Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2026-73240
Specifically crafted inputs may lead to git argument injection in Apache Allura.
This issue affects Apache Allura: before 1.19.1.
Users are recomme…
Allura
1.19.1+
CRITICAL 9.1
CVE-2026-71290
Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effe…
Httpclient
5.6.4+
CRITICAL 9.1
CVE-2026-69223
Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF).
This issue affects Apache Allura: before 1.19.1.
Users are recommend…
Allura
1.19.1+
CRITICAL 9.8
CVE-2026-32227
SQL Injection vulnerability vulnerability in Apache Ranger.
This issue affects .
Users are recommended to upgrade to version 2.9.0, which fixes the…
Ranger
2.9.0+
CRITICAL 9.8
CVE-2026-40920
Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0.
Users are recommended to upgrade to version 2.9.0, which fixe…
Ranger
2.9.0+
CRITICAL 9.8
CVE-2026-42537
Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0
Users are recommended to upgrade to version 2.9.0, which fixes this issue.
Ranger
2.9.0+
CRITICAL 9.8
CVE-2026-44416
Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0.
Users are recommended to upgra…
Ranger
2.9.0+
CRITICAL 9.8
CVE-2026-55799
Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0
Users are recommended to upgrade to version 2.9.0, which fi…
Ranger
2.9.0+
CRITICAL 9.8
CVE-2026-28672
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger.
This issue affects Apache Ranger…
Ranger
after 2.8.0
CRITICAL 9.8
CVE-2026-71558
Heap type confusion vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafte…
Fory
1.5.0+
CRITICAL 9.1
CVE-2026-71560
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deser…
Fory
1.5.0+
CRITICAL 9.1
CVE-2026-32327
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources an…
Apr Util
1.6.4+
CRITICAL 9.1
CVE-2026-34191
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_ora…
Apr Util
after 1.6.3
CRITICAL 9.8
CVE-2026-68079
In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the im…
Cxf
3.6.12 / 4.1.8+
CRITICAL 9.1
CVE-2026-61466
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client reg…
Cxf
3.6.12 / 4.1.8+
CRITICAL 9.1
CVE-2026-63687
Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensiti…
Cxf
3.6.12 / 4.1.8+
CRITICAL 9.1
CVE-2026-65583
Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/…
Cxf
3.6.12 / 4.1.8+
CRITICAL 9.8
CVE-2026-66909
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in pla…
Cxf
3.6.12 / 4.1.8+
CRITICAL 9.1
CVE-2026-60053
Insufficient Session Expiration vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
Administrative API keys remained u…
Answer
2.0.2+
CRITICAL 9.8
CVE-2026-61484
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy.
This issue affects Apache Lucy: all versions.
As th…
Lucy
Mitigation only
CRITICAL 9.8
CVE-2026-61486
** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy.
This issue affects Apache Lucy: all versions.
As this pro…
Lucy
No fix yet
CRITICAL 9.1
CVE-2026-68980
Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framewor…
Nifi
2.11.0+
CRITICAL 9.8
CVE-2026-68979
Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components refer…
Nifi
2.11.0+
CRITICAL 9.8
CVE-2026-66756
Improper Protection of Alternate Path vulnerability in Apache Tika.
This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1.
Users a…
Tika
No fix yet
CRITICAL 9.8
CVE-2026-52680
Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote …
Kyuubi
1.12.0+
CRITICAL 9.8
CVE-2026-28812
UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges.
Users are recommende…
Jspwiki
2.12.4+
CRITICAL 9.8
CVE-2026-59243
The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or…
Apache Airflow Providers Fab
3.7.3+
CRITICAL 9.8
CVE-2026-58185
The Apache Traffic Server intercept plugin has a use-after-free.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 thro…
Traffic Server
9.2.15 / 10.1.4+
CRITICAL 9.8
CVE-2026-58177
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors.
This issue affects Apache Traffic Se…
Traffic Server
10.1.4+
CRITICAL 9.8
CVE-2026-58179
The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input.
This issue affects Apache Traffic Server: fro…
Traffic Server
9.2.15 / 10.1.4+