Threat Alerts

Real-time critical CVE alerts, security advisories, and vulnerability intelligence — curated by the Vulnios Threat Intelligence team.

500 Critical
0 High
500 Total Alerts
Follow on TelegramSubscribe via RSS
Filter:
500 alerts
criticalCVE Alert
CVE-2026-44985

Critical Vulnerability: CVE-2026-44985 — amirraminfar — dozzle

Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach endpoints uses CheckOrigin: func(r *http.Request) bool { return true }, acceptin

amirraminfar· dozzle
criticalxss
May 29 · 8:57 PM
Read analysis
criticalCVE Alert
CVE-2026-47744

Critical Vulnerability: CVE-2026-47744

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/I

critical
May 29 · 8:16 PM
Read analysis
criticalCVE Alert
CVE-2026-9051

Critical Vulnerability: CVE-2026-9051

There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to pri

criticalauth-bypassprivesc
May 29 · 8:16 PM
Read analysis
criticalCVE Alert
CVE-2026-44650

Critical Vulnerability: CVE-2026-44650

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,

critical
May 29 · 8:16 PM
Read analysis
criticalCVE Alert
CVE-2026-44649

Critical Vulnerability: CVE-2026-44649

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,

critical
May 29 · 8:16 PM
Read analysis
criticalVendor Advisory
CVE-2026-0257

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-0257 Palo Alto Networks PAN-OS Authentication Bypass Vulne

Palo Alto· PAN-OS
zero-dayrceics-ot
May 29 · 7:36 PM
Read analysis
criticalCVE Alert
CVE-2026-45628

Critical Vulnerability: CVE-2026-45628

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands using JavaScript template literals and executes them via child_process.exec() (w

critical
May 29 · 7:16 PM
Read analysis
criticalCVE Alert
CVE-2026-45661

Critical Vulnerability: CVE-2026-45661

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated users to write arbitra

criticalrce
May 29 · 7:16 PM
Read analysis
criticalCVE Alert
CVE-2026-45629

Critical Vulnerability: CVE-2026-45629

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment WebSocket endpoint allows any organization member to

critical
May 29 · 7:16 PM
Read analysis
criticalCVE Alert
CVE-2026-45633

Critical Vulnerability: CVE-2026-45633

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and

critical
May 29 · 7:16 PM
Read analysis
criticalCVE Alert
CVE-2026-45632

Critical Vulnerability: CVE-2026-45632

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authenticated user can create, upd

criticalrce
May 29 · 7:16 PM
Read analysis
criticalCVE Alert
CVE-2026-45625

Critical Vulnerability: CVE-2026-45625

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/customize/git-repositories and /ap

critical
May 29 · 7:16 PM
Read analysis

Protect Your Organization

Monitor CVEs, scan for vulnerabilities, and get real-time threat alerts — all in one platform.