Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Cxf CRITICAL 9.8
CVE-2026-44930

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certi…

Fix: 3.6.11 / 4.1.6+
Fix from $2,300 2026-05-22
Fory CRITICAL 9.8
CVE-2026-48207

Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks dur…

Fix: 1.0.0+
Fix from $2,300 2026-05-21
Camel CRITICAL 9.8
CVE-2026-47323

Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStrategy implementations (CxfRsHe…

Fix: 4.14.6 / 4.18.2+
Fix from $2,300 2026-05-19
Ofbiz CRITICAL 9.8
CVE-2026-45434EPSS 22%

Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBi…

Fix: 24.09.06+
Fix from $2,300 2026-05-19
Ofbiz CRITICAL 9.1
CVE-2026-31986

Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgra…

Fix: 24.09.06+
Fix from $2,300 2026-05-19
Ofbiz CRITICAL 9.1
CVE-2026-41919

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz:…

Fix: 24.09.06+
Fix from $2,300 2026-05-19
Tomcat CRITICAL 9.1
CVE-2026-43515

Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affe…

Fix: 9.0.118 / 10.1.55+
Fix from $2,300 2026-05-12
Tomcat CRITICAL 9.8
CVE-2026-41293

Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 1…

Fix: 9.0.118 / 10.1.55+
Fix from $2,300 2026-05-12
Tomcat CRITICAL 9.8
CVE-2026-43512

DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 t…

Fix: 9.0.118 / 10.1.55+
Fix from $2,300 2026-05-12
Cloudstack CRITICAL 9.1
CVE-2026-25199

Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudSt…

Fix: 4.22.0.1+
Fix from $2,300 2026-05-08
Wicket CRITICAL 9.1
CVE-2026-40010

Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache …

Fix: 10.9.0+
Fix from $2,300 2026-05-06
HTTP Server CRITICAL 9.8
CVE-2026-28780

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server …

Fix: 2.4.67+
Fix from $2,300 2026-05-05
Polaris CRITICAL 9.9
CVE-2026-42809

Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been val…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Polaris CRITICAL 9.9
CVE-2026-42810

Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table acc…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Polaris CRITICAL 9.9
CVE-2026-42811

In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or tabl…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Polaris CRITICAL 9.9
CVE-2026-42812

In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to re…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Opennlp CRITICAL 9.8
CVE-2026-42027

Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M…

Fix: 2.5.9+
Fix from $2,300 2026-05-04
Opennlp CRITICAL 9.1
CVE-2026-40682

XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0…

Fix: 2.5.9+
Fix from $2,300 2026-05-04
Mina CRITICAL 9.8
CVE-2026-42778

The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 i…

Fix: 2.1.12 / 2.2.7+
Fix from $2,300 2026-05-01
Mina CRITICAL 9.8
CVE-2026-42779

The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: Apache MINA's Abstrac…

Fix: 2.1.12 / 2.2.7+
Fix from $2,300 2026-05-01
Pony Mail CRITICAL 9.8
CVE-2026-41873

** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading t…

Mitigation only
Fix from $2,300 2026-04-28
Camel CRITICAL 10.0
CVE-2026-33453EPSS 6%

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's ca…

Fix: after 4.14.5
Fix from $2,300 2026-04-27
Mina CRITICAL 9.8
CVE-2026-41409

The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized …

Fix: 2.0.28 / 2.1.11+
Fix from $2,300 2026-04-27
Camel CRITICAL 9.4
CVE-2026-33454

The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterSt…

Fix: 4.14.6 / 4.18.1+
Fix from $2,300 2026-04-27
Camel CRITICAL 9.9
CVE-2026-40453

The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable…

Fix: 4.14.6 / 4.18.2+
Fix from $2,300 2026-04-27
Camel CRITICAL 9.8
CVE-2026-40860

JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessa…

Fix: 4.14.7 / 4.18.2+
Fix from $2,300 2026-04-27
Mina CRITICAL 9.8
CVE-2026-41635

Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at …

Fix: 2.0.28 / 2.1.11+
Fix from $2,300 2026-04-27
Kafka CRITICAL 9.1
CVE-2026-33557

A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set…

Fix: 4.1.2+
Fix from $2,300 2026-04-20
Apisix CRITICAL 9.1
CVE-2026-31908

Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious…

Fix: 3.16.0+
Fix from $2,300 2026-04-14
Tomcat CRITICAL 9.1
CVE-2026-29145

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Nati…

Fix: 1.3.7 / 2.0.14+
Fix from $2,300 2026-04-09