, potentially leading to unauthorized access or data loss. To fix this, update to Dokploy vers...
9.9
Dokploy Backup: Authenticated Remote Code Execution via Command Injection
CVE-2026-72738
An authenticated user with backup access can execute arbitrary commands on the Dokploy server. This can lead to data loss or system compromise. Update to version 0.29.13 or later to fix this issue.
9.9
Dokploy: Malicious Commands Can Be Executed on Server
CVE-2026-72733
Dokploy's database restore feature allows authenticated users with permission to execute arbitrary commands on the server. This could lead to unauthorized access or data loss. Update to version 0.29.1...
9.9