Known vulnerabilities in Artifactory

Vendor: JFrog
Software: Artifactory
Software CPE: cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:*:*:*
Total vulnerabilities: 48
Public exploits: 0
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Artifactory Artifactory is affected by 48 known vulnerabilities: 2 high, 12 medium, 34 low Critical High Medium Low

Vulnerabilities (48)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU146513 - Improper Verification of Cryptographic Signature
CVE-2026-65616
CWE-347 Medium
No
No
7.146.27 31.08.2026 SB20260831103
#VU146512 - Exposure of sensitive information to an unauthorized actor
CVE-2026-42017
CWE-200 Medium
No
No
7.133.21, 7.146.8 31.08.2026 SB2026083194
#VU146511 - Incorrect Authorization
CVE-2026-42016
CWE-863 Low
No
No
7.133.11 31.08.2026 SB20260831102
#VU146510 - Server-Side Request Forgery (SSRF)
CVE-2026-65618
CWE-918 Medium
No
No
7.133.6 31.08.2026 SB20260831101
#VU146509 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-14830
CWE-79 Medium
No
No
7.117.10 31.08.2026 SB20260831100
#VU146508 - Improper input validation
CVE-2024-6915
CWE-20 Low
No
No
7.55.18, 7.59.23, 7.63.22, 7.68.22, 7.71.23, 7.77.14, 7.84.20, 7.90.6 31.08.2026 SB2026083199
#VU146507 - Improper input validation
CVE-2024-2248
CWE-20 Medium
No
No
7.84.7 31.08.2026 SB2026083198
#VU146506 - Improper input validation
CVE-2024-4142
CWE-20 Medium
No
No
7.55.17, 7.59.22, 7.63.21, 7.68.21, 7.71.21, 7.77.11 31.08.2026 SB2026083197
#VU146505 - Exposure of sensitive information to an unauthorized actor
CVE-2024-3505
CWE-200 Low
No
No
7.77.3 31.08.2026 SB2026083196
#VU146504 - Improper input validation
CVE-2026-69106
CWE-20 Low
No
No
7.146.28 31.08.2026 SB2026083195
#VU146495 - Improper Authentication
CVE-2026-42018
CWE-287 Medium
No
No
7.111.20, 7.117.27, 7.125.19, 7.133.28, 7.146.8 31.08.2026 SB2026083194
#VU146494 - Missing Authorization
CVE-2026-69107
CWE-862 Low
No
No
7.104.16, 7.111.14, 7.117.21, 7.125.14, 7.133.21, 7.146.8 31.08.2026 SB2026083194
#VU146491 - Missing Authorization
CVE-2026-69104
CWE-862 Low
No
No
7.161.19 31.08.2026 SB2026083193
#VU146490 - Server-Side Request Forgery (SSRF)
CVE-2026-70548
CWE-918 Low
No
No
7.146.36, 7.161.19 31.08.2026 SB2026083193
#VU146489 - Missing Authorization
CVE-2026-70550
CWE-862 Low
No
No
7.146.36, 7.161.19 31.08.2026 SB2026083193
#VU146488 - Server-Side Request Forgery (SSRF)
CVE-2026-70551
CWE-918 Low
No
No
7.146.36, 7.161.19 31.08.2026 SB2026083193
#VU146487 - Improper Authentication
CVE-2026-82329
CWE-287 High
No
No
7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20 31.08.2026 SB2026083192
#VU146485 - Server-Side Request Forgery (SSRF)
CVE-2026-65925
CWE-918 Low
No
No
7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, 7.161.15 31.08.2026 SB2026083191
#VU146484 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-65921
CWE-22 Low
No
No
7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, 7.161.15 31.08.2026 SB2026083191
#VU146479 - Improper Privilege Management
CVE-2026-66015
CWE-269 Medium
No
No
7.146.34, 7.161.15 31.08.2026 SB2026083191


Showing elements 1 - 20 out of 48