Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
76 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 14% | ⚠ Explotación activa | Jfrog Artifactory | 28/8/2026 | 3/9/2026 | JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. | |
| Pendiente de análisis | Media (6.5) | 0.35% | — | Jfrog ArtifactoryAI | 25/8/2026 | 28/8/2026 | An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions. | |
| Pendiente de análisis | Baja (3.5) | 0.29% | — | Jfrog ArtifactoryAICocoapodsAI | 25/8/2026 | 28/8/2026 | Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External Dependency. | |
| Analizada | Alta (8.8) | 0.52% | — | Jfrog Artifactory | 12/8/2026 | 11/9/2026 | A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content. | |
| Analizada | Alta (7.5) | 9.8% | ⚠ Explotación activa | Jfrog Artifactory | 12/8/2026 | 1/10/2026 | JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. | |
| Analizada | Media (4.3) | 0.28% | — | Jfrog Artifactory | 12/8/2026 | 11/9/2026 | An authenticated user without repository read permission may access package metadata under specific conditions. | |
| Analizada | Media (5.9) | 0.41% | — | Jfrog Artifactory | 12/8/2026 | 11/9/2026 | An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions. | |
| Analizada | Alta (8.1) | 0.22% | — | Jfrog Artifactory | 12/8/2026 | 11/9/2026 | An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability. | |
| Analizada | Alta (7.2) | 0.33% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | A holder of a valid integration credential may impersonate other users under specific conditions. | |
| Analizada | Media (6.5) | 0.35% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | A low-privileged authenticated user may access restricted support information under specific conditions. | |
| Analizada | Media (5.3) | 0.66% | ⚠ Explotación activa | Jfrog Artifactory | 12/8/2026 | 28/8/2026 | An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. | |
| Analizada | Media (6.7) | 0.12% | — | Jfrog Artifactory | 12/8/2026 | 11/9/2026 | Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users. | |
| Analizada | Media (5.3) | 0.46% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | An unauthenticated user may bypass authentication under specific cache conditions. | |
| Analizada | Alta (7.5) | 0.27% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | A user with access to a valid SAML response may impersonate another user under specific conditions. | |
| Analizada | Media (6.6) | 0.47% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | A party with write access to stored session data may affect JFrog Artifactory under specific conditions. | |
| Analizada | Media (4.3) | 0.26% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | A bundle writer may create misleading release promotion information under specific conditions. | |
| Analizada | Media (6.5) | 0.31% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | A repository publisher without delete permission may modify protected package content under specific conditions. | |
| Analizada | Media (5.3) | 0.31% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way. | |
| Analizada | Alta (7.2) | 0.49% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | A Project Resource Manager may gain broader administrative privileges under specific conditions. | |
| Analizada | Media (4.3) | 0.35% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | An authenticated user may write files outside the intended Artifactory work directory under specific conditions. | |
| Analizada | Media (5.3) | 0.39% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions. | |
| Analizada | Media (4.3) | 0.30% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions. | |
| Analizada | Media (4.3) | 0.30% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | An authenticated user may view private Puppet module metadata without repository read access. | |
| Analizada | Media (4.3) | 0.30% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | An authenticated user without repository read permission may access private NuGet metadata under specific conditions. | |
| Analizada | Media (5.3) | 0.36% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | An unauthenticated user may access restricted repository information under specific conditions. |