Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-68968 |
|
Vulnerability in apache (CVE-2026-68968)
vulnerability in apache (CVE-2026-68968). Confidential information can be exposed externally. Exploitable via ``backfill_id``.
|
| CVE-2026-68970 |
|
Vulnerability in apache (CVE-2026-68970)
vulnerability in apache (CVE-2026-68970). Confidential information can be exposed externally.
|
| CVE-2026-68759 |
|
A holder of a valid integration credential may impersonate other users under specific conditions.
A holder of a valid integration credential may impersonate other users under specific conditions.
|
| CVE-2026-68758 |
|
Vulnerability in jfrog (CVE-2026-68758)
vulnerability in jfrog (CVE-2026-68758). Confidential information can be exposed externally.
|
| CVE-2026-67587 |
|
Unsafe Deserialization in apache (CVE-2026-67587)
vulnerability in apache (CVE-2026-67587). Successful exploitation can lead to full system takeover. Exploitable via ``Callback``.
|
| CVE-2026-67260 |
|
Unsafe Deserialization in apache (CVE-2026-67260)
vulnerability in apache (CVE-2026-67260). Risk of unauthorized operations or information disclosure. Exploitable via ``awaiting_input``.
|
| CVE-2026-66384 KEV |
|
[KEV] Path Traversal in Jfrog artifactory (CVE-2026-66384)
path traversal in Jfrog artifactory (CVE-2026-66384). Data can be tampered with by attackers. Listed in CISA KEV — actively exploited.
|
| CVE-2026-66016 |
|
Vulnerability in CVE-2026-66016 (CVE-2026-66016)
vulnerability in CVE-2026-66016 (CVE-2026-66016). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65941 |
|
Vulnerability in progress (CVE-2026-65941)
vulnerability in progress (CVE-2026-65941). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65940 |
|
Vulnerability in progress (CVE-2026-65940)
vulnerability in progress (CVE-2026-65940). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65926 |
|
Vulnerability in CVE-2026-65926 (CVE-2026-65926)
vulnerability in CVE-2026-65926 (CVE-2026-65926). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65938 |
|
Vulnerability in progress (CVE-2026-65938)
vulnerability in progress (CVE-2026-65938). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65939 |
|
Path Traversal in progress (CVE-2026-65939)
path traversal in progress (CVE-2026-65939). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65937 |
|
Cross-Site Scripting (XSS) in progress (CVE-2026-65937)
cross-site scripting in progress (CVE-2026-65937). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65017 |
|
Information Disclosure in apache (CVE-2026-65017)
vulnerability in apache (CVE-2026-65017). Confidential information can be exposed externally.
|
| CVE-2026-59244 |
|
Vulnerability in apache (CVE-2026-59244)
vulnerability in apache (CVE-2026-59244). Confidential information can be exposed externally.
|
| CVE-2026-59242 |
|
Unsafe Deserialization in apache (CVE-2026-59242)
vulnerability in apache (CVE-2026-59242). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v2/{...}/xcomEntries/{key}`.
|
| CVE-2026-58076 |
|
Unsafe Deserialization in apache (CVE-2026-58076)
vulnerability in apache (CVE-2026-58076). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v2/dags/{dag_id}/details`.
|
| CVE-2026-54183 |
|
Information Disclosure in apache (CVE-2026-54183)
vulnerability in apache (CVE-2026-54183). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19548 |
|
Use-After-Free in c (CVE-2026-19548)
vulnerability in c (CVE-2026-19548). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15803 |
|
XXE (XML External Entity) in CVE-2026-15803 (CVE-2026-15803)
vulnerability in CVE-2026-15803 (CVE-2026-15803). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73374 |
|
Cross-Site Scripting (XSS) in CVE-2026-73374 (CVE-2026-73374)
cross-site scripting in CVE-2026-73374 (CVE-2026-73374). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73431 |
|
Vulnerability in CVE-2026-73431 (CVE-2026-73431)
vulnerability in CVE-2026-73431 (CVE-2026-73431). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73405 |
|
Vulnerability in CVE-2026-73405 (CVE-2026-73405)
vulnerability in CVE-2026-73405 (CVE-2026-73405). Risk of unauthorized operations or information disclosure. Exploitable via `X-API-Key header`.
|
| CVE-2026-73432 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-73432)
SSRF in ssrf (CVE-2026-73432). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68755 |
|
A bundle writer may create misleading release promotion information under specific conditions.
A bundle writer may create misleading release promotion information under specific conditions.
|
| CVE-2026-68756 |
|
Unsafe Deserialization in jfrog (CVE-2026-68756)
vulnerability in jfrog (CVE-2026-68756). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68760 |
|
An unauthenticated user may bypass authentication under specific cache conditions.
An unauthenticated user may bypass authentication under specific cache conditions.
|
| CVE-2026-68757 |
|
A user with access to a valid SAML response may impersonate another user under specific conditions.
A user with access to a valid SAML response may impersonate another user under specific conditions.
|
| CVE-2026-68752 |
|
A Project Resource Manager may gain broader administrative privileges under specific conditions.
A Project Resource Manager may gain broader administrative privileges under specific conditions.
|
| CVE-2026-68753 |
|
Vulnerability in jfrog (CVE-2026-68753)
vulnerability in jfrog (CVE-2026-68753). Confidential information can be exposed externally.
|
| CVE-2026-68754 |
|
Vulnerability in jfrog (CVE-2026-68754)
vulnerability in jfrog (CVE-2026-68754). Data can be tampered with by attackers.
|
| CVE-2026-66379 |
|
An authenticated user may view private Puppet module metadata without repository read access.
An authenticated user may view private Puppet module metadata without repository read access.
|
| CVE-2026-66380 |
|
Vulnerability in jfrog (CVE-2026-66380)
vulnerability in jfrog (CVE-2026-66380). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67286 |
|
Path Traversal in CVE-2026-67286 (CVE-2026-67286)
path traversal in CVE-2026-67286 (CVE-2026-67286). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66381 |
|
Path Traversal in jfrog (CVE-2026-66381)
path traversal in jfrog (CVE-2026-66381). Confidential information can be exposed externally.
|
| CVE-2026-66382 |
|
Path Traversal in jfrog (CVE-2026-66382)
path traversal in jfrog (CVE-2026-66382). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67287 |
|
Vulnerability in CVE-2026-67287 (CVE-2026-67287)
vulnerability in CVE-2026-67287 (CVE-2026-67287). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66375 |
|
Vulnerability in jfrog (CVE-2026-66375)
vulnerability in jfrog (CVE-2026-66375). Data can be tampered with by attackers.
|
| CVE-2026-66378 |
|
Vulnerability in jfrog (CVE-2026-66378)
vulnerability in jfrog (CVE-2026-66378). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66377 |
|
An unauthenticated user may access restricted repository information under specific conditions.
An unauthenticated user may access restricted repository information under specific conditions.
|
| CVE-2026-18171 |
|
Authorization Flaw in CVE-2026-18171 (CVE-2026-18171)
vulnerability in CVE-2026-18171 (CVE-2026-18171). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-59324 |
|
Vulnerability in CVE-2025-59324 (CVE-2025-59324)
vulnerability in CVE-2025-59324 (CVE-2025-59324). Confidential information can be exposed externally.
|
| CVE-2026-14478 |
|
Vulnerability in CVE-2026-14478 (CVE-2026-14478)
vulnerability in CVE-2026-14478 (CVE-2026-14478). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14479 |
|
Vulnerability in CVE-2026-14479 (CVE-2026-14479)
vulnerability in CVE-2026-14479 (CVE-2026-14479). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-59319 |
|
Vulnerability in CVE-2025-59319 (CVE-2025-59319)
vulnerability in CVE-2025-59319 (CVE-2025-59319). Successful exploitation can lead to full system takeover.
|
| CVE-2025-59321 |
|
Vulnerability in CVE-2025-59321 (CVE-2025-59321)
vulnerability in CVE-2025-59321 (CVE-2025-59321). Successful exploitation can lead to full system takeover.
|
| CVE-2025-59322 |
|
Vulnerability in CVE-2025-59322 (CVE-2025-59322)
vulnerability in CVE-2025-59322 (CVE-2025-59322). Confidential information can be exposed externally.
|
| CVE-2026-52776 |
|
Vulnerability in compliance-trestle (CVE-2026-52776)
vulnerability in compliance-trestle (CVE-2026-52776). Risk of unauthorized operations or information disclosure. Exploitable via ``URLSecurityValidator``. Mitigation: upgrade to `4.1.0` or later.
|
| CVE-2026-48798 |
|
Path Traversal in SSH.NET (CVE-2026-48798)
path traversal in SSH.NET (CVE-2026-48798). Data can be tampered with by attackers. Exploitable via ``ScpException``. Mitigation: upgrade to `2026.0.0` or later.
|