Search
442 CVEs · published 2026-08-12 to 2026-08-12
CVEs (442)
Showing 226–250 of 442
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-73294 | CRITICAL | Patched | 9.9 | 2026-08-12 | Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option… |
| CVE-2026-73293 | HIGH | Patched | 8.8 | 2026-08-12 | Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5, ProjectMiddleware and GetProjectOrGlobalRoleBySlug a… |
| CVE-2026-73292 | HIGH | Patched | 8.3 | 2026-08-12 | Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user… |
| CVE-2026-70547 | MEDIUM | 4.3 | 2026-08-12 | An authenticated user without repository read permission may access package metadata under specific conditions. | |
| CVE-2026-69107 | MEDIUM | 5.9 | 2026-08-12 | An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions. | |
| CVE-2026-69105 | HIGH | 8.1 | 2026-08-12 | An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability. | |
| CVE-2026-68971 | MEDIUM | Patched | 6.5 | 2026-08-12 | Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the tar… |
| CVE-2026-68970 | MEDIUM | Patched | 6.5 | 2026-08-12 | Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the … |
| CVE-2026-68969 | MEDIUM | Patched | 6.5 | 2026-08-12 | Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/varia… |
| CVE-2026-68968 | HIGH | Patched | 7.5 | 2026-08-12 | Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization depend… |
| CVE-2026-68759 | HIGH | 7.2 | 2026-08-12 | A holder of a valid integration credential may impersonate other users under specific conditions. | |
| CVE-2026-68758 | MEDIUM | 6.5 | 2026-08-12 | A low-privileged authenticated user may access restricted support information under specific conditions. | |
| CVE-2026-68076 | MEDIUM | Patched | 5.4 | 2026-08-12 | Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran wh… |
| CVE-2026-67587 | HIGH | Patched | 8.8 | 2026-08-12 | Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Becaus… |
| CVE-2026-67260 | HIGH | Patched | 7.3 | 2026-08-12 | Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance… |
| CVE-2026-66384 | MEDIUM | 5.3 | 2026-08-12 | An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. | |
| CVE-2026-66016 | MEDIUM | 6.7 | 2026-08-12 | Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users. | |
| CVE-2026-65941 | HIGH | Patched | 8.8 | 2026-08-12 | In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context … |
| CVE-2026-65940 | MEDIUM | Patched | 6.8 | 2026-08-12 | In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server. |
| CVE-2026-65939 | MEDIUM | Patched | 6.8 | 2026-08-12 | In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root. |
| CVE-2026-65938 | MEDIUM | Patched | 4.3 | 2026-08-12 | In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions. |
| CVE-2026-65937 | HIGH | Patched | 8.0 | 2026-08-12 | In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content. |
| CVE-2026-65926 | LOW | 3.1 | 2026-08-12 | An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known. | |
| CVE-2026-65017 | MEDIUM | Patched | 6.5 | 2026-08-12 | Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed… |
| CVE-2026-64639 | NONE | Patched | — | 2026-08-12 | Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behal… |