| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-18098 | Hig | 0.53 | 8.1 | 0.00 | Aug 12, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and compromise system integrity due to an XML injection flaw. | ||
| CVE-2026-17095 | Hig | 0.54 | 8.3 | 0.01 | Aug 12, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to unsafe reflection. | ||
| CVE-2026-17094 | Med | 0.28 | 4.3 | 0.01 | Aug 12, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate files due to a path traversal vulnerability. | ||
| CVE-2026-16694 | Med | 0.42 | 6.4 | 0.00 | Aug 12, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted… | ||
| CVE-2026-73325 | Hig | 0.51 | 7.8 | 0.00 | Aug 12, 2026 | Fujitsu Research's OneCompression library before 1.2.1 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unconditionally calls… | ||
| CVE-2026-73294 | Cri | 0.57 | 9.9 | 0.01 | Aug 12, 2026 | Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option to CmdGitClient.GetLastRemoteCommitHash through POST /api/project/{id}/repositories and scheduled… | ||
| CVE-2026-73293 | Hig | 0.50 | 8.8 | 0.01 | Aug 12, 2026 | Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5, ProjectMiddleware and GetProjectOrGlobalRoleBySlug allow a project manager to use POST /api/project/{id}/roles to create a custom manager role with permission… | ||
| CVE-2026-73292 | Hig | 0.47 | 8.3 | 0.00 | Aug 12, 2026 | Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-password confirmation, allowing an… | ||
| CVE-2026-70547 | Med | 0.28 | 4.3 | 0.00 | Aug 12, 2026 | An authenticated user without repository read permission may access package metadata under specific conditions. | ||
| CVE-2026-69107 | Med | 0.38 | 5.9 | 0.00 | Aug 12, 2026 | An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions. | ||
| CVE-2026-69105 | Hig | 0.53 | 8.1 | 0.00 | Aug 12, 2026 | An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability. | ||
| CVE-2026-68971 | Med | 0.35 | 6.5 | 0.00 | Aug 12, 2026 | Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization site. A team-aware auth manager distinguishes a… | ||
| CVE-2026-68970 | Med | 0.35 | 6.5 | 0.00 | Aug 12, 2026 | Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string or a dict; a list… | ||
| CVE-2026-68969 | Med | 0.35 | 6.5 | 0.00 | Aug 12, 2026 | Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only top-level request fields, and… | ||
| CVE-2026-68968 | Hig | 0.42 | 7.5 | 0.00 | Aug 12, 2026 | Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegativeInt`, which accepts… | ||
| CVE-2026-68759 | Hig | 0.47 | 7.2 | 0.00 | Aug 12, 2026 | A holder of a valid integration credential may impersonate other users under specific conditions. | ||
| CVE-2026-68758 | Med | 0.42 | 6.5 | 0.00 | Aug 12, 2026 | A low-privileged authenticated user may access restricted support information under specific conditions. | ||
| CVE-2026-68076 | Med | 0.28 | 5.4 | 0.00 | Aug 12, 2026 | Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was supplied, and its pattern could not match a team name containing an underscore, which… | ||
| CVE-2026-67587 | Hig | 0.50 | 8.8 | 0.01 | Aug 12, 2026 | Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserialization_classes`… | ||
| CVE-2026-67260 | Hig | 0.41 | 7.3 | 0.01 | Aug 12, 2026 | Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task… | ||
| CVE-2026-66384 | Med | 0.46 | 5.3 | 0.01 | KEV | Aug 12, 2026 | An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. | |
| CVE-2026-66016 | Med | 0.44 | 6.7 | 0.00 | Aug 12, 2026 | Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users. | ||
| CVE-2026-65941 | Hig | 0.57 | 8.8 | 0.01 | Aug 12, 2026 | In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account. | ||
| CVE-2026-65940 | Med | 0.44 | 6.8 | 0.00 | Aug 12, 2026 | In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server. | ||
| CVE-2026-65939 | Med | 0.44 | 6.8 | 0.00 | Aug 12, 2026 | In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root. | ||
| CVE-2026-65938 | Med | 0.28 | 4.3 | 0.00 | Aug 12, 2026 | In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions. | ||
| CVE-2026-65937 | Hig | 0.52 | 8.0 | 0.00 | Aug 12, 2026 | In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content. | ||
| CVE-2026-65926 | Low | 0.20 | 3.1 | 0.00 | Aug 12, 2026 | An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known. | ||
| CVE-2026-65017 | Med | 0.35 | 6.5 | 0.00 | Aug 12, 2026 | Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authenticated Viewer holding only configuration-read access — with no prior access to… | ||
| CVE-2026-64639 | Cri | 0.60 | — | 0.01 | Aug 12, 2026 | Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator. | ||
| CVE-2026-59244 | Med | 0.35 | 6.5 | 0.00 | Aug 12, 2026 | Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` was displayed in… | ||
| CVE-2026-59242 | Med | 0.28 | 5.4 | 0.01 | Aug 12, 2026 | Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user with XCom write-and-read access to… | ||
| CVE-2026-58076 | Hig | 0.50 | 8.8 | 0.00 | Aug 12, 2026 | Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config`… | ||
| CVE-2026-54183 | Med | 0.21 | 4.3 | 0.00 | Aug 12, 2026 | Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into values nested inside a list, tuple, or set beyond that limit, so an Airflow Variable holding such a… | ||
| CVE-2026-19548 | Med | 0.36 | 5.5 | 0.00 | Aug 12, 2026 | Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when… | ||
| CVE-2026-15803 | Hig | 0.57 | — | 0.00 | Aug 12, 2026 | In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-based RDF data or query results, permitting DOCTYPE declarations, external entity references, and external DTD loading. This is due to an… | ||
| CVE-2025-35988 | — | 0.00 | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2025-35977 | — | 0.00 | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2025-32737 | — | 0.00 | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2025-32087 | — | 0.00 | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2025-32084 | — | 0.00 | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2025-31943 | — | 0.00 | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2025-30178 | — | 0.00 | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2025-27570 | — | 0.00 | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2025-27245 | — | 0.00 | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2025-25275 | — | 0.00 | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2025-24837 | — | 0.00 | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2025-24488 | — | 0.00 | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2025-20020 | — | 0.00 | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2026-18725 | mod | 0.41 | 6.3 | — | Aug 12, 2026 | open-iscsi: open-iscsi: Out-of-bounds access in iscsiuio ICMPv6 echo handling |
- risk 0.53cvss 8.1epss 0.00
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and compromise system integrity due to an XML injection flaw.
- risk 0.54cvss 8.3epss 0.01
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to unsafe reflection.
- risk 0.28cvss 4.3epss 0.01
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate files due to a path traversal vulnerability.
- risk 0.42cvss 6.4epss 0.00
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…
- risk 0.51cvss 7.8epss 0.00
Fujitsu Research's OneCompression library before 1.2.1 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unconditionally calls…
- risk 0.57cvss 9.9epss 0.01
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option to CmdGitClient.GetLastRemoteCommitHash through POST /api/project/{id}/repositories and scheduled…
- risk 0.50cvss 8.8epss 0.01
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5, ProjectMiddleware and GetProjectOrGlobalRoleBySlug allow a project manager to use POST /api/project/{id}/roles to create a custom manager role with permission…
- risk 0.47cvss 8.3epss 0.00
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-password confirmation, allowing an…
- risk 0.28cvss 4.3epss 0.00
An authenticated user without repository read permission may access package metadata under specific conditions.
- risk 0.38cvss 5.9epss 0.00
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
- risk 0.53cvss 8.1epss 0.00
An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.
- risk 0.35cvss 6.5epss 0.00
Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization site. A team-aware auth manager distinguishes a…
- risk 0.35cvss 6.5epss 0.00
Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string or a dict; a list…
- risk 0.35cvss 6.5epss 0.00
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only top-level request fields, and…
- risk 0.42cvss 7.5epss 0.00
Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegativeInt`, which accepts…
- risk 0.47cvss 7.2epss 0.00
A holder of a valid integration credential may impersonate other users under specific conditions.
- risk 0.42cvss 6.5epss 0.00
A low-privileged authenticated user may access restricted support information under specific conditions.
- risk 0.28cvss 5.4epss 0.00
Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was supplied, and its pattern could not match a team name containing an underscore, which…
- risk 0.50cvss 8.8epss 0.01
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserialization_classes`…
- risk 0.41cvss 7.3epss 0.01
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task…
- risk 0.46cvss 5.3epss 0.01
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
- risk 0.44cvss 6.7epss 0.00
Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.
- risk 0.57cvss 8.8epss 0.01
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
- risk 0.44cvss 6.8epss 0.00
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.
- risk 0.44cvss 6.8epss 0.00
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
- risk 0.28cvss 4.3epss 0.00
In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.
- risk 0.52cvss 8.0epss 0.00
In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content.
- risk 0.20cvss 3.1epss 0.00
An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known.
- risk 0.35cvss 6.5epss 0.00
Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authenticated Viewer holding only configuration-read access — with no prior access to…
- risk 0.60cvss —epss 0.01
Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator.
- risk 0.35cvss 6.5epss 0.00
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` was displayed in…
- risk 0.28cvss 5.4epss 0.01
Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user with XCom write-and-read access to…
- risk 0.50cvss 8.8epss 0.00
Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config`…
- risk 0.21cvss 4.3epss 0.00
Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into values nested inside a list, tuple, or set beyond that limit, so an Airflow Variable holding such a…
- risk 0.36cvss 5.5epss 0.00
Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when…
- risk 0.57cvss —epss 0.00
In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-based RDF data or query results, permitting DOCTYPE declarations, external entity references, and external DTD loading. This is due to an…
- CVE-2025-35988Aug 12, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2025-35977Aug 12, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2025-32737Aug 12, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2025-32087Aug 12, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2025-32084Aug 12, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2025-31943Aug 12, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2025-30178Aug 12, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2025-27570Aug 12, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2025-27245Aug 12, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2025-25275Aug 12, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2025-24837Aug 12, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2025-24488Aug 12, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2025-20020Aug 12, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- risk 0.41cvss 6.3epss —
open-iscsi: open-iscsi: Out-of-bounds access in iscsiuio ICMPv6 echo handling