Vulnerabilities
Vulnerable Software
Security Vulnerabilities
An authenticated user may write files outside the intended Artifactory work directory under specific conditions.
CVSS Score
4.3
EPSS Score
0.003
Published
2026-08-12
A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.
CVSS Score
8.1
EPSS Score
0.003
Published
2026-08-12
Credentials for a deleted user may remain valid for a short period under specific conditions.
CVSS Score
4.2
EPSS Score
0.002
Published
2026-08-12
An unauthenticated user may access restricted repository information under specific conditions.
CVSS Score
5.3
EPSS Score
0.002
Published
2026-08-12
An authenticated user without repository read permission may access private NuGet metadata under specific conditions.
CVSS Score
4.3
EPSS Score
0.002
Published
2026-08-12
An authenticated user may view private Puppet module metadata without repository read access.
CVSS Score
4.3
EPSS Score
0.002
Published
2026-08-12
An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.
CVSS Score
4.3
EPSS Score
0.002
Published
2026-08-12
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnostic secret name. In a deployment running multi-team mode with this backend, a task or Dag belonging to one team resolved another team's Connection or Variable, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backend. Users are advised to upgrade to apache-airflow-providers-google 22.3.0 or later, which builds and applies the team-scoped secret name.
CVSS Score
6.5
EPSS Score
0.005
Published
2026-08-12
Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSS Score
8.8
EPSS Score
0.004
Published
2026-08-11
Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVSS Score
8.3
EPSS Score
0.003
Published
2026-08-11


Contact Us

Shodan ® - All rights reserved