Live feed

CVE Feed

Last 30 days — 13,777 matching across all industries.

Showing 40

Auto-refreshupdated 5s ago
CVE-2026-73288
NONE

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crates/ecstore/src/bucket/object_lock/objectlock_sys.rs lets check_object_lock_for_deletion, delete_prefix, and lifecycle and scanner sweeps treat ConfigNotFound, unreadable .metadata.bin data, or unparseable metadata as no lock configuration, allowing objects under COMPLIANCE retention to be deleted or expired. This issue is fixed in version 1.0.0-rc.1.

29d ago
CVE-2026-73287
MEDIUM· 5.4

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriver::mkd in crates/protocols/src/ftps/driver.rs by calling storage.create_bucket without authorize_operation for S3Action::CreateBucket, allowing authenticated FTPS users denied s3:CreateBucket to create buckets. This issue is fixed in version 1.0.0-beta.12.

29d ago
CVE-2026-73286
HIGH· 8.1

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, principaltype, groups, versionid, signatureversion, jwt:, and ldap: condition keys, allowing authenticated callers to satisfy identity-based policy conditions. This issue is fixed in version 1.0.0-beta.12.

29d ago
CVE-2026-73285
HIGH· 7.5

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTFS_POLICY_PLUGIN_URL in crates/iam/src/sys.rs sets PreparedIamAuth.needs_existing_object_tag incorrectly for PreparedIamMode::Opa, causing maybe_merge_object_tag_conditions to omit s3:ExistingObjectTag/* values and allowing authenticated users to bypass tag-based policy restrictions. This issue is fixed in version 1.0.0-rc.1.

29d ago
CVE-2026-73284
HIGH· 8.8

RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/service_account.rs accepts an attacker-controlled target_user after only checking CreateServiceAccountAdminAction, passes it to new_service_account, and prepare_service_account_auth sets is_owner for the resulting root-parent service account. This issue is fixed in version 1.0.0-beta.11.

29d ago
CVE-2026-73265
MEDIUM· 6.5

RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadPartCopy sources with s3:GetObject instead of s3:GetObjectVersion, allowing principals without historical-version permission to disclose known historical object content. This issue is fixed in version 1.0.0-beta.11.

29d ago
CVE-2026-73264
HIGH· 7.6

Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration access could supply an unvalidated base_url for the openai_compatible provider through POST /api/v1/lighthouse/providers and POST /api/v1/lighthouse/providers/{id}/connection, causing api/src/backend/tasks/jobs/lighthouse_providers.py to send outbound requests, including the API key in the Authorization header, to attacker-controlled or internal endpoints when client.models.list was called. This issue is fixed in version 5.33.1.

29d ago
CVE-2026-73263
CRITICAL· 9.9

Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args because kubeconfig_contains_exec_auth in api/src/backend/api/v1/serializers.py checked only exec blocks, and POST /api/v1/providers/{id}/connection loaded it through config.load_kube_config_from_dict in prowler/providers/kubernetes/kubernetes_provider.py, causing kubernetes-python CommandTokenSource.token to run the attacker-supplied command through subprocess.Popen on the shared worker. This issue is fixed in version 5.36.0.

29d ago
CVE-2026-73262
MEDIUM· 5.4

Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.py inserted finding.resource_tags, assembled by unroll_dict and parse_html_string, into generated reports without HTML escaping, allowing a cloud principal who can modify a scanned resource tag to store HTML or JavaScript that executes when another user opens the report. This issue is fixed in version 5.37.0.

29d ago
CVE-2026-68760
MEDIUM· 5.3

An unauthenticated user may bypass authentication under specific cache conditions.

jfrog
29d ago
CVE-2026-68757
HIGH· 7.5

A user with access to a valid SAML response may impersonate another user under specific conditions.

jfrog
29d ago
CVE-2026-68756
MEDIUM· 6.6

A party with write access to stored session data may affect JFrog Artifactory under specific conditions.

jfrog
29d ago
CVE-2026-68755
MEDIUM· 4.3

A bundle writer may create misleading release promotion information under specific conditions.

jfrog
29d ago
CVE-2026-68754
MEDIUM· 6.5

A repository publisher without delete permission may modify protected package content under specific conditions.

jfrog
29d ago
CVE-2026-68753
MEDIUM· 5.3

An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.

jfrog
29d ago
CVE-2026-68752
HIGH· 7.2

A Project Resource Manager may gain broader administrative privileges under specific conditions.

jfrog
29d ago
CVE-2026-67287
NONE

Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input.

29d ago
CVE-2026-67286
NONE

Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files with a predefined name.

29d ago
CVE-2026-66382
MEDIUM· 4.3

An authenticated user may write files outside the intended Artifactory work directory under specific conditions.

jfrog
29d ago
CVE-2026-66381
MEDIUM· 5.3

A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.

jfrog
29d ago
CVE-2026-66380
MEDIUM· 4.3

An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.

jfrog
29d ago
CVE-2026-66379
MEDIUM· 4.3

An authenticated user may view private Puppet module metadata without repository read access.

jfrog
29d ago
CVE-2026-66378
MEDIUM· 4.3

An authenticated user without repository read permission may access private NuGet metadata under specific conditions.

jfrog
29d ago
CVE-2026-66377
MEDIUM· 5.3

An unauthenticated user may access restricted repository information under specific conditions.

jfrog
29d ago
CVE-2026-66376
MEDIUM· 4.2

Credentials for a deleted user may remain valid for a short period under specific conditions.

jfrog
29d ago
CVE-2026-66375
HIGH· 8.1

A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.

jfrog
29d ago
CVE-2026-50561
CRITICAL· 9.4

Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authentication mechanism contains a flaw. In affected versions, the system does not sufficiently validate the identity token in the Authorization header — only performing a validity check. This allows an administrator token generated in another deployment instance or local testing environment to be used to access the backend management interfaces of a different affected instance. An attacker who obtains or constructs an acceptable administrator Authorization token may bypass normal login authentication and gain administrator privileges. This vulnerability could allow an attacker to access system configurations, invoke backend management APIs, create administrator accounts, and ultimately take over the system backend. This issue has been fixed in version 0.6.2. Before upgrading, users are advised to implement the following temporary measures: Set the environment variable `JWT_SECRET_KEY` to a non-default value, and configure a unique, sufficiently strong JWT/authentication key for each deployment instance; and/or avoid exposing backend management interfaces directly to the public network.

29d ago
CVE-2026-49349
MEDIUM· 6.8

regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvertently leaked to external servers. A prerequisite for this attack is a malicious registry server, a malicious blob store, or a registry that does not restrict the external URLs for foreign blobs. Version 0.11.5 fixes the issue.

29d ago
CVE-2026-49262
LOW· 3.0

In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding. A Time-of-Check to Time-of-Use (TOCTOU) race condition exists between the URL validation phase and the actual HTTP request phase, allowing attackers to access internal network resources and cloud metadata endpoints. Version 0.10.4 fixes the issue.

29d ago
CVE-2026-47234
MEDIUM· 4.4

Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::setCookie()` logs full cookie values and `Session::start()` logs the current session ID. In a real Admidio deployment this includes both the active session cookie and the persistent auto-login cookie. Anyone with access to the log sink can recover live bearer-style credentials from the logs. Version 5.0.10 contains a fix.

29d ago
CVE-2026-47233
MEDIUM· 6.5

Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `case 'item_delete':` in `modules/inventory.php`. The same fix was not applied to the sibling `case 'field_delete':` handler, which destroys an entire inventory field definition, cascading to every `adm_inventory_item_data` row that referenced that field and every `adm_inventory_field_options` entry. The handler validates only a session-bound CSRF token; there is no `isAdministratorInventory()` check at the controller level, and `Admidio\Inventory\Entity\ItemField::delete()` does not enforce one at the entity level either (unlike its sibling `ItemField::save()`, which does check `$gCurrentUser->isAdministrator()`). Any user who can log in to the site can permanently destroy a non-system inventory field by sending one POST. Version 5.0.10 provides an updated fix.

29d ago
CVE-2026-18171
NONE

Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge grant is added to the sandbox's policy-share allowlist with no access mode. The directory stays writable at its shared-export path, so unprivileged code inside the sandbox can derive that path and write to a host directory the operator attached read-only.

29d ago
CVE-2026-14479
MEDIUM· 5.5

A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malicious actor may leverage this vulnerability to cause the NT AUTHORITY\SYSTEM service to terminate unexpectedly, resulting in a denial-of-service condition.

autodesk
29d ago
CVE-2026-14478
HIGH· 7.8

A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability.

autodesk
29d ago
CVE-2025-59324
CRITICAL· 9.1

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.

29d ago
CVE-2025-59323
HIGH· 8.4

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for code execution in the context of high privilege.

29d ago
CVE-2025-59322
HIGH· 7.5

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext.

29d ago
CVE-2025-59321
CRITICAL· 9.8

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform.

29d ago
CVE-2025-59320
MEDIUM· 4.6

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM.

29d ago
CVE-2025-59319
HIGH· 7.2

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for code execution in the context of high privilege.

29d ago
Feedback

How was this page?

Spotted something off, or have an idea? Let us know.

0/1000