Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.4 MEDIUM
CVE-2026-16694 — IBM i is Affected By Stored Cross-site Scripting for i

IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended …

i i | Remote | Cross-Site Scripting
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
8.4 HIGH
CVE-2026-73325 — Fujitsu OneCompression 1.2.0 Arbitrary Code Execution via torch.load Deserialization

Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as Qu…

| Injection
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
9.9 CRITICAL
CVE-2026-73294 — Semaphore U: OS Command Injection

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option to CmdGitClient.GetLastRem…

Remote | Injection
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
8.8 HIGH
CVE-2026-73293 — Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5, ProjectMiddleware and GetProjectOrGlobalRoleBySlug allow a project manager to u…

Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
8.3 HIGH
CVE-2026-73292 — Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password …

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie…

Remote | Cross-Site Request Forgery
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
4.3 MEDIUM
CVE-2026-70547 — Potential unauthorized metadata exposure in JFrog Artifactory

An authenticated user without repository read permission may access package metadata under specific conditions.

artifactory | Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.9 MEDIUM
CVE-2026-69107 — Potential unauthorized artifact access in JFrog Artifactory

An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.

artifactory | Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
8.1 HIGH
CVE-2026-69105 — Potential package cache integrity issue in JFrog Artifactory

An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.

artifactory | Remote | Supply Chain
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
0.0 NA
CVE-2026-68971 — Apache Airflow: Cross-team authorization bypass in the asset materialization and dag-run …

Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, u…

airflow | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
0.0 NA
CVE-2026-68970 — Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rend…

Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Mask…

airflow | Information Disclosure
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
0.0 NA
CVE-2026-68969 — Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audit …

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/co…

airflow | Information Disclosure
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
0.0 NA
CVE-2026-68968 — Apache Airflow: Authorization bypass in the Backfill API through conflicting interpretati…

Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()`…

airflow | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
7.2 HIGH
CVE-2026-68759 — Integration credential holders may impersonate users in JFrog Access

A holder of a valid integration credential may impersonate other users under specific conditions.

artifactory | Remote | Authentication
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
6.5 MEDIUM
CVE-2026-68758 — Authenticated users may access restricted Artifactory support information

A low-privileged authenticated user may access restricted support information under specific conditions.

artifactory | Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
0.0 NA
CVE-2026-68076 — Apache Airflow: Connections test API: team-scope guard bypass resolves another team's env…

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was suppli…

airflow | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
0.0 NA
CVE-2026-67587 — Apache Airflow: DAG-author remote code execution on the Scheduler via a Serde `Callback` …

Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself …

airflow | Injection
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
7.3 HIGH
CVE-2026-67260 — Apache Airflow: DAG-author remote code execution on the Scheduler via awaiting_input next…

Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an…

airflow | Remote | Injection
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.3 MEDIUM
CVE-2026-66384 — Authenticated users may write data outside the intended Docker cache path

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

artifactory | Remote | Path Traversal
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
6.7 MEDIUM
CVE-2026-66016 — Rendered Artifactory Helm manifests may contain generated TLS private keys

Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.

artifactory | Information Disclosure
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
8.8 HIGH
CVE-2026-65941 — WhatsUp Gold versions prior to 26.0.2 contain an unauthenticated remote code execution vu…

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application serv…

whatsup_gold | Authentication
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
Showing 20 of 10962 Results