Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

48821
Total
3921
Critical
14470
High
14211
Medium
CVE ID Severity Score Description Published
CVE-2026-73294 CRITICAL 9.9 Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option to CmdGitClient.GetLastRemoteCommitHash … Aug 12, 2026
CVE-2026-73293 HIGH 8.8 Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5, ProjectMiddleware and GetProjectOrGlobalRoleBySlug allow a project manager … Aug 12, 2026
CVE-2026-73292 HIGH 8.3 Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore … Aug 12, 2026
CVE-2026-70547 MEDIUM 4.3 An authenticated user without repository read permission may access package metadata under specific conditions. Aug 12, 2026
CVE-2026-69107 MEDIUM 5.9 An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions. Aug 12, 2026
CVE-2026-69105 HIGH 8.1 An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability. Aug 12, 2026
CVE-2026-68971 UNKNOWN Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization … Aug 12, 2026
CVE-2026-68970 MEDIUM 6.5 Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared … Aug 12, 2026
CVE-2026-68969 UNKNOWN Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` … Aug 12, 2026
CVE-2026-68968 UNKNOWN Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization … Aug 12, 2026
CVE-2026-68759 HIGH 7.2 A holder of a valid integration credential may impersonate other users under specific conditions. Aug 12, 2026
CVE-2026-68758 MEDIUM 6.5 A low-privileged authenticated user may access restricted support information under specific conditions. Aug 12, 2026
CVE-2026-68076 MEDIUM 5.4 Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when … Aug 12, 2026
CVE-2026-67587 UNKNOWN Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. … Aug 12, 2026
CVE-2026-67260 HIGH 7.3 Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's … Aug 12, 2026
CVE-2026-66384 MEDIUM 5.3 An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. Aug 12, 2026
CVE-2026-66016 MEDIUM 6.7 Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users. Aug 12, 2026
CVE-2026-65941 HIGH 8.8 In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context … Aug 12, 2026
CVE-2026-65940 MEDIUM 6.8 In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server. Aug 12, 2026
CVE-2026-65939 MEDIUM 6.8 In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root. Aug 12, 2026
CVE-2026-65938 MEDIUM 4.3 In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions. Aug 12, 2026
CVE-2026-65937 HIGH 8.0 In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content. Aug 12, 2026
CVE-2026-65926 LOW 3.1 An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name … Aug 12, 2026
CVE-2026-65017 UNKNOWN Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config … Aug 12, 2026
CVE-2026-64639 UNKNOWN Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of … Aug 12, 2026