Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

442 CVEs · published 2026-08-12 to 2026-08-12

CVEs (442)

Showing 276–300 of 442

CVE ID Severity Patch CVSS Published Description
CVE-2026-73289 HIGH Patched 8.1 2026-08-12 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: set qualifiers with the negated str…
CVE-2026-73288 NONE Patched — 2026-08-12 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crates/ecstore/src/bucket/object_lock/objectlock_sys.rs …
CVE-2026-73287 MEDIUM Patched 5.4 2026-08-12 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriver::mkd in crates/protocols/src/ftps/driver.rs by ca…
CVE-2026-73286 HIGH Patched 8.1 2026-08-12 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap in…
CVE-2026-73285 HIGH Patched 7.5 2026-08-12 RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTFS_POLICY_PLUGIN_URL in …
CVE-2026-73284 HIGH Patched 8.8 2026-08-12 RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/service_account.rs accepts an attacker-controlled target_…
CVE-2026-73265 MEDIUM Patched 6.5 2026-08-12 RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadPartCopy sources with s3…
CVE-2026-73264 HIGH Patched 7.6 2026-08-12 Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration access could supply an unvalidated base_url for the open…
CVE-2026-73263 CRITICAL Patched 9.9 2026-08-12 Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config…
CVE-2026-73262 MEDIUM Patched 5.4 2026-08-12 Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.py inserted finding.resource_tags, assembled by unro…
CVE-2026-68760 MEDIUM 5.3 2026-08-12 An unauthenticated user may bypass authentication under specific cache conditions.
CVE-2026-68757 HIGH 7.5 2026-08-12 A user with access to a valid SAML response may impersonate another user under specific conditions.
CVE-2026-68756 MEDIUM 6.6 2026-08-12 A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
CVE-2026-68755 MEDIUM 4.3 2026-08-12 A bundle writer may create misleading release promotion information under specific conditions.
CVE-2026-68754 MEDIUM 6.5 2026-08-12 A repository publisher without delete permission may modify protected package content under specific conditions.
CVE-2026-68753 MEDIUM 5.3 2026-08-12 An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.
CVE-2026-68752 HIGH 7.2 2026-08-12 A Project Resource Manager may gain broader administrative privileges under specific conditions.
CVE-2026-67287 NONE &mdash; 2026-08-12 Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled&hellip;
CVE-2026-67286 NONE &mdash; 2026-08-12 Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrar&hellip;
CVE-2026-66382 MEDIUM 4.3 2026-08-12 An authenticated user may write files outside the intended Artifactory work directory under specific conditions.
CVE-2026-66381 MEDIUM 5.3 2026-08-12 A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.
CVE-2026-66380 MEDIUM 4.3 2026-08-12 An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.
CVE-2026-66379 MEDIUM 4.3 2026-08-12 An authenticated user may view private Puppet module metadata without repository read access.
CVE-2026-66378 MEDIUM 4.3 2026-08-12 An authenticated user without repository read permission may access private NuGet metadata under specific conditions.
CVE-2026-66377 MEDIUM 5.3 2026-08-12 An unauthenticated user may access restricted repository information under specific conditions.