Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2026-82329
Known exploited
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
CVSS Score
9.8
EPSS Score
0.077
Published
2026-08-28
CVE-2026-82078
Known exploited
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.
CVSS Score
9.4
EPSS Score
0.036
Published
2026-08-28
CVE-2026-81578
Known exploited
An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.
CVSS Score
8.8
EPSS Score
0.033
Published
2026-08-28
CVE-2026-60004
Known exploited
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
CVSS Score
9.8
EPSS Score
0.868
Published
2026-08-26
CVE-2026-72530
Known exploited
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
CVSS Score
9.5
EPSS Score
0.018
Published
2026-08-19
CVE-2026-72529
Known exploited
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
CVSS Score
9.3
EPSS Score
0.016
Published
2026-08-19
CVE-2026-19490
Known exploited
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
CVSS Score
9.3
EPSS Score
0.056
Published
2026-08-19
CVE-2026-64849
Known exploited
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.
CVSS Score
9.3
EPSS Score
0.164
Published
2026-08-17
CVE-2026-73570
Known exploited
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
CVSS Score
8.9
EPSS Score
0.324
Published
2026-08-13
CVE-2026-42018
Known exploited
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
CVSS Score
7.5
EPSS Score
0.11
Published
2026-08-12


Contact Us

Shodan ® - All rights reserved