Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48821
Total
3921
Critical
14470
High
14211
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-73289 | HIGH | 8.1 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: set qualifiers with the negated string … | Aug 12, 2026 |
| CVE-2026-73288 | UNKNOWN | — | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crates/ecstore/src/bucket/object_lock/objectlock_sys.rs lets check_object_lock_for_deletion, delete_prefix, and lifecycle and … | Aug 12, 2026 |
| CVE-2026-73287 | MEDIUM | 5.4 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriver::mkd in crates/protocols/src/ftps/driver.rs by calling storage.create_bucket without … | Aug 12, 2026 |
| CVE-2026-73286 | HIGH | 8.1 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, … | Aug 12, 2026 |
| CVE-2026-73285 | HIGH | 7.5 | RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTFS_POLICY_PLUGIN_URL in crates/iam/src/sys.rs sets PreparedIamAuth.needs_existing_object_tag … | Aug 12, 2026 |
| CVE-2026-73284 | HIGH | 8.8 | RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/service_account.rs accepts an attacker-controlled target_user after only checking CreateServiceAccountAdminAction, passes it to … | Aug 12, 2026 |
| CVE-2026-73265 | MEDIUM | 6.5 | RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadPartCopy sources with s3:GetObject instead … | Aug 12, 2026 |
| CVE-2026-73264 | HIGH | 7.6 | Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration access could supply an unvalidated base_url for the openai_compatible … | Aug 12, 2026 |
| CVE-2026-73263 | CRITICAL | 9.9 | Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args … | Aug 12, 2026 |
| CVE-2026-73262 | MEDIUM | 5.4 | Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.py inserted finding.resource_tags, assembled by unroll_dict and parse_html_string, into generated reports … | Aug 12, 2026 |
| CVE-2026-68760 | MEDIUM | 5.3 | An unauthenticated user may bypass authentication under specific cache conditions. | Aug 12, 2026 |
| CVE-2026-68757 | HIGH | 7.5 | A user with access to a valid SAML response may impersonate another user under specific conditions. | Aug 12, 2026 |
| CVE-2026-68756 | MEDIUM | 6.6 | A party with write access to stored session data may affect JFrog Artifactory under specific conditions. | Aug 12, 2026 |
| CVE-2026-68755 | MEDIUM | 4.3 | A bundle writer may create misleading release promotion information under specific conditions. | Aug 12, 2026 |
| CVE-2026-68754 | MEDIUM | 6.5 | A repository publisher without delete permission may modify protected package content under specific conditions. | Aug 12, 2026 |
| CVE-2026-68753 | MEDIUM | 5.3 | An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way. | Aug 12, 2026 |
| CVE-2026-68752 | HIGH | 7.2 | A Project Resource Manager may gain broader administrative privileges under specific conditions. | Aug 12, 2026 |
| CVE-2026-67287 | UNKNOWN | — | Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled … | Aug 12, 2026 |
| CVE-2026-67286 | UNKNOWN | — | Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary … | Aug 12, 2026 |
| CVE-2026-66382 | MEDIUM | 4.3 | An authenticated user may write files outside the intended Artifactory work directory under specific conditions. | Aug 12, 2026 |
| CVE-2026-66381 | MEDIUM | 5.3 | A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions. | Aug 12, 2026 |
| CVE-2026-66380 | MEDIUM | 4.3 | An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions. | Aug 12, 2026 |
| CVE-2026-66379 | MEDIUM | 4.3 | An authenticated user may view private Puppet module metadata without repository read access. | Aug 12, 2026 |
| CVE-2026-66378 | MEDIUM | 4.3 | An authenticated user without repository read permission may access private NuGet metadata under specific conditions. | Aug 12, 2026 |
| CVE-2026-66377 | MEDIUM | 5.3 | An unauthenticated user may access restricted repository information under specific conditions. | Aug 12, 2026 |