Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
38,402 matching · page 200/769Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2026-73287(opens NVD record) | Medium | 5.4 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriver::mkd in crates/protocols/src/ftps/driver.rs by calling storage.create_bucket without authorize_operation for S3Action::CreateBucket, allowing authenticated FTPS users denied s3:CreateBucket to create buckets. This issue is fixed in version 1.0.0-beta.12. | Aug 12, 2026 |
| CVE-2026-73286(opens NVD record) | High | 8.1 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, principaltype, groups, versionid, signatureversion, jwt:, and ldap: condition keys, allowing authenticated callers to satisfy identity-based policy conditions. This issue is fixed in version 1.0.0-beta.12. | Aug 12, 2026 |
| CVE-2026-73285(opens NVD record) | High | 7.5 | RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTFS_POLICY_PLUGIN_URL in crates/iam/src/sys.rs sets PreparedIamAuth.needs_existing_object_tag incorrectly for PreparedIamMode::Opa, causing maybe_merge_object_tag_conditions to omit s3:ExistingObjectTag/* values and allowing authenticated users to bypass tag-based policy restrictions. This issue is fixed in version 1.0.0-rc.1. | Aug 12, 2026 |
| CVE-2026-73284(opens NVD record) | High | 8.8 | RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/service_account.rs accepts an attacker-controlled target_user after only checking CreateServiceAccountAdminAction, passes it to new_service_account, and prepare_service_account_auth sets is_owner for the resulting root-parent service account. This issue is fixed in version 1.0.0-beta.11. | Aug 12, 2026 |
| CVE-2026-73265(opens NVD record) | Medium | 6.5 | RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadPartCopy sources with s3:GetObject instead of s3:GetObjectVersion, allowing principals without historical-version permission to disclose known historical object content. This issue is fixed in version 1.0.0-beta.11. | Aug 12, 2026 |
| CVE-2026-73264(opens NVD record) | High | 7.6 | Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration access could supply an unvalidated base_url for the openai_compatible provider through POST /api/v1/lighthouse/providers and POST /api/v1/lighthouse/providers/{id}/connection, causing api/src/backend/tasks/jobs/lighthouse_providers.py to send outbound requests, including the API key in the Authorization header, to attacker-controlled or internal endpoints when client.models.list was called. This issue is fixed in version 5.33.1. | Aug 12, 2026 |
| CVE-2026-73263(opens NVD record) | Critical | 9.9 | Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args because kubeconfig_contains_exec_auth in api/src/backend/api/v1/serializers.py checked only exec blocks, and POST /api/v1/providers/{id}/connection loaded it through config.load_kube_config_from_dict in prowler/providers/kubernetes/kubernetes_provider.py, causing kubernetes-python CommandTokenSource.token to run the attacker-supplied command through subprocess.Popen on the shared worker. This issue is fixed in version 5.36.0. | Aug 12, 2026 |
| CVE-2026-73262(opens NVD record) | Medium | 5.4 | Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.py inserted finding.resource_tags, assembled by unroll_dict and parse_html_string, into generated reports without HTML escaping, allowing a cloud principal who can modify a scanned resource tag to store HTML or JavaScript that executes when another user opens the report. This issue is fixed in version 5.37.0. | Aug 12, 2026 |
| CVE-2026-68760(opens NVD record) | Medium | 5.3 | An unauthenticated user may bypass authentication under specific cache conditions. | Aug 12, 2026 |
| CVE-2026-68757(opens NVD record) | High | 7.5 | A user with access to a valid SAML response may impersonate another user under specific conditions. | Aug 12, 2026 |
| CVE-2026-68756(opens NVD record) | Medium | 6.6 | A party with write access to stored session data may affect JFrog Artifactory under specific conditions. | Aug 12, 2026 |
| CVE-2026-68755(opens NVD record) | Medium | 4.3 | A bundle writer may create misleading release promotion information under specific conditions. | Aug 12, 2026 |
| CVE-2026-68754(opens NVD record) | Medium | 6.5 | A repository publisher without delete permission may modify protected package content under specific conditions. | Aug 12, 2026 |
| CVE-2026-68753(opens NVD record) | Medium | 5.3 | An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way. | Aug 12, 2026 |
| CVE-2026-68752(opens NVD record) | High | 7.2 | A Project Resource Manager may gain broader administrative privileges under specific conditions. | Aug 12, 2026 |
| CVE-2026-67287(opens NVD record) | Unscored | — | Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input. | Aug 12, 2026 |
| CVE-2026-67286(opens NVD record) | Unscored | — | Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files with a predefined name. | Aug 12, 2026 |
| CVE-2026-66382(opens NVD record) | Medium | 4.3 | An authenticated user may write files outside the intended Artifactory work directory under specific conditions. | Aug 12, 2026 |
| CVE-2026-66381(opens NVD record) | Medium | 5.3 | A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions. | Aug 12, 2026 |
| CVE-2026-66380(opens NVD record) | Medium | 4.3 | An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions. | Aug 12, 2026 |
| CVE-2026-66379(opens NVD record) | Medium | 4.3 | An authenticated user may view private Puppet module metadata without repository read access. | Aug 12, 2026 |
| CVE-2026-66378(opens NVD record) | Medium | 4.3 | An authenticated user without repository read permission may access private NuGet metadata under specific conditions. | Aug 12, 2026 |
| CVE-2026-66377(opens NVD record) | Medium | 5.3 | An unauthenticated user may access restricted repository information under specific conditions. | Aug 12, 2026 |
| CVE-2026-66376(opens NVD record) | Medium | 4.2 | Credentials for a deleted user may remain valid for a short period under specific conditions. | Aug 12, 2026 |
| CVE-2026-66375(opens NVD record) | High | 8.1 | A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions. | Aug 12, 2026 |
| CVE-2026-50561(opens NVD record) | Critical | 9.4 | Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authentication mechanism contains a flaw. In affected versions, the system does not sufficiently validate the identity token in the Authorization header — only performing a validity check. This allows an administrator token generated in another deployment instance or local testing environment to be used to access the backend management interfaces of a different affected instance. An attacker who obtains or constructs an acceptable administrator Authorization token may bypass normal login authentication and gain administrator privileges. This vulnerability could allow an attacker to access system configurations, invoke backend management APIs, create administrator accounts, and ultimately take over the system backend. This issue has been fixed in version 0.6.2. Before upgrading, users are advised to implement the following temporary measures: Set the environment variable `JWT_SECRET_KEY` to a non-default value, and configure a unique, sufficiently strong JWT/authentication key for each deployment instance; and/or avoid exposing backend management interfaces directly to the public network. | Aug 12, 2026 |
| CVE-2026-49349(opens NVD record) | Medium | 6.8 | regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvertently leaked to external servers. A prerequisite for this attack is a malicious registry server, a malicious blob store, or a registry that does not restrict the external URLs for foreign blobs. Version 0.11.5 fixes the issue. | Aug 12, 2026 |
| CVE-2026-49262(opens NVD record) | Low | 3.0 | In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding. A Time-of-Check to Time-of-Use (TOCTOU) race condition exists between the URL validation phase and the actual HTTP request phase, allowing attackers to access internal network resources and cloud metadata endpoints. Version 0.10.4 fixes the issue. | Aug 12, 2026 |
| CVE-2026-47234(opens NVD record) | Medium | 4.4 | Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::setCookie()` logs full cookie values and `Session::start()` logs the current session ID. In a real Admidio deployment this includes both the active session cookie and the persistent auto-login cookie. Anyone with access to the log sink can recover live bearer-style credentials from the logs. Version 5.0.10 contains a fix. | Aug 12, 2026 |
| CVE-2026-47233(opens NVD record) | Medium | 6.5 | Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `case 'item_delete':` in `modules/inventory.php`. The same fix was not applied to the sibling `case 'field_delete':` handler, which destroys an entire inventory field definition, cascading to every `adm_inventory_item_data` row that referenced that field and every `adm_inventory_field_options` entry. The handler validates only a session-bound CSRF token; there is no `isAdministratorInventory()` check at the controller level, and `Admidio\Inventory\Entity\ItemField::delete()` does not enforce one at the entity level either (unlike its sibling `ItemField::save()`, which does check `$gCurrentUser->isAdministrator()`). Any user who can log in to the site can permanently destroy a non-system inventory field by sending one POST. Version 5.0.10 provides an updated fix. | Aug 12, 2026 |
| CVE-2026-18171(opens NVD record) | Unscored | — | Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge grant is added to the sandbox's policy-share allowlist with no access mode. The directory stays writable at its shared-export path, so unprivileged code inside the sandbox can derive that path and write to a host directory the operator attached read-only. | Aug 12, 2026 |
| CVE-2026-14479(opens NVD record) | Medium | 5.5 | A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malicious actor may leverage this vulnerability to cause the NT AUTHORITY\SYSTEM service to terminate unexpectedly, resulting in a denial-of-service condition. | Aug 12, 2026 |
| CVE-2026-14478(opens NVD record) | High | 7.8 | A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability. | Aug 12, 2026 |
| CVE-2025-59324(opens NVD record) | Critical | 9.1 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped. | Aug 12, 2026 |
| CVE-2025-59323(opens NVD record) | High | 8.4 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for code execution in the context of high privilege. | Aug 12, 2026 |
| CVE-2025-59322(opens NVD record) | High | 7.5 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext. | Aug 12, 2026 |
| CVE-2025-59321(opens NVD record) | Critical | 9.8 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform. | Aug 12, 2026 |
| CVE-2025-59320(opens NVD record) | Medium | 4.6 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM. | Aug 12, 2026 |
| CVE-2025-59319(opens NVD record) | High | 7.2 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for code execution in the context of high privilege. | Aug 12, 2026 |
| CVE-2026-67285(opens NVD record) | Unscored | — | Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can perform includes to arbitrary PHP files that are accessible by the system. | Aug 12, 2026 |
| CVE-2026-47232(opens NVD record) | Medium | 4.3 | Admidio is an open-source user management solution. Prior to version 5.0.10, the sensitive `mode=export` action in `modules/sso/keys.php` exports a PKCS#12 bundle containing the configured private key and certificate, but the CSRF validation line is commented out. A forged cross-site POST from an administrator session can therefore trigger private key export without a valid form token. Version 5.0.10 contains a fix. | Aug 12, 2026 |
| CVE-2026-47231(opens NVD record) | High | 8.1 | Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-changing modes by checking that the actor has `hasUploadRight()` on the URL parameter `folder_uuid`. The `move_save` handler then operates on a *separate* URL parameter `file_uuid` and calls `File::moveToFolder($destFolderUUID)`. `File::moveToFolder()` checks the upload right on the destination folder but never on the source folder containing the file. As a result, any user who can upload to any single folder can move any file from any other folder — including private folders to which they have no view rights — into a folder they control, and then download it. Confidentiality is broken (private file contents leak) and integrity is broken (the file is removed from the original location). Version 5.0.10 contains a fix. | Aug 12, 2026 |
| CVE-2026-47230(opens NVD record) | Medium | 6.5 | Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` mode `file_rename_save` shares the same root-cause shape as the cross-folder move bug (`05-documents-cross-folder-move-idor.md`): the top-level rights check at lines 79-89 validates `hasUploadRight()` on the URL parameter `folder_uuid`, but the rename operation acts on `file_uuid` — a separate URL parameter — without re-checking the folder that actually contains the file. `DocumentsService::renameFile()` resolves the target file via `getFileForDownload()` (which permits view-readable files) but does not require upload right on the file's source folder. Result: a user with upload right on any folder A can rename a file in folder B as long as they can view it. They can also overwrite the file's description. Version 5.0.10 contains a fix. | Aug 12, 2026 |
| CVE-2026-47229(opens NVD record) | Medium | 5.4 | Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.php` validates an `adm_csrf_token` on every state-changing branch except `enable`. The `enable` case loads the SAML or OIDC client by UUID, calls `$client->enable($enabled)`, and persists the new state with no token check. Because the action is reachable via plain GET parameters, a third-party page can trick an authenticated administrator into disabling (or silently re-enabling) any configured SAML or OIDC client. Disabling an SSO client breaks every downstream relying-party application that authenticates through it. Version 5.0.10 contains a fix. | Aug 12, 2026 |
| CVE-2026-47228(opens NVD record) | Medium | 5.2 | Admidio is an open-source user management solution. `modules/registration.php` mode `send_login` regenerates a random password for `user_uuid_assigned`, stores its bcrypt hash in `adm_users.usr_password`, and emails the cleartext to that user. Every other state-changing mode in the same file (`assign_member`, `assign_user`, `delete_user`, `create_user`) calls `SecurityUtils::validateCsrfToken($_POST['adm_csrf_token'])` first; the `send_login` branch does not. Prior to version 5.0.10, page visited by a registration-administrator can issue the request as a top-level navigation, the browser sends the admin's `SameSite=Lax` cookies, and the server resets the chosen user's password without any further interaction from the admin. Version 5.0.10 fixes the issue. | Aug 12, 2026 |
| CVE-2026-47227(opens NVD record) | Medium | 6.5 | Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (`ANN`, `EVT`, `ROL`, `USF`, …) corresponds to a module the actor administers. The follow-up "is this specific category editable by me" check at lines 56-61 is dead code because it compares `$getType` (a category-type code) against mode names (`edit`/`save`/`delete`); the condition is permanently false, so `$category->isEditable()` is never invoked. Prior to version 5.0.10, the `delete`, `sequence`, and `save` switch cases load the category by the supplied UUID and act on it without re-checking that the category belongs to a module the actor administers. A user holding only one module-administrator right can therefore destroy or reorder empty categories belonging to *other* modules — for example, an announcements administrator can delete role categories, profile-field categories, or weblink categories that they have no right to touch. Version 5.0.10 fixes the issue. | Aug 12, 2026 |
| CVE-2026-16999(opens NVD record) | Medium | 6.3 | Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows Serialized Data External Linking. This issue affects UYAP Document Editor: from 4.5.17 before 5.4.17. | Aug 12, 2026 |
| CVE-2025-59327(opens NVD record) | High | 7.5 | In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped. | Aug 12, 2026 |
| CVE-2025-59326(opens NVD record) | Critical | 9.8 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file systems, allowing for unsigned code to be executed from these locations. | Aug 12, 2026 |
| CVE-2025-59325(opens NVD record) | High | 7.5 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents, allowing for the offline recovery of secrets and cryptographic details. | Aug 12, 2026 |