Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.3 MEDIUM
CVE-2026-67286 — Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file…

Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files wit…

Remote | Path Traversal
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
4.3 MEDIUM
CVE-2026-66382 — Authenticated users may write files outside the intended Artifactory work directory

An authenticated user may write files outside the intended Artifactory work directory under specific conditions.

artifactory | Remote | Path Traversal
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.3 MEDIUM
CVE-2026-66381 — Repository readers may access content outside configured upstream paths

A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.

artifactory | Remote | Path Traversal
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
4.3 MEDIUM
CVE-2026-66380 — Authenticated users may access private OCI referrer metadata

An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.

artifactory | Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
4.3 MEDIUM
CVE-2026-66379 — Authenticated users may view private Puppet module metadata

An authenticated user may view private Puppet module metadata without repository read access.

artifactory | Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
4.3 MEDIUM
CVE-2026-66378 — Authenticated users may access private NuGet metadata

An authenticated user without repository read permission may access private NuGet metadata under specific conditions.

artifactory | Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.3 MEDIUM
CVE-2026-66377 — Anonymous users may access restricted Artifactory repository information

An unauthenticated user may access restricted repository information under specific conditions.

artifactory | Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
4.2 MEDIUM
CVE-2026-66376 — Deleted users may temporarily retain access to JFrog Artifactory

Credentials for a deleted user may remain valid for a short period under specific conditions.

artifactory | Remote | Authentication
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
8.1 HIGH
CVE-2026-66375 — Low-privilege users may remove protected Artifactory metadata

A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.

artifactory | Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
9.4 CRITICAL
CVE-2026-50561 — Yuxi has a JWT Authentication Bypass Leading to Cross-Instance Administrator Token Reuse

Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authentication mechanism contains a flaw. In affected vers…

Remote | Authentication
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
6.8 MEDIUM
CVE-2026-49349 — regclient may leak authentication credentials to external blob stores

regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvertently leaked to external servers. A prerequisite for this attack is a malicious…

Remote | Information Disclosure
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
3.0 LOW
CVE-2026-49262 — Aimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in …

In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding. A …

Remote | Server-Side Request Forgery
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
4.4 MEDIUM
CVE-2026-47234 — Admidio writes session IDs and auto-login cookie values to application logs

Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::setCookie()` logs full cookie values and `Session::start()` logs the current sess…

| Information Disclosure
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
6.5 MEDIUM
CVE-2026-47233 — Admidio: Any logged-in user can delete inventory fields via `mode=field_delete` — incompl…

Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `case 'item_delete':` in `modules/inventory.php`. The same fix was not applied t…

Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.7 MEDIUM
CVE-2026-18171 — Docker Sandboxes read-only runtime mount writable through its shared-export alias

Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge grant is added to the sandbox's policy-share allowl…

sandboxes | Misconfiguration
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.5 MEDIUM
CVE-2026-14479 — Denial of Service in Autodesk Installer IPC Channel

A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substrin…

installer | Denial of Service
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
7.8 HIGH
CVE-2026-14478 — Incorrect Permission Assignment in Autodesk Installer Named Pipes

A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or …

installer | Injection
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
0.0 NA
CVE-2025-59324 — CryptoPro Secure Disk for Bitlocker LUKS Encryption Validation Bypass

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.

| Cryptography
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
0.0 NA
CVE-2025-59323 — CryptoPro Secure Disk for Bitlocker DataStore Integrity Validation Vulnerability

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details.…

| Cryptography
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
0.0 NA
CVE-2025-59322 — CPSD CryptoPro Secure Disk for BitLocker Improper Access Control Vulnerability

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext.

| Cryptography
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
Showing 20 of 10908 Results