Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-66825 — Cross-Site Scripting via Unsafe URL Schemes in Pivotick Property Links

Pivotick contains a cross-site scripting vulnerability in the sidebar property-list component. Values associated with link-like properties, such as url, uri, href, link, website, or homepage, were re…

Remote | Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.5 MEDIUM
CVE-2026-66018 — JFrog Artifactory build environment properties exposure

Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment prope…

artifactory | Remote | Authorization
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.2 HIGH
CVE-2026-66015 — JFrog Platform contains an authorization flaw that may allow authenticated privilege esca…

An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator a…

artifactory | Remote | Authentication
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
8.8 HIGH
CVE-2026-66014 — Potential authentication bypass leading to privilege escalation in Artifactory

JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access …

artifactory | Remote | Authentication
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.5 MEDIUM
CVE-2026-65925 — Server-Side Request Forgery (SSRF) via JFrog Artifactory Cargo remote repository

A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.

artifactory | Remote | Server-Side Request Forgery
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.5 MEDIUM
CVE-2026-65924 — Server-Side Request Forgery (SSRF) via Terraform Remote repository

JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the reposi…

artifactory | Remote | Server-Side Request Forgery
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.8 MEDIUM
CVE-2026-65923 — Potential server-side request forgery in Artifactory Ansible repository handling

A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primari…

artifactory | Remote | Server-Side Request Forgery
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.1 HIGH
CVE-2026-65922 — Potential unauthorized modification of Artifactory internal metadata

An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. S…

artifactory | Remote | Authorization
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
8.8 HIGH
CVE-2026-65921 — Potential path traversal leading to unauthorized file writes

A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.

artifactory | Remote | Path Traversal
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.5 MEDIUM
CVE-2026-65618 — Improper URL validation when handling specific URLs Pub, Terraform and Docker packages mi…

Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cac…

artifactory | Remote | Server-Side Request Forgery
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
8.8 HIGH
CVE-2026-65617 — Potential remote code execution on an Artifactory package service container.

A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.

artifactory | Remote | Misconfiguration
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
8.8 HIGH
CVE-2026-65616 — Potential privilege escalation to JFrog administrator privileges

Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.

artifactory | Remote | Authorization
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
8.3 HIGH
CVE-2026-64649 — Next.js: Server-Side Request Forgery in Server Actions on Custom Servers

Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker…

next.js | Remote | Server-Side Request Forgery
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.0 MEDIUM
CVE-2026-64648 — Next.js: Response Body Cache Confusion for Requests Containing Bodies

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached resp…

next.js | Remote | Information Disclosure
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
5.1 MEDIUM
CVE-2026-59729 — Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for …

Astro is a web framework for content-driven websites. Versions prior to 7.0.6 are vulnerable to XSS through unescaped spread attribute names in renderHTMLElement. The fix for CVE-2026-54298 (GHSA-jrp…

Remote | Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
2.1 LOW
CVE-2026-59727 — Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islan…

Astro is a web framework for content-driven websites. In versions 3.10.0 through 7.0.3, when a transition:persist, transition:scope, or transition:persist-props directive is applied to a client-hydra…

Remote | Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
8.8 HIGH
CVE-2026-56748 — Authenticated RCE via Symlink Following in Cribl Stream Pack Git Import

Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authenticated attacker with Pack import and pipeline preview permissions to execute …

Remote | Path Traversal
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
8.8 HIGH
CVE-2026-56747 — Code Injection in JSON Pointer Processing Component in Cribl Stream

Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker with edit privileges to execute arbitrary JavaScri…

Remote | Injection
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
8.8 HIGH
CVE-2026-42017 — Privilege escalation via JFrog Worker event token exposure

An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions.

artifactory | Remote | Authorization
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
8.1 HIGH
CVE-2026-42016 — Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Es…

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

artifactory | Remote | Authorization
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Showing 20 of 9306 Results