10

CVSS3.1

CVE-2025-22612 - Coolify Vulnerable to Private Key Enumeration on Onboarding resulting in Remote Command Execution (…

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.374, the missing authorization allows an authenticated user to retrieve any existing private keys on a coolify instance in plain text. If the server configuration of IP / …

πŸ“… Published: Jan. 24, 2025, 4:43 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 3:27 p.m.

10

CVSS3.1

CVE-2025-22611 - Coolify vulnerable to Privilege Escalation resulting in Remote Command Execution (RCE)

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to escalate his or any other team members privileges to any role, including the owner role. He's also able to …

πŸ“… Published: Jan. 24, 2025, 4:35 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 3:26 p.m.

5.7

CVSS4.0

CVE-2025-22610 - Coolify Vulnerable to OAuth Secrets Leak

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to fetch the global coolify instance OAuth configuration. This exposes the "client id" and "client secret" for…

πŸ“… Published: Jan. 24, 2025, 4:33 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 3:26 p.m.

10

CVSS3.1

CVE-2025-22609 - Coolify Vulnerable to Private Key Hijacking / Remote Command Execution (RCE)

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to attach any existing private key on a coolify instance to his own server. If the server configuration of IP …

πŸ“… Published: Jan. 24, 2025, 4:30 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 3:21 p.m.

6.5

CVSS3.1

CVE-2025-22608 - Coolify Vulnerable to Revocation of Arbitrary Team Invitations (DOS)

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to revoke any team invitations on a Coolify instance by only providing a predictable and incrementing ID, resu…

πŸ“… Published: Jan. 24, 2025, 4:28 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 3:14 p.m.

4.7

CVSS4.0

CVE-2025-22607 - Coolify Vulnerable to GitHub / GitLab OAuth Secrets Leak

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to fetch the details page for any GitHub / GitLab configuration on a Coolify instance by only knowing the UUID…

πŸ“… Published: Jan. 24, 2025, 3:45 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 3:12 p.m.

8.5

CVSS4.0

CVE-2025-22606 - Coolify Command Injection Vulnerability in Project Name

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In version 4.0.0-beta.358 and possibly earlier versions, when creating or updating a "project," it is possible to inject arbitrary shell commands by altering the project name. If a name includes unes…

πŸ“… Published: Jan. 24, 2025, 3:38 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 3:12 p.m.

6.5

CVSS3.1

CVE-2024-45077 - IBM Maximo Asset Management file upload

IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API is vulnerable to unrestricted file upload which allows authenticated low privileged user to upload restricted file types with a simple method of adding a dot to the end of the file name if Maximo is installed on Windows operating system.

πŸ“… Published: Jan. 24, 2025, 3:38 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 3:18 p.m.

4.3

CVSS3.1

CVE-2025-23991 - WordPress Product Size Charts Plugin for WooCommerce plugin <= 2.4.5 - Broken Access Control vulner…

Missing Authorization vulnerability in Dotstore Product Size Charts Plugin for WooCommerce woo-advanced-product-size-chart.This issue affects Product Size Charts Plugin for WooCommerce: from n/a through <= 2.4.5.

πŸ“… Published: Jan. 24, 2025, 3:31 p.m. πŸ”„ Last Modified: April 23, 2026, 3:24 p.m.

5.3

CVSS4.0

CVE-2025-0699 - JoeyBling bootplus list sql injection

A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/sys/role/list. The manipulation of the argument sort leads to sql injection. The attack can…

πŸ“… Published: Jan. 24, 2025, 3:31 p.m. πŸ”„ Last Modified: Oct. 10, 2025, 7:05 p.m.
Total resulsts: 349182
Page 6976 of 34,919
Β« previous page Β» next page
Filters