Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
78 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.5) | 0.43% | — | Coollabs Coolify | 5/1/2026 | 30/9/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, an attacker can initiate a password reset for a victim, and modify the host header of the request to a malicious value. The victim will receive a password reset… | |
| Analizada | Crítica (9.4) | 2.1% | — | Coollabs Coolify | 5/1/2026 | 30/9/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vulnerability exists in the git source input fields of a resource, allowing a low privileged user (member) to execute system commands as root… | |
| Analizada | Alta (7.7) | 0.35% | — | Coollabs Coolify | 5/1/2026 | 30/9/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a low privileged user (member) can see and use invitation links sent to an administrator. When they use the link before the legitimate recipient does, they are… | |
| Analizada | Media (5.5) | 0.31% | — | Coollabs Coolify | 5/1/2026 | 30/9/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting with version 4.0.0-beta.434, the /login endpoint advertises a rate limit of 5 requests but can be trivially bypassed by rotating the X-Forwarded-For header. This enables unlimited credential… | |
| Analizada | Alta (8.7) | 0.30% | — | Coollabs Coolify | 5/1/2026 | 30/9/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a low privileged user (member) can invite a high privileged user. At first, the application will throw an error, but if the attacker clicks the invite button a… | |
| Analizada | Alta (8.8) | 0.53% | — | Coollabs Coolify | 5/1/2026 | 30/9/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0-beta.434, low privileged users are able to see the private key of the root user on the Coolify instance. This allows them to ssh to the server and authenticate as root… | |
| Analizada | Alta (8.8) | 0.66% | — | Coollabs Coolify | 5/1/2026 | 30/9/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.445, parameters coming from docker-compose.yaml are not sanitized when used in commands. If a victim user creates an application from an attacker repository (using build pack "docker… | |
| Analizada | Media (5.7) | 0.30% | — | Coollabs Coolify | 5/1/2026 | 30/9/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.8 have an information disclosure vulnerability in the `/api/v1/teams/{team_id}/members` and `/api/v1/teams/current/members` API endpoints allows authenticated team… | |
| Analizada | Crítica (9.4) | 0.50% | — | Coollabs Coolify | 5/1/2026 | 30/9/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges (e.g., member role) can… | |
| Analizada | Alta (8.8) | 1.8% | — | Coollabs Coolify | 5/1/2026 | 30/9/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, the Git Repository field during project creation is vulnerable to command injection. User input is not properly sanitized, allowing attackers to inject arbitrary shell commands that… | |
| Analizada | Crítica (9.4) | 1.00% | — | Coollabs Coolify | 5/1/2026 | 30/9/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, a Remote Code Execution (RCE)*vulnerability exists in Coolify's application deployment workflow. This flaw allows a low-privileged member to inject arbitrary Docker Compose directives… | |
| Modificada | Crítica (9.4) | 3.1% | — | Coollabs Coolify | 23/12/2025 | 17/6/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the File Storage Directory Mount Path functionality allows users with application/service management permissions to execute arbitrary… | |
| Modificada | Crítica (9.4) | 3.1% | — | Coollabs Coolify | 23/12/2025 | 17/6/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Dynamic Proxy Configuration Filename handling allows users with application/service management permissions to execute arbitrary… | |
| Modificada | Crítica (9.4) | 2.7% | — | Coollabs Coolify | 23/12/2025 | 17/6/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in PostgreSQL Init Script Filename handling allows users with application/service management permissions to execute arbitrary commands as… | |
| Modificada | Crítica (9.4) | 2.7% | — | Coollabs Coolify | 23/12/2025 | 17/6/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Import functionality allows users with application/service management permissions to execute arbitrary commands as root… | |
| Modificada | Alta (8.8) | 3.9% | — | Coollabs Coolify | 23/12/2025 | 17/6/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Backup functionality allows users with application/service management permissions to execute arbitrary commands as root… | |
| Analizada | Crítica (9.4) | 3.0% | — | Coollabs Coolify | 27/8/2025 | 14/7/2026 | Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary shell commands via the Git Repository field during project creation. By submitting a… | |
| Analizada | Crítica (9.4) | 0.96% | — | Coollabs Coolify | 27/8/2025 | 14/7/2026 | Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary Docker Compose directives during project creation. By crafting a malicious service… | |
| Analizada | Crítica (9.4) | 0.46% | — | Coollabs Coolify | 27/8/2025 | 14/7/2026 | Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a maliciously crafted name containing embedded JavaScript. When an administrator attempts to delete the project… | |
| Analizada | Baja (1.3) | 0.23% | — | Coollabs Coolify | 24/1/2025 | 17/6/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.380, the tags page allows users to search for tags. If the search does not return any results, the query gets reflected on the error modal, which leads to cross-site scripting. Version… | |
| Analizada | Crítica (10) | 0.62% | — | Coollabs Coolify | 24/1/2025 | 17/6/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.374, the missing authorization allows an authenticated user to retrieve any existing private keys on a coolify instance in plain text. If the server configuration of IP / domain, port (most… | |
| Analizada | Crítica (9.9) | 0.49% | — | Coollabs Coolify | 24/1/2025 | 17/6/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to escalate his or any other team members privileges to any role, including the owner role. He's also able to kick every other… | |
| Analizada | Media (5.7) | 0.39% | — | Coollabs Coolify | 24/1/2025 | 17/6/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to fetch the global coolify instance OAuth configuration. This exposes the "client id" and "client secret" for every custom OAuth… | |
| Analizada | Crítica (10) | 0.75% | — | Coollabs Coolify | 24/1/2025 | 17/6/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to attach any existing private key on a coolify instance to his own server. If the server configuration of IP / domain, port (most… | |
| Analizada | Media (6.5) | 0.36% | — | Coollabs Coolify | 24/1/2025 | 17/6/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to revoke any team invitations on a Coolify instance by only providing a predictable and incrementing ID, resulting in a… |