Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Struts HIGH 7.5
CVE-2026-73634

Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violatio…

Fix unknown
Fix from $4,900 2026-08-15
Struts HIGH 7.5
CVE-2026-73635

Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localize…

Fix unknown
Fix from $4,900 2026-08-15
Struts HIGH 7.5
CVE-2026-73633

Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSO…

No fix yet
Fix from $4,900 2026-08-14
Allura CRITICAL 9.8
CVE-2026-73240

Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recomme…

No fix yet
Fix from $5,750 2026-08-12
Allura MEDIUM 6.5
CVE-2026-73239

Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache All…

No fix yet
Fix from $4,000 2026-08-12
Allura MEDIUM 6.1
CVE-2026-73238

XSS vulnerability in code display in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.…

No fix yet
Fix from $4,000 2026-08-12
Allura MEDIUM 6.1
CVE-2026-73237

XSS vulnerability in Markdown handling in Apache Allura. This issue affects Apache Allura: from 1.10.0 before 1.19.1. Users are recommended to upgr…

No fix yet
Fix from $4,000 2026-08-12
Airflow HIGH 7.5
CVE-2026-68968

Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. T…

Fix: 3.3.1+
Fix from $4,900 2026-08-12
Airflow MEDIUM 6.5
CVE-2026-68970

Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext i…

Fix: 3.3.1+
Fix from $4,000 2026-08-12
Airflow MEDIUM 6.5
CVE-2026-68969

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoint…

Fix: 3.3.1+
Fix from $4,000 2026-08-12
Airflow MEDIUM 6.5
CVE-2026-68971

Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finis…

Fix: 3.3.1+
Fix from $4,000 2026-08-12
Airflow HIGH 8.8
CVE-2026-67587

Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the store…

No fix yet
Fix from $4,900 2026-08-12
Airflow MEDIUM 5.4
CVE-2026-68076

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to p…

Fix: 3.3.1+
Fix from $4,000 2026-08-12
Airflow HIGH 7.3
CVE-2026-67260

Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deseria…

No fix yet
Fix from $4,900 2026-08-12
Airflow MEDIUM 6.5
CVE-2026-65017

Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled mult…

Fix: 3.3.1+
Fix from $4,000 2026-08-12
Airflow MEDIUM 6.5
CVE-2026-59244

Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an…

Fix: 3.3.1+
Fix from $4,000 2026-08-12
Airflow MEDIUM 5.4
CVE-2026-59242

Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_v…

Fix: 3.3.1+
Fix from $4,000 2026-08-12
Airflow HIGH 8.8
CVE-2026-58076

Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and in…

Fix: 3.3.1+
Fix from $4,900 2026-08-12
Apache Airflow Providers Google MEDIUM 6.5
CVE-2026-68868

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Varia…

No fix yet
Fix from $4,000 2026-08-12
Httpclient CRITICAL 9.1
CVE-2026-71290

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effe…

No fix yet
Fix from $5,750 2026-08-11
Allura CRITICAL 9.1
CVE-2026-69223

Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommend…

No fix yet
Fix from $5,750 2026-08-11
Apache Airflow Providers Amazon MEDIUM 6.5
CVE-2026-68872

The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variabl…

No fix yet
Fix from $4,000 2026-08-10
Apache Airflow Providers Apache Yandex MEDIUM 6.5
CVE-2026-68871

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic loo…

No fix yet
Fix from $4,000 2026-08-10
Tapestry HIGH 7.5
CVE-2026-61899

Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs. Us…

No fix yet
Fix from $4,900 2026-08-10
Ranger HIGH 7.5
CVE-2026-65942

TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes thi…

No fix yet
Fix from $4,900 2026-08-10
Ranger HIGH 7.3
CVE-2026-65948

UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:  UnixAuth is NOT a recommended option for production deployments.  U…

No fix yet
Fix from $4,900 2026-08-10
Ranger MEDIUM 6.5
CVE-2026-65945

Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.

No fix yet
Fix from $4,000 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-32227

SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the…

No fix yet
Fix from $5,750 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-40920

Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixe…

No fix yet
Fix from $5,750 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-42537

Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.

No fix yet
Fix from $5,750 2026-08-10