Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2026-58163
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing.
This issue affects Apache Traffic Server: …
Traffic Server
9.2.15 / 10.1.4+
CRITICAL 10.0
CVE-2026-58162
The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI.
This issue affects Apache Traffic Server:…
Traffic Server
9.2.15 / 10.1.4+
CRITICAL 9.3
CVE-2026-58155
Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass.
This issue affects Apache Tr…
Traffic Server
9.2.15 / 10.1.4+
CRITICAL 10.0
CVE-2026-57834
Apache Traffic Server allows request smuggling if chunked messages are malformed.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9…
Traffic Server
9.2.15 / 10.1.4+
CRITICAL 10.0
CVE-2026-58150
Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling.
This issue affects Apache Traffic …
Traffic Server
9.2.15 / 10.1.4+
CRITICAL 9.3
CVE-2026-41920
Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 thr…
Traffic Server
9.2.15 / 10.1.4+
CRITICAL 9.1
CVE-2026-33267
Improper Input Validation vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 t…
Traffic Server
9.2.15 / 10.1.4+
CRITICAL 9.8
CVE-2026-66713
Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component
in Apache Software Foundation Apache Axis2/Java through 2.0.0…
Axis2\/java
2.0.1+
CRITICAL 9.8
CVE-2026-55971
Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to u…
Thrift
0.24.0+
CRITICAL 9.1
CVE-2026-58023
Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrad…
Thrift
0.24.0+
CRITICAL 9.1
CVE-2026-58662
Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift…
Thrift
0.24.0+
CRITICAL 9.1
CVE-2026-48144
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.24.…
Thrift
0.24.0+
CRITICAL 9.8
CVE-2026-64606
Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lamb…
Fory
1.4.0+
CRITICAL 9.1
CVE-2026-64609
Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the b…
Fory
1.4.0+
CRITICAL 9.8
CVE-2026-64608
Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip pa…
Fory
1.4.0+
CRITICAL 9.8
CVE-2026-63071
Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements for Implementations can crea…
Syncope
4.0.7 / 4.1.2+
CRITICAL 9.8
CVE-2026-57308
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope.
An administrator with adequate…
Syncope
4.0.7 / 4.1.2+
CRITICAL 9.8
CVE-2026-62183
Improper Privilege Management vulnerability in Apache Syncope.
When:
* the all-Java user workflow adapter is configured, or
* the Flowable user wor…
Syncope
4.0.7 / 4.1.2+
CRITICAL 9.8
CVE-2026-53421
Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements can achieve remote code ex…
Syncope
4.0.7 / 4.1.2+
CRITICAL 9.8
CVE-2026-53405
Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements can import arbitrary BPMN pr…
Syncope
4.0.7 / 4.1.2+
CRITICAL 9.8
CVE-2026-62390
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table ca…
Kylin
5.0.4+
CRITICAL 9.8
CVE-2026-62392
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job…
Kylin
5.0.4+
CRITICAL 9.1
CVE-2026-58319
Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access …
Doris
3.1.0+
CRITICAL 9.1
CVE-2026-59083
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configura…
Tomcat
after 11.0.23
CRITICAL 9.1
CVE-2026-59084
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clea…
Tomcat
after 11.0.23
CRITICAL 9.1
CVE-2026-41041
URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino.
This issue affects Apache Gravitino: from 1.0.0 before…
Gravitino
1.2.1+
CRITICAL 9.8
CVE-2026-33264
A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server …
Airflow
3.3.0+
CRITICAL 9.8
CVE-2026-56140
Improper Input Validation vulnerability in Apache Camel AWS SNS component.
The camel-aws2-sns component filters Camel headers through a component-s…
Camel
4.14.8 / 4.18.3+
CRITICAL 9.8
CVE-2026-53913
Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak C…
Camel
4.18.3 / 4.21.0+
CRITICAL 9.8
CVE-2026-48204
Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component.
The camel-mongodb-gridfs produce…
Camel
4.14.8 / 4.18.3+