Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Airflow CRITICAL 9.1
CVE-2025-57735

When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was inte…

Fix: 3.2.0+
Fix from $2,300 2026-04-09
Iotdb CRITICAL 9.8
CVE-2026-24015

A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrad…

Fix: 1.3.7 / 2.0.7+
Fix from $2,300 2026-03-09
Iotdb CRITICAL 9.8
CVE-2026-24713

Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users a…

Fix: 1.3.7 / 2.0.7+
Fix from $2,300 2026-03-09
Artemis CRITICAL 9.8
CVE-2026-27446EPSS 10%

Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker c…

Fix: after 2.44.0
Fix from $2,300 2026-03-04
Ranger CRITICAL 9.8
CVE-2025-59059

Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to…

Fix: 2.8.0+
Fix from $2,300 2026-03-03
Camel CRITICAL 9.1
CVE-2026-23552

Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.  The Camel-Keycloak KeycloakSecurityPolicy does not v…

Fix: 4.18.0+
Fix from $2,300 2026-02-23
Tomcat CRITICAL 9.1
CVE-2025-66614

Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.…

Fix: 9.0.113 / 10.1.50+
Fix from $2,300 2026-02-17
Druid CRITICAL 9.8
CVE-2026-23906

Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * d…

Fix: 36.0.0+
Fix from $2,300 2026-02-10
Continuum CRITICAL 9.9
CVE-2016-15057

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum…

Mitigation only
Fix from $2,300 2026-01-26
Brpc CRITICAL 9.8
CVE-2025-60021EPSS 25%

Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to …

Fix: 1.15.0+
Fix from $2,300 2026-01-16
Uniffle CRITICAL 9.1
CVE-2025-68637

The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This insecure configuration expos…

Fix: 0.10.0+
Fix from $2,300 2026-01-07
Apache Airflow Providers Edge3 CRITICAL 9.8
CVE-2025-67895

Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on …

Fix: 2.0.0+
Fix from $2,300 2025-12-17
Streampark CRITICAL 9.8
CVE-2025-54947

In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs b…

Fix: 2.1.7+
Fix from $2,300 2025-12-12
Fineract CRITICAL 9.1
CVE-2025-58130

Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in ver…

Fix: 1.12.1+
Fix from $2,300 2025-12-12
Tika CRITICAL 9.8
CVE-2025-66516EPSS 79%

Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an a…

Fix: 3.2.2+
Fix from $2,300 2025-12-04
Druid CRITICAL 9.8
CVE-2025-59390

Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is…

Fix: 35.0.0+
Fix from $2,300 2025-11-26
Tomcat CRITICAL 9.6
CVE-2025-55754EPSS 10%

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log mes…

Fix: 9.0.109 / 10.0.27+
Fix from $2,300 2025-10-27
Activemq Nms Amqp CRITICAL 9.8
CVE-2025-54539

A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ …

Fix: 2.4.0+
Fix from $2,300 2025-10-16
Fory CRITICAL 9.8
CVE-2025-61622EPSS 41%

Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows…

Fix: after 0.12.2
Fix from $2,300 2025-10-01
Dolphinscheduler CRITICAL 9.8
CVE-2024-43166

Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recomme…

Fix: 3.2.2+
Fix from $2,300 2025-09-03
Ofbiz CRITICAL 9.8
CVE-2025-54466EPSS 15%

Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects A…

Fix: 24.09.02+
Fix from $2,300 2025-08-15
Seata CRITICAL 9.8
CVE-2025-53606

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recomm…

Mitigation only
Fix from $2,300 2025-08-08
Cxf CRITICAL 9.8
CVE-2025-48913

If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution cap…

Fix: 3.6.8 / 4.0.9+
Fix from $2,300 2025-08-08
HTTP Server CRITICAL 9.1
CVE-2025-23048

In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 …

Fix: 2.4.64+
Fix from $2,300 2025-07-10
Seata CRITICAL 9.8
CVE-2025-32897

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the ver…

Fix: 2.3.0+
Fix from $2,300 2025-06-28
Apache Airflow Providers Snowflake CRITICAL 9.8
CVE-2025-50213

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This is…

Fix: 6.4.0+
Fix from $2,300 2025-06-24
Nuttx CRITICAL 9.8
CVE-2025-47868

Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that…

Fix: 12.9.0+
Fix from $2,300 2025-06-16
Nuttx CRITICAL 9.8
CVE-2025-47869

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability was discovered in Apache NuttX RTOS apps/exapmles/xmlrpc applic…

Fix: 12.9.0+
Fix from $2,300 2025-06-16
Inlong CRITICAL 9.8
CVE-2025-27531

Deserialization of Untrusted Data vulnerability in Apache InLong.  This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would al…

Fix: 2.1.0+
Fix from $2,300 2025-06-06
Inlong CRITICAL 9.1
CVE-2025-27528

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability …

Fix: 2.2.0+
Fix from $2,300 2025-05-28