Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2025-57735 When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was inte… Airflow 3.2.0+ Fix from $2,3002026-04-09 CRITICAL 9.8 CVE-2026-24015 A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrad… Iotdb 1.3.7 / 2.0.7+ Fix from $2,3002026-03-09 CRITICAL 9.8 CVE-2026-24713 Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users a… Iotdb 1.3.7 / 2.0.7+ Fix from $2,3002026-03-09 CRITICAL 9.8 CVE-2026-27446EPSS 10% Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker c… Artemis after 2.44.0 Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2025-59059 Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to… Ranger 2.8.0+ Fix from $2,3002026-03-03 CRITICAL 9.1 CVE-2026-23552 Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.  The Camel-Keycloak KeycloakSecurityPolicy does not v… Camel 4.18.0+ Fix from $2,3002026-02-23 CRITICAL 9.1 CVE-2025-66614 Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.… Tomcat 9.0.113 / 10.1.50+ Fix from $2,3002026-02-17 CRITICAL 9.8 CVE-2026-23906 Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * d… Druid 36.0.0+ Fix from $2,3002026-02-10 CRITICAL 9.9 CVE-2016-15057 ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum… Continuum Mitigation only Fix from $2,3002026-01-26 CRITICAL 9.8 CVE-2025-60021EPSS 25% Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to … Brpc 1.15.0+ Fix from $2,3002026-01-16 CRITICAL 9.1 CVE-2025-68637 The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This insecure configuration expos… Uniffle 0.10.0+ Fix from $2,3002026-01-07 CRITICAL 9.8 CVE-2025-67895 Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on … Apache Airflow Providers Edge3 2.0.0+ Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2025-54947 In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs b… Streampark 2.1.7+ Fix from $2,3002025-12-12 CRITICAL 9.1 CVE-2025-58130 Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in ver… Fineract 1.12.1+ Fix from $2,3002025-12-12 CRITICAL 9.8 CVE-2025-66516EPSS 79% Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an a… Tika 3.2.2+ Fix from $2,3002025-12-04 CRITICAL 9.8 CVE-2025-59390 Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is… Druid 35.0.0+ Fix from $2,3002025-11-26 CRITICAL 9.6 CVE-2025-55754EPSS 10% Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log mes… Tomcat 9.0.109 / 10.0.27+ Fix from $2,3002025-10-27 CRITICAL 9.8 CVE-2025-54539 A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ … Activemq Nms Amqp 2.4.0+ Fix from $2,3002025-10-16 CRITICAL 9.8 CVE-2025-61622EPSS 41% Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows… Fory after 0.12.2 Fix from $2,3002025-10-01 CRITICAL 9.8 CVE-2024-43166 Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recomme… Dolphinscheduler 3.2.2+ Fix from $2,3002025-09-03 CRITICAL 9.8 CVE-2025-54466EPSS 15% Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects A… Ofbiz 24.09.02+ Fix from $2,3002025-08-15 CRITICAL 9.8 CVE-2025-53606 Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recomm… Seata Mitigation only Fix from $2,3002025-08-08 CRITICAL 9.8 CVE-2025-48913 If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution cap… Cxf 3.6.8 / 4.0.9+ Fix from $2,3002025-08-08 CRITICAL 9.1 CVE-2025-23048 In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 … HTTP Server 2.4.64+ Fix from $2,3002025-07-10 CRITICAL 9.8 CVE-2025-32897 Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the ver… Seata 2.3.0+ Fix from $2,3002025-06-28 CRITICAL 9.8 CVE-2025-50213 Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This is… Apache Airflow Providers Snowflake 6.4.0+ Fix from $2,3002025-06-24 CRITICAL 9.8 CVE-2025-47868 Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that… Nuttx 12.9.0+ Fix from $2,3002025-06-16 CRITICAL 9.8 CVE-2025-47869 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability was discovered in Apache NuttX RTOS apps/exapmles/xmlrpc applic… Nuttx 12.9.0+ Fix from $2,3002025-06-16 CRITICAL 9.8 CVE-2025-27531 Deserialization of Untrusted Data vulnerability in Apache InLong.  This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would al… Inlong 2.1.0+ Fix from $2,3002025-06-06 CRITICAL 9.1 CVE-2025-27528 Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability … Inlong 2.2.0+ Fix from $2,3002025-05-28