Vulnerabilidades en coollabsio
73 resultadosAnálisis Vexday
A Coollabs acumula 71 vulnerabilidades no histórico, com 46 publicadas nos últimos 90 dias, indicando ritmo acelerado de descobertas. Embora nenhuma esteja sob exploração ativa no momento, 19 são classificadas como críticas, predominantemente relacionadas a injeção de comandos (CWE-78), o que representa risco significativo se explorado. A concentração recente de divulgações requer monitoramento atento e priorização de patches críticos.
CVE-2025-66209CRITICALCoolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database BackupEPSS 3.9%CVE-2025-66213CRITICALCoolify Vulnerable to Authenticated Remote Code Execution via Command Injection in File Storage Directory Mount PathEPSS 3.1%CVE-2025-66212CRITICALCoolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Dynamic Proxy Configuration FilenameEPSS 3.1%CVE-2026-34599HIGHCoolify: Authenticated Remote Code Execution in GetLogs Livewire ComponentEPSS 2.8%CVE-2025-66210CRITICALCoolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database ImportEPSS 2.7%CVE-2025-66211CRITICALCoolify Vulnerable to Authenticated Remote Code Execution via Command Injection in PostgreSQL Init Script FilenameEPSS 2.7%CVE-2026-34038CRITICALCoolify authenticated remote command injection leading to RCE and secret exfiltrationEPSS 2.5%CVE-2025-64424CRITICALColify has command injection vulnerability in project git sourceEPSS 2.1%CVE-2026-12815MEDIUMcoollabsio coolify Image Name os command injectionEPSS 2.0%CVE-2026-34594HIGHCoolify: Authenticated Remote Code Execution via Command Injection in Destination Network ManagementEPSS 1.9%CVE-2025-59157CRITICALCoolify has Git Repository RCEEPSS 1.8%CVE-2026-27957HIGHCoolify: Authenticated RCE via command injection in CA certificate management featureEPSS 1.2%CVE-2026-34597HIGHCoolify: Authenticated Host RCEEPSS 1.0%CVE-2025-59156CRITICALCoolify has Docker Compose Injection issueEPSS 1.0%CVE-2026-42200HIGHCoolify: PostgreSQL Init Script Path Traversal Leads to Arbitrary File Write and Root RCEEPSS 0.9%CVE-2026-59734HIGHCoolify: OS Command Injection in Health Check Configuration Allows Remote Code ExecutionEPSS 0.8%CVE-2026-34048CRITICALCoolify: Missing authorization on terminal websocket bootstrap routes allows low-privileged members to execute commands on team serversEPSS 0.8%CVE-2026-42143HIGHCoolify: OS Command Injection via Persistent Volume Names - Root RCE on Managed ServersEPSS 0.8%CVE-2026-34153HIGHCoolify LocalFileVolume fs_path command injection enables RCEEPSS 0.8%CVE-2026-34034HIGHCoolify: Host RCE via Sentinel token injectionEPSS 0.8%