Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

48821
Total
3921
Critical
14470
High
14211
Medium
CVE ID Severity Score Description Published
CVE-2026-73289 HIGH 8.1 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: set qualifiers with the negated string … Aug 12, 2026
CVE-2026-73288 UNKNOWN RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crates/ecstore/src/bucket/object_lock/objectlock_sys.rs lets check_object_lock_for_deletion, delete_prefix, and lifecycle and … Aug 12, 2026
CVE-2026-73287 MEDIUM 5.4 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriver::mkd in crates/protocols/src/ftps/driver.rs by calling storage.create_bucket without … Aug 12, 2026
CVE-2026-73286 HIGH 8.1 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, … Aug 12, 2026
CVE-2026-73285 HIGH 7.5 RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTFS_POLICY_PLUGIN_URL in crates/iam/src/sys.rs sets PreparedIamAuth.needs_existing_object_tag … Aug 12, 2026
CVE-2026-73284 HIGH 8.8 RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/service_account.rs accepts an attacker-controlled target_user after only checking CreateServiceAccountAdminAction, passes it to … Aug 12, 2026
CVE-2026-73265 MEDIUM 6.5 RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadPartCopy sources with s3:GetObject instead … Aug 12, 2026
CVE-2026-73264 HIGH 7.6 Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration access could supply an unvalidated base_url for the openai_compatible … Aug 12, 2026
CVE-2026-73263 CRITICAL 9.9 Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args … Aug 12, 2026
CVE-2026-73262 MEDIUM 5.4 Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.py inserted finding.resource_tags, assembled by unroll_dict and parse_html_string, into generated reports … Aug 12, 2026
CVE-2026-68760 MEDIUM 5.3 An unauthenticated user may bypass authentication under specific cache conditions. Aug 12, 2026
CVE-2026-68757 HIGH 7.5 A user with access to a valid SAML response may impersonate another user under specific conditions. Aug 12, 2026
CVE-2026-68756 MEDIUM 6.6 A party with write access to stored session data may affect JFrog Artifactory under specific conditions. Aug 12, 2026
CVE-2026-68755 MEDIUM 4.3 A bundle writer may create misleading release promotion information under specific conditions. Aug 12, 2026
CVE-2026-68754 MEDIUM 6.5 A repository publisher without delete permission may modify protected package content under specific conditions. Aug 12, 2026
CVE-2026-68753 MEDIUM 5.3 An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way. Aug 12, 2026
CVE-2026-68752 HIGH 7.2 A Project Resource Manager may gain broader administrative privileges under specific conditions. Aug 12, 2026
CVE-2026-67287 UNKNOWN Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled … Aug 12, 2026
CVE-2026-67286 UNKNOWN Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary … Aug 12, 2026
CVE-2026-66382 MEDIUM 4.3 An authenticated user may write files outside the intended Artifactory work directory under specific conditions. Aug 12, 2026
CVE-2026-66381 MEDIUM 5.3 A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions. Aug 12, 2026
CVE-2026-66380 MEDIUM 4.3 An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions. Aug 12, 2026
CVE-2026-66379 MEDIUM 4.3 An authenticated user may view private Puppet module metadata without repository read access. Aug 12, 2026
CVE-2026-66378 MEDIUM 4.3 An authenticated user without repository read permission may access private NuGet metadata under specific conditions. Aug 12, 2026
CVE-2026-66377 MEDIUM 5.3 An unauthenticated user may access restricted repository information under specific conditions. Aug 12, 2026