Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Allura CRITICAL 9.8
CVE-2026-73240

Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recomme…

Fix: 1.19.1+
Fix from $2,300 2026-08-12
Httpclient CRITICAL 9.1
CVE-2026-71290

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effe…

Fix: 5.6.4+
Fix from $2,300 2026-08-11
Allura CRITICAL 9.1
CVE-2026-69223

Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommend…

Fix: 1.19.1+
Fix from $2,300 2026-08-11
Ranger CRITICAL 9.8
CVE-2026-32227

SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the…

Fix: 2.9.0+
Fix from $2,300 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-40920

Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixe…

Fix: 2.9.0+
Fix from $2,300 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-42537

Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.

Fix: 2.9.0+
Fix from $2,300 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-44416

Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgra…

Fix: 2.9.0+
Fix from $2,300 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-55799

Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fi…

Fix: 2.9.0+
Fix from $2,300 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-28672

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger…

Fix: after 2.8.0
Fix from $2,300 2026-08-10
Fory CRITICAL 9.8
CVE-2026-71558

Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafte…

Fix: 1.5.0+
Fix from $2,300 2026-08-07
Fory CRITICAL 9.1
CVE-2026-71560

Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deser…

Fix: 1.5.0+
Fix from $2,300 2026-08-07
Apr Util CRITICAL 9.1
CVE-2026-32327

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources an…

Fix: 1.6.4+
Fix from $2,300 2026-08-06
Apr Util CRITICAL 9.1
CVE-2026-34191

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_ora…

Fix: after 1.6.3
Fix from $2,300 2026-08-06
Cxf CRITICAL 9.8
CVE-2026-68079

In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the im…

Fix: 3.6.12 / 4.1.8+
Fix from $2,300 2026-08-06
Cxf CRITICAL 9.1
CVE-2026-61466

In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client reg…

Fix: 3.6.12 / 4.1.8+
Fix from $2,300 2026-08-06
Cxf CRITICAL 9.1
CVE-2026-63687

Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensiti…

Fix: 3.6.12 / 4.1.8+
Fix from $2,300 2026-08-06
Cxf CRITICAL 9.1
CVE-2026-65583

Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/…

Fix: 3.6.12 / 4.1.8+
Fix from $2,300 2026-08-06
Cxf CRITICAL 9.8
CVE-2026-66909

Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in pla…

Fix: 3.6.12 / 4.1.8+
Fix from $2,300 2026-08-06
Answer CRITICAL 9.1
CVE-2026-60053

Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained u…

Fix: 2.0.2+
Fix from $2,300 2026-08-05
Lucy CRITICAL 9.8
CVE-2026-61484

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As th…

Mitigation only
Fix from $2,300 2026-08-05
Lucy CRITICAL 9.8
CVE-2026-61486

** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this pro…

No fix yet
Fix from $2,300 2026-08-05
Nifi CRITICAL 9.1
CVE-2026-68980

Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framewor…

Fix: 2.11.0+
Fix from $2,300 2026-08-03
Nifi CRITICAL 9.8
CVE-2026-68979

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components refer…

Fix: 2.11.0+
Fix from $2,300 2026-08-03
Tika CRITICAL 9.8
CVE-2026-66756

Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users a…

No fix yet
Fix from $2,300 2026-07-30
Kyuubi CRITICAL 9.8
CVE-2026-52680

Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote …

Fix: 1.12.0+
Fix from $2,300 2026-07-30
Jspwiki CRITICAL 9.8
CVE-2026-28812

UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommende…

Fix: 2.12.4+
Fix from $2,300 2026-07-30
Apache Airflow Providers Fab CRITICAL 9.8
CVE-2026-59243

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or…

Fix: 3.7.3+
Fix from $2,300 2026-07-29
Traffic Server CRITICAL 9.8
CVE-2026-58185

The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 thro…

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29
Traffic Server CRITICAL 9.8
CVE-2026-58177

The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Se…

Fix: 10.1.4+
Fix from $2,300 2026-07-29
Traffic Server CRITICAL 9.8
CVE-2026-58179

The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: fro…

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29