Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Traffic Server CRITICAL 9.1
CVE-2026-58163

Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: …

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29
Traffic Server CRITICAL 10.0
CVE-2026-58162

The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server:…

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29
Traffic Server CRITICAL 9.3
CVE-2026-58155

Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Tr…

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29
Traffic Server CRITICAL 10.0
CVE-2026-57834

Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9…

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29
Traffic Server CRITICAL 10.0
CVE-2026-58150

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic …

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29
Traffic Server CRITICAL 9.3
CVE-2026-41920

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 thr…

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29
Traffic Server CRITICAL 9.1
CVE-2026-33267

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 t…

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29
Axis2\/java CRITICAL 9.8
CVE-2026-66713

Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0…

Fix: 2.0.1+
Fix from $2,300 2026-07-28
Thrift CRITICAL 9.8
CVE-2026-55971

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to u…

Fix: 0.24.0+
Fix from $2,300 2026-07-27
Thrift CRITICAL 9.1
CVE-2026-58023

Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrad…

Fix: 0.24.0+
Fix from $2,300 2026-07-27
Thrift CRITICAL 9.1
CVE-2026-58662

Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift…

Fix: 0.24.0+
Fix from $2,300 2026-07-27
Thrift CRITICAL 9.1
CVE-2026-48144

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.…

Fix: 0.24.0+
Fix from $2,300 2026-07-27
Fory CRITICAL 9.8
CVE-2026-64606

Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lamb…

Fix: 1.4.0+
Fix from $2,300 2026-07-21
Fory CRITICAL 9.1
CVE-2026-64609

Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the b…

Fix: 1.4.0+
Fix from $2,300 2026-07-21
Fory CRITICAL 9.8
CVE-2026-64608

Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip pa…

Fix: 1.4.0+
Fix from $2,300 2026-07-21
Syncope CRITICAL 9.8
CVE-2026-63071

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can crea…

Fix: 4.0.7 / 4.1.2+
Fix from $2,300 2026-07-20
Syncope CRITICAL 9.8
CVE-2026-57308

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate…

Fix: 4.0.7 / 4.1.2+
Fix from $2,300 2026-07-20
Syncope CRITICAL 9.8
CVE-2026-62183

Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user wor…

Fix: 4.0.7 / 4.1.2+
Fix from $2,300 2026-07-20
Syncope CRITICAL 9.8
CVE-2026-53421

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code ex…

Fix: 4.0.7 / 4.1.2+
Fix from $2,300 2026-07-20
Syncope CRITICAL 9.8
CVE-2026-53405

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN pr…

Fix: 4.0.7 / 4.1.2+
Fix from $2,300 2026-07-20
Kylin CRITICAL 9.8
CVE-2026-62390

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table ca…

Fix: 5.0.4+
Fix from $2,300 2026-07-14
Kylin CRITICAL 9.8
CVE-2026-62392

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job…

Fix: 5.0.4+
Fix from $2,300 2026-07-14
Doris CRITICAL 9.1
CVE-2026-58319

Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access …

Fix: 3.1.0+
Fix from $2,300 2026-07-14
Tomcat CRITICAL 9.1
CVE-2026-59083

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configura…

Fix: after 11.0.23
Fix from $2,300 2026-07-14
Tomcat CRITICAL 9.1
CVE-2026-59084

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clea…

Fix: after 11.0.23
Fix from $2,300 2026-07-14
Gravitino CRITICAL 9.1
CVE-2026-41041

URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before…

Fix: 1.2.1+
Fix from $2,300 2026-07-13
Airflow CRITICAL 9.8
CVE-2026-33264

A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server …

Fix: 3.3.0+
Fix from $2,300 2026-07-07
Camel CRITICAL 9.8
CVE-2026-56140

Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns component filters Camel headers through a component-s…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.8
CVE-2026-53913

Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak C…

Fix: 4.18.3 / 4.21.0+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.8
CVE-2026-48204

Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs produce…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06