Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-44930 An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certi… Cxf 3.6.11 / 4.1.6+ Fix from $2,3002026-05-22 CRITICAL 9.8 CVE-2026-48207 Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks dur… Fory 1.0.0+ Fix from $2,3002026-05-21 CRITICAL 9.8 CVE-2026-47323 Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStrategy implementations (CxfRsHe… Camel 4.14.6 / 4.18.2+ Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-45434EPSS 22% Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBi… Ofbiz 24.09.06+ Fix from $2,3002026-05-19 CRITICAL 9.1 CVE-2026-31986 Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgra… Ofbiz 24.09.06+ Fix from $2,3002026-05-19 CRITICAL 9.1 CVE-2026-41919 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz:… Ofbiz 24.09.06+ Fix from $2,3002026-05-19 CRITICAL 9.1 CVE-2026-43515 Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affe… Tomcat 9.0.118 / 10.1.55+ Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-41293 Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 1… Tomcat 9.0.118 / 10.1.55+ Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-43512 DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 t… Tomcat 9.0.118 / 10.1.55+ Fix from $2,3002026-05-12 CRITICAL 9.1 CVE-2026-25199 Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudSt… Cloudstack 4.22.0.1+ Fix from $2,3002026-05-08 CRITICAL 9.1 CVE-2026-40010 Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache … Wicket 10.9.0+ Fix from $2,3002026-05-06 CRITICAL 9.8 CVE-2026-28780 Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server … HTTP Server 2.4.67+ Fix from $2,3002026-05-05 CRITICAL 9.9 CVE-2026-42809 Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been val… Polaris 1.4.1+ Fix from $2,3002026-05-04 CRITICAL 9.9 CVE-2026-42810 Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table acc… Polaris 1.4.1+ Fix from $2,3002026-05-04 CRITICAL 9.9 CVE-2026-42811 In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or tabl… Polaris 1.4.1+ Fix from $2,3002026-05-04 CRITICAL 9.9 CVE-2026-42812 In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to re… Polaris 1.4.1+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-42027 Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M… Opennlp 2.5.9+ Fix from $2,3002026-05-04 CRITICAL 9.1 CVE-2026-40682 XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0… Opennlp 2.5.9+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-42778 The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 i… Mina 2.1.12 / 2.2.7+ Fix from $2,3002026-05-01 CRITICAL 9.8 CVE-2026-42779 The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: Apache MINA's Abstrac… Mina 2.1.12 / 2.2.7+ Fix from $2,3002026-05-01 CRITICAL 9.8 CVE-2026-41873 ** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading t… Pony Mail Mitigation only Fix from $2,3002026-04-28 CRITICAL 10.0 CVE-2026-33453EPSS 6% Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's ca… Camel after 4.14.5 Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-41409 The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized … Mina 2.0.28 / 2.1.11+ Fix from $2,3002026-04-27 CRITICAL 9.4 CVE-2026-33454 The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterSt… Camel 4.14.6 / 4.18.1+ Fix from $2,3002026-04-27 CRITICAL 9.9 CVE-2026-40453 The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable… Camel 4.14.6 / 4.18.2+ Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-40860 JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessa… Camel 4.14.7 / 4.18.2+ Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-41635 Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at … Mina 2.0.28 / 2.1.11+ Fix from $2,3002026-04-27 CRITICAL 9.1 CVE-2026-33557 A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set… Kafka 4.1.2+ Fix from $2,3002026-04-20 CRITICAL 9.1 CVE-2026-31908 Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious… Apisix 3.16.0+ Fix from $2,3002026-04-14 CRITICAL 9.1 CVE-2026-29145 CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Nati… Tomcat 1.3.7 / 2.0.14+ Fix from $2,3002026-04-09