Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Camel CRITICAL 9.1
CVE-2026-48203

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Fo…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.1
CVE-2026-48205

Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. The camel-dns producers read DNS operatio…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.8
CVE-2026-43867

Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-quantum key metadata (KeyMetada…

Fix: 4.18.3 / 4.21.0+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.8
CVE-2026-46454

Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeux (CometD) message headers in…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.8
CVE-2026-46455

Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper KeycloakSecurityHelper.parseAnd…

Fix: 4.18.3 / 4.21.0+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.8
CVE-2026-46456

Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs component map inbound message attributes into the Ca…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Iotdb CRITICAL 9.8
CVE-2026-24014

Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without suffici…

Fix: 2.0.8+
Fix from $2,300 2026-07-06
Iotdb CRITICAL 9.1
CVE-2026-24013

Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter.…

Fix: 2.0.8+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.1
CVE-2026-40047

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. The camel-doclin…

Fix: 4.18.3+
Fix from $2,300 2026-07-06
Lucene.net CRITICAL 9.8
CVE-2026-47898

Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Ap…

Mitigation only
Fix from $2,300 2026-07-03
Tomcat CRITICAL 9.1
CVE-2026-55276

Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not inc…

Fix: 9.0.119 / 10.1.56+
Fix from $2,300 2026-06-29
Tomcat CRITICAL 9.1
CVE-2026-53434

Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apach…

Fix: 9.0.119 / 10.1.56+
Fix from $2,300 2026-06-29
Apisix CRITICAL 9.3
CVE-2026-49871

Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manag…

Fix: 3.17.0+
Fix from $2,300 2026-06-19
Apisix CRITICAL 9.1
CVE-2026-49230

Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default configuration is vulnerable to aut…

Fix: 3.17.0+
Fix from $2,300 2026-06-19
Apisix CRITICAL 9.1
CVE-2026-44087

Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default configuration has an attack s…

Fix: 3.17.0+
Fix from $2,300 2026-06-19
Apisix CRITICAL 9.1
CVE-2026-39999

Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configur…

Fix: 3.17.0+
Fix from $2,300 2026-06-19
Shiro CRITICAL 9.1
CVE-2026-49268

A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username …

Fix: 2.2.1+
Fix from $2,300 2026-06-17
Apache Airflow Providers Sftp CRITICAL 9.1
CVE-2026-50203

A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP serv…

Fix: 5.8.1+
Fix from $2,300 2026-06-17
Dolphinscheduler CRITICAL 9.8
CVE-2026-32966

DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache …

Fix: 3.4.2+
Fix from $2,300 2026-06-17
Dolphinscheduler CRITICAL 9.1
CVE-2026-32967

Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before…

Fix: 3.4.2+
Fix from $2,300 2026-06-17
Cxf CRITICAL 9.8
CVE-2026-49875

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configuration…

Fix: 4.1.7 / 4.2.2+
Fix from $2,300 2026-06-12
Cxf CRITICAL 9.8
CVE-2026-50628

A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other…

Fix: 4.1.7 / 4.2.2+
Fix from $2,300 2026-06-12
Cxf CRITICAL 9.1
CVE-2026-50627

The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued…

Fix: 4.1.7 / 4.2.2+
Fix from $2,300 2026-06-12
HTTP Server CRITICAL 9.8
CVE-2026-44631

Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: fr…

Fix: 2.4.68+
Fix from $2,300 2026-06-08
HTTP Server CRITICAL 9.1
CVE-2026-42535

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases…

Fix: 2.4.68+
Fix from $2,300 2026-06-08
HTTP Server CRITICAL 9.8
CVE-2026-29167

Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 th…

Fix: 2.4.68+
Fix from $2,300 2026-06-08
Fory CRITICAL 9.1
CVE-2026-50076

Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remo…

Fix: 1.1.0+
Fix from $2,300 2026-06-04
Mina CRITICAL 9.8
CVE-2026-47065

ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the seri…

Mitigation only
Fix from $2,300 2026-06-03
Solr CRITICAL 9.8
CVE-2026-44825

Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a …

Fix: after 9.10.1
Fix from $2,300 2026-06-01
Airflow CRITICAL 9.1
CVE-2026-42252

Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a verbatim `BashOperator(b…

Fix: 3.2.2+
Fix from $2,300 2026-06-01