8.5

CVSS4.0

CVE-2025-64425 - Coolify has host header injection in forgot password

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, an attacker can initiate a password reset for a victim, and modify the host header of the request to a malicious value. The victim will receiv…

📅 Published: Jan. 5, 2026, 8:49 p.m. 🔄 Last Modified: Jan. 12, 2026, 6:36 p.m.

9.4

CVSS4.0

CVE-2025-64424 - Colify has command injection vulnerability in project git source

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vulnerability exists in the git source input fields of a resource, allowing a low privileged user (member) to execute syst…

📅 Published: Jan. 5, 2026, 8:45 p.m. 🔄 Last Modified: Jan. 12, 2026, 6:37 p.m.

7.7

CVSS4.0

CVE-2025-64423 - Coolify has a Privilege Escalation - low privileged users can see and use admin invitation links

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a low privileged user (member) can see and use invitation links sent to an administrator. When they use the link before the legitimate recipie…

📅 Published: Jan. 5, 2026, 8:41 p.m. 🔄 Last Modified: Jan. 9, 2026, 4:10 p.m.

6.9

CVSS4.0

CVE-2026-0605 - code-projects Online Music Site login.php sql injection

A security vulnerability has been detected in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. Such manipulation of the argument username/password leads to sql injection. The attack may be performed from remote. The exploit has …

📅 Published: Jan. 5, 2026, 8:32 p.m. 🔄 Last Modified: April 18, 2026, 8:30 a.m.

5.5

CVSS4.0

CVE-2025-64422 - Rate-limit bypass on login via X-Forwarded-Host header

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting with version 4.0.0-beta.434, the /login endpoint advertises a rate limit of 5 requests but can be trivially bypassed by rotating the X-Forwarded-For header. This enables unlimite…

📅 Published: Jan. 5, 2026, 8:29 p.m. 🔄 Last Modified: Jan. 12, 2026, 2:23 p.m.

8.7

CVSS4.0

CVE-2025-64421 - Coolify has a privilege escalation - low privileged user can invite themselves as an admin user

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a low privileged user (member) can invite a high privileged user. At first, the application will throw an error, but if the attacker clicks th…

📅 Published: Jan. 5, 2026, 7:42 p.m. 🔄 Last Modified: Jan. 12, 2026, 2:26 p.m.

10

CVSS3.1

CVE-2025-64420 - Coolify members can see private key of root user

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0-beta.434, low privileged users are able to see the private key of the root user on the Coolify instance. This allows them to ssh to the server and au…

📅 Published: Jan. 5, 2026, 7:20 p.m. 🔄 Last Modified: Jan. 12, 2026, 2:31 p.m.

9.7

CVSS3.1

CVE-2025-64419 - Coolify vulnerable to command injection via docker-compose.yaml parameters

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.445, parameters coming from docker-compose.yaml are not sanitized when used in commands. If a victim user creates an application from an attacker repository (using build p…

📅 Published: Jan. 5, 2026, 7:16 p.m. 🔄 Last Modified: Jan. 12, 2026, 2:38 p.m.

7.1

CVSS3.1

CVE-2025-61781 - GraphQL IDOR allows authenticated user to delete workspace content of other users

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.1, the GraphQL mutation "WorkspacePopoverDeletionMutation" allows users to delete workspace-related objects such as dashboards and investigation cases. However, the mutation lac…

📅 Published: Jan. 5, 2026, 5:53 p.m. 🔄 Last Modified: Jan. 30, 2026, 1:18 a.m.

5.7

CVSS4.0

CVE-2025-59955 - Coolify leaksensitive information `email_change_code` in `/api/v1/teams/{team_id | current}/members…

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.8 have an information disclosure vulnerability in the `/api/v1/teams/{team_id}/members` and `/api/v1/teams/current/members` API endpoints allow…

📅 Published: Jan. 5, 2026, 5:46 p.m. 🔄 Last Modified: Jan. 12, 2026, 2:48 p.m.
Total resulsts: 349182
Page 2284 of 34,919
« previous page » next page
Filters