Search
442 CVEs · published 2026-08-12 to 2026-08-12
CVEs (442)
Showing 276–300 of 442
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-73289 | HIGH | Patched | 8.1 | 2026-08-12 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: set qualifiers with the negated str… |
| CVE-2026-73288 | NONE | Patched | — | 2026-08-12 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crates/ecstore/src/bucket/object_lock/objectlock_sys.rs … |
| CVE-2026-73287 | MEDIUM | Patched | 5.4 | 2026-08-12 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriver::mkd in crates/protocols/src/ftps/driver.rs by ca… |
| CVE-2026-73286 | HIGH | Patched | 8.1 | 2026-08-12 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap in… |
| CVE-2026-73285 | HIGH | Patched | 7.5 | 2026-08-12 | RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTFS_POLICY_PLUGIN_URL in … |
| CVE-2026-73284 | HIGH | Patched | 8.8 | 2026-08-12 | RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/service_account.rs accepts an attacker-controlled target_… |
| CVE-2026-73265 | MEDIUM | Patched | 6.5 | 2026-08-12 | RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadPartCopy sources with s3… |
| CVE-2026-73264 | HIGH | Patched | 7.6 | 2026-08-12 | Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration access could supply an unvalidated base_url for the open… |
| CVE-2026-73263 | CRITICAL | Patched | 9.9 | 2026-08-12 | Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config… |
| CVE-2026-73262 | MEDIUM | Patched | 5.4 | 2026-08-12 | Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.py inserted finding.resource_tags, assembled by unro… |
| CVE-2026-68760 | MEDIUM | 5.3 | 2026-08-12 | An unauthenticated user may bypass authentication under specific cache conditions. | |
| CVE-2026-68757 | HIGH | 7.5 | 2026-08-12 | A user with access to a valid SAML response may impersonate another user under specific conditions. | |
| CVE-2026-68756 | MEDIUM | 6.6 | 2026-08-12 | A party with write access to stored session data may affect JFrog Artifactory under specific conditions. | |
| CVE-2026-68755 | MEDIUM | 4.3 | 2026-08-12 | A bundle writer may create misleading release promotion information under specific conditions. | |
| CVE-2026-68754 | MEDIUM | 6.5 | 2026-08-12 | A repository publisher without delete permission may modify protected package content under specific conditions. | |
| CVE-2026-68753 | MEDIUM | 5.3 | 2026-08-12 | An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way. | |
| CVE-2026-68752 | HIGH | 7.2 | 2026-08-12 | A Project Resource Manager may gain broader administrative privileges under specific conditions. | |
| CVE-2026-67287 | NONE | — | 2026-08-12 | Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled… | |
| CVE-2026-67286 | NONE | — | 2026-08-12 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrar… | |
| CVE-2026-66382 | MEDIUM | 4.3 | 2026-08-12 | An authenticated user may write files outside the intended Artifactory work directory under specific conditions. | |
| CVE-2026-66381 | MEDIUM | 5.3 | 2026-08-12 | A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions. | |
| CVE-2026-66380 | MEDIUM | 4.3 | 2026-08-12 | An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions. | |
| CVE-2026-66379 | MEDIUM | 4.3 | 2026-08-12 | An authenticated user may view private Puppet module metadata without repository read access. | |
| CVE-2026-66378 | MEDIUM | 4.3 | 2026-08-12 | An authenticated user without repository read permission may access private NuGet metadata under specific conditions. | |
| CVE-2026-66377 | MEDIUM | 5.3 | 2026-08-12 | An unauthenticated user may access restricted repository information under specific conditions. |