Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2026-48203
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Fo…
Camel
4.14.8 / 4.18.3+
CRITICAL 9.1
CVE-2026-48205
Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component.
The camel-dns producers read DNS operatio…
Camel
4.14.8 / 4.18.3+
CRITICAL 9.8
CVE-2026-43867
Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component.
The camel-pqc component persists post-quantum key metadata (KeyMetada…
Camel
4.18.3 / 4.21.0+
CRITICAL 9.8
CVE-2026-46454
Improper Input Validation vulnerability in Apache Camel Cometd Component.
The camel-cometd component maps inbound Bayeux (CometD) message headers in…
Camel
4.14.8 / 4.18.3+
CRITICAL 9.8
CVE-2026-46455
Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component.
The camel-keycloak security helper KeycloakSecurityHelper.parseAnd…
Camel
4.18.3 / 4.21.0+
CRITICAL 9.8
CVE-2026-46456
Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component.
The camel-aws2-sqs component map inbound message attributes into the Ca…
Camel
4.14.8 / 4.18.3+
CRITICAL 9.8
CVE-2026-24014
Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without suffici…
Iotdb
2.0.8+
CRITICAL 9.1
CVE-2026-24013
Authentication Bypass by Spoofing vulnerability in Apache IoTDB.
Certain Thrift RPC query handlers lack strict validation of the sessionId
parameter.…
Iotdb
2.0.8+
CRITICAL 9.1
CVE-2026-40047
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component.
The camel-doclin…
Camel
4.18.3+
CRITICAL 9.8
CVE-2026-47898
Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library).
This issue affects Ap…
Lucene.net
Mitigation only
CRITICAL 9.1
CVE-2026-55276
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not inc…
Tomcat
9.0.119 / 10.1.56+
CRITICAL 9.1
CVE-2026-53434
Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.
This issue affects Apach…
Tomcat
9.0.119 / 10.1.56+
CRITICAL 9.3
CVE-2026-49871
Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations.
This defect allows a remote attacker that manag…
Apisix
3.17.0+
CRITICAL 9.1
CVE-2026-49230
Improper Validation of Integrity Check Value vulnerability in Apache APISIX.
The jwe-decrypt plugin under default configuration is vulnerable to aut…
Apisix
3.17.0+
CRITICAL 9.1
CVE-2026-44087
Insufficient Verification of Data Authenticity vulnerability in Apache APISIX.
The openid-connect plugin under default configuration has an attack s…
Apisix
3.17.0+
CRITICAL 9.1
CVE-2026-39999
Authentication Bypass by Spoofing vulnerability in Apache APISIX.
The attacker can completely bypass authentication capitalising on certain configur…
Apisix
3.17.0+
CRITICAL 9.1
CVE-2026-49268
A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username …
Shiro
2.2.1+
CRITICAL 9.1
CVE-2026-50203
A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP serv…
Apache Airflow Providers Sftp
5.8.1+
CRITICAL 9.8
CVE-2026-32966
DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler.
This issue affects Apache …
Dolphinscheduler
3.4.2+
CRITICAL 9.1
CVE-2026-32967
Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler.
This issue affects Apache DolphinScheduler: before…
Dolphinscheduler
3.4.2+
CRITICAL 9.8
CVE-2026-49875
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configuration…
Cxf
4.1.7 / 4.2.2+
CRITICAL 9.8
CVE-2026-50628
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other…
Cxf
4.1.7 / 4.2.2+
CRITICAL 9.1
CVE-2026-50627
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued…
Cxf
4.1.7 / 4.2.2+
CRITICAL 9.8
CVE-2026-44631
Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.
This issue affects Apache HTTP Server: fr…
HTTP Server
2.4.68+
CRITICAL 9.1
CVE-2026-42535
A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases…
HTTP Server
2.4.68+
CRITICAL 9.8
CVE-2026-29167
Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration
This issue affects Apache HTTP Server: from 2.4.0 th…
HTTP Server
2.4.68+
CRITICAL 9.1
CVE-2026-50076
Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remo…
Fory
1.1.0+
CRITICAL 9.8
CVE-2026-47065
ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy
Assessment: Fully addressed.
When the seri…
Mina
Mitigation only
CRITICAL 9.8
CVE-2026-44825
Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a …
Solr
after 9.10.1
CRITICAL 9.1
CVE-2026-42252
Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a verbatim `BashOperator(b…
Airflow
3.2.2+