Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-73240 Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recomme… Allura 1.19.1+ Fix from $2,3002026-08-12 CRITICAL 9.1 CVE-2026-71290 Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effe… Httpclient 5.6.4+ Fix from $2,3002026-08-11 CRITICAL 9.1 CVE-2026-69223 Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommend… Allura 1.19.1+ Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-32227 SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the… Ranger 2.9.0+ Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-40920 Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixe… Ranger 2.9.0+ Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-42537 Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. Ranger 2.9.0+ Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-44416 Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgra… Ranger 2.9.0+ Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-55799 Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fi… Ranger 2.9.0+ Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-28672 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger… Ranger after 2.8.0 Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-71558 Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafte… Fory 1.5.0+ Fix from $2,3002026-08-07 CRITICAL 9.1 CVE-2026-71560 Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deser… Fory 1.5.0+ Fix from $2,3002026-08-07 CRITICAL 9.1 CVE-2026-32327 A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources an… Apr Util 1.6.4+ Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-34191 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_ora… Apr Util after 1.6.3 Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-68079 In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the im… Cxf 3.6.12 / 4.1.8+ Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-61466 In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client reg… Cxf 3.6.12 / 4.1.8+ Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-63687 Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensiti… Cxf 3.6.12 / 4.1.8+ Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-65583 Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/… Cxf 3.6.12 / 4.1.8+ Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-66909 Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in pla… Cxf 3.6.12 / 4.1.8+ Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-60053 Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained u… Answer 2.0.2+ Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-61484 ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As th… Lucy Mitigation only Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-61486 ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this pro… Lucy No fix yet Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-68980 Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framewor… Nifi 2.11.0+ Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-68979 Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components refer… Nifi 2.11.0+ Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-66756 Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users a… Tika No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-52680 Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote … Kyuubi 1.12.0+ Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-28812 UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommende… Jspwiki 2.12.4+ Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-59243 The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or… Apache Airflow Providers Fab 3.7.3+ Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-58185 The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 thro… Traffic Server 9.2.15 / 10.1.4+ Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-58177 The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Se… Traffic Server 10.1.4+ Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-58179 The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: fro… Traffic Server 9.2.15 / 10.1.4+ Fix from $2,3002026-07-29