Known vulnerabilities in Artifactory - page 2

Vendor: JFrog
Software: Artifactory
Software CPE: cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:*:*:*
Total vulnerabilities: 48
Public exploits: 0
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Artifactory Artifactory is affected by 48 known vulnerabilities: 2 high, 12 medium, 34 low Critical High Medium Low

Vulnerabilities (48)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU146514 - Deserialization of Untrusted Data
CVE-2026-65617
CWE-502 Low
No
No
7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, 7.161.15 31.08.2026 SB2026083191
#VU146503 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-66382
CWE-22 Low
No
No
7.146.35, 7.161.16 31.08.2026 SB2026083190
#VU146502 - Missing Authorization
CVE-2026-66380
CWE-862 Low
No
No
7.146.35, 7.161.16 31.08.2026 SB2026083190
#VU146501 - Missing Authorization
CVE-2026-66378
CWE-862 Low
No
No
7.146.35, 7.161.16 31.08.2026 SB2026083190
#VU146500 - Improper Authentication
CVE-2026-68760
CWE-287 Medium
No
No
7.146.35, 7.161.16 31.08.2026 SB2026083190
#VU146499 - Missing Authorization
CVE-2026-65926
CWE-862 Low
No
No
7.146.35, 7.161.16 31.08.2026 SB2026083190
#VU146498 - Cleartext Storage of Sensitive Information
CVE-2026-66016
CWE-312 Low
No
No
7.146.35, 7.161.16 31.08.2026 SB2026083190
#VU146497 - Missing Authorization
CVE-2026-66375
CWE-862 Low
No
No
7.146.35, 7.161.16 31.08.2026 SB2026083190
#VU146496 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-66384
CWE-22 High
No
Exploited
7.146.35, 7.161.16 31.08.2026 SB2026083190
#VU146493 - Insufficient Verification of Data Authenticity
CVE-2026-69105
CWE-345 Medium
No
No
7.161.16 31.08.2026 SB2026083190
#VU146492 - Missing Authorization
CVE-2026-70547
CWE-862 Low
No
No
7.161.16 31.08.2026 SB2026083190
#VU146486 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-66381
CWE-22 Low
No
No
7.146.35, 7.161.16 31.08.2026 SB2026083190
#VU146483 - Missing Authorization
CVE-2026-65922
CWE-862 Low
No
No
7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, 7.161.15 31.08.2026 SB2026083191
#VU146482 - Server-Side Request Forgery (SSRF)
CVE-2026-65923
CWE-918 Low
No
No
7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, 7.161.15 31.08.2026 SB2026083191
#VU146481 - Exposure of sensitive information to an unauthorized actor
CVE-2026-66018
CWE-200 Low
No
No
7.146.34, 7.161.15 31.08.2026 SB2026083191
#VU146480 - Improper Authentication
CVE-2026-66014
CWE-287 Low
No
No
7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, 7.161.15 31.08.2026 SB2026083191
#VU146478 - Server-Side Request Forgery (SSRF)
CVE-2026-65924
CWE-918 Low
No
No
7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, 7.161.15 31.08.2026 SB2026083191
#VU146477 - Missing Authorization
CVE-2026-66379
CWE-862 Low
No
No
7.146.35, 7.161.16 31.08.2026 SB2026083190
#VU146476 - Missing Authorization
CVE-2026-68758
CWE-862 Low
No
No
7.146.35, 7.161.16 31.08.2026 SB2026083190
#VU146475 - Improper Verification of Cryptographic Signature
CVE-2026-68759
CWE-347 Low
No
No
7.146.35, 7.161.16 31.08.2026 SB2026083190


Showing elements 21 - 40 out of 48