| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1. |
| A weakness has been identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file backend/webserver/api/datasets.py of the component Data Endpoint. Executing a manipulation of the argument folder can lead to path traversal. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. |
| LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0. |
| A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions. |
| Credentials for a deleted user may remain valid for a short period under specific conditions. |
| An unauthenticated user may access restricted repository information under specific conditions. |
| An authenticated user without repository read permission may access private NuGet metadata under specific conditions. |
| An authenticated user may view private Puppet module metadata without repository read access. |
| An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions. |
| A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions. |
| An authenticated user may write files outside the intended Artifactory work directory under specific conditions. |
| A Project Resource Manager may gain broader administrative privileges under specific conditions. |
| An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way. |
| A repository publisher without delete permission may modify protected package content under specific conditions. |
| A bundle writer may create misleading release promotion information under specific conditions. |
| A party with write access to stored session data may affect JFrog Artifactory under specific conditions. |
| A user with access to a valid SAML response may impersonate another user under specific conditions. |
| An unauthenticated user may bypass authentication under specific cache conditions. |