Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-67260 — Apache Airflow: DAG-author remote code execution on the Scheduler via awaiting_input next…

Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an…

airflow | Injection
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
0.0 NA
CVE-2026-67587 — Apache Airflow: DAG-author remote code execution on the Scheduler via a Serde `Callback` …

Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself …

airflow | Injection
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
0.0 NA
CVE-2026-64639 — Plesk Database Cloning Arbitrary Code Execution Vulnerability

Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server ad…

| Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
0.0 NA
CVE-2026-65017 — Apache Airflow: Config API: team-scoped Celery broker secret disclosed to a Viewer (multi…

Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authent…

airflow | Information Disclosure
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
0.0 NA
CVE-2026-68968 — Apache Airflow: Authorization bypass in the Backfill API through conflicting interpretati…

Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()`…

airflow | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
0.0 NA
CVE-2026-68969 — Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audit …

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/co…

airflow | Information Disclosure
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
0.0 NA
CVE-2026-68970 — Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rend…

Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Mask…

airflow | Information Disclosure
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
0.0 NA
CVE-2026-68971 — Apache Airflow: Cross-team authorization bypass in the asset materialization and dag-run …

Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, u…

airflow | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
8.8 HIGH
CVE-2026-65941 — WhatsUp Gold versions prior to 26.0.2 contain an unauthenticated remote code execution vu…

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application serv…

whatsup_gold | Authentication
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
6.8 MEDIUM
CVE-2026-65940 — WhatsUp Gold versions prior to 26.0.2 excessive file system permissions allows a privileg…

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.

whatsup_gold | Path Traversal
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
0.0 NA
CVE-2026-68076 — Apache Airflow: Connections test API: team-scope guard bypass resolves another team's env…

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was suppli…

airflow | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
6.8 MEDIUM
CVE-2026-65939 — WhatsUp Gold versions prior to 26.0.2 contain an arbitrary file write vulnerability in th…

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.

whatsup_gold | Misconfiguration
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
4.3 MEDIUM
CVE-2026-65938 — WhatsUp Gold versions prior to 26.0.2 contain an improper authorization vulnerability in …

In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.

whatsup_gold | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
8.0 HIGH
CVE-2026-65937 — WhatsUp Gold versions prior to 26.0.2 contain multiple stored cross-site scripting (XSS) …

In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content.

whatsup_gold | Cross-Site Scripting
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
8.1 HIGH
CVE-2026-69105 — Potential package cache integrity issue in JFrog Artifactory

An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.

artifactory | Remote | Supply Chain
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.1 MEDIUM
CVE-2026-73432 — Stored Server-Side Request Forgery in Remote-Instance Synchronization Allows Access to In…

Vulnerability-Lookup contains a server-side request forgery (SSRF) vulnerability in the remote-instance synchronization functionality. Remote instance addresses were validated only for basic URL synt…

Remote | Server-Side Request Forgery
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
8.8 HIGH
CVE-2026-73431 — Reusable Account Activation and Recovery Tokens Allow Repeated Account Takeover in vulner…

Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Activation and recovery links were generated using stateless signed tokens conta…

Remote | Authentication
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.3 MEDIUM
CVE-2026-73405 — Authorization Bypass in SSE Pub/Sub Allows Unconfirmed Accounts to Access Stream Events i…

An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to Server-Sent Events (SSE) streams through the /pubsub/subscribe/<topic> endpoint.…

Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
6.1 MEDIUM
CVE-2026-73374 — Stored Cross-Site Scripting (XSS) via Unescaped CNA Reference Tags in vulnerability-lookup

A stored cross-site scripting (XSS) vulnerability existed in Vulnerability-Lookup in the render_tag_badges Jinja filter used to display reference tags associated with vulnerability records. Values f…

Remote | Cross-Site Scripting
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
7.1 HIGH
CVE-2026-73291 — Seerr: Path traversal to RCE via /avatarproxy image cache filename from upstream ETag

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream ETag and Content-Typ…

| Path Traversal
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
Showing 20 of 10908 Results