Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
413 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.7) | 0.12% | — | Jfrog Artifactory | 12/8/2026 | 11/9/2026 | Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users. | |
| Analizada | Media (5.3) | 0.46% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | An unauthenticated user may bypass authentication under specific cache conditions. | |
| Analizada | Alta (7.5) | 0.27% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | A user with access to a valid SAML response may impersonate another user under specific conditions. | |
| Analizada | Media (6.6) | 0.47% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | A party with write access to stored session data may affect JFrog Artifactory under specific conditions. | |
| Analizada | Media (4.3) | 0.26% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | A bundle writer may create misleading release promotion information under specific conditions. | |
| Analizada | Media (6.5) | 0.31% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | A repository publisher without delete permission may modify protected package content under specific conditions. | |
| Analizada | Media (5.3) | 0.31% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way. | |
| Analizada | Alta (7.2) | 0.49% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | A Project Resource Manager may gain broader administrative privileges under specific conditions. | |
| Analizada | Media (4.3) | 0.35% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | An authenticated user may write files outside the intended Artifactory work directory under specific conditions. | |
| Analizada | Media (5.3) | 0.39% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions. | |
| Analizada | Media (4.3) | 0.30% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions. | |
| Analizada | Media (4.3) | 0.30% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | An authenticated user may view private Puppet module metadata without repository read access. | |
| Analizada | Media (4.3) | 0.30% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | An authenticated user without repository read permission may access private NuGet metadata under specific conditions. | |
| Analizada | Media (5.3) | 0.36% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | An unauthenticated user may access restricted repository information under specific conditions. | |
| Analizada | Media (5.4) | 0.22% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | Credentials for a deleted user may remain valid for a short period under specific conditions. | |
| Analizada | Alta (8.1) | 0.40% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions. | |
| Aplazada | Alta (8.8) | 0.40% | — | Nishishi Factory TegalogAI | 10/8/2026 | 28/8/2026 | Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log in to the management console. As a result, the attacker may perform any operations available from the management… | |
| Analizada | Media (6.5) | 0.34% | — | Widgetfactorylimited JCE | 29/7/2026 | 5/8/2026 | Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file rename functionality allowed an authenticated user with file management permissions to rename files to otherwise… | |
| Analizada | Media (6.5) | 0.39% | — | Jfrog Artifactory | 27/7/2026 | 30/7/2026 | Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability… | |
| Analizada | Alta (7.2) | 0.57% | — | Jfrog Artifactory | 27/7/2026 | 30/7/2026 | An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator access. | |
| Analizada | Alta (8.8) | 0.64% | — | Jfrog Artifactory | 27/7/2026 | 15/9/2026 | JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level. | |
| Analizada | Media (6.5) | 0.35% | — | Jfrog Artifactory | 27/7/2026 | 30/7/2026 | A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response. | |
| Analizada | Media (6.5) | 0.41% | — | Jfrog Artifactory | 27/7/2026 | 30/7/2026 | JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and… | |
| Analizada | Media (6.8) | 0.31% | — | Jfrog Artifactory | 27/7/2026 | 30/7/2026 | A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions. | |
| Analizada | Media (5.4) | 0.31% | — | Jfrog Artifactory | 27/7/2026 | 30/7/2026 | An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level; confidentiality is not affected. |