Vulnerability index

Browse CVEs

258 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Activemq HIGH 7.5
CVE-2026-49434

Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to publish or m…

Fix: 5.19.8 / 6.2.7+
Fix from $1,950 2026-06-30
Apisix HIGH 8.8
CVE-2026-39998

Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to spoof i…

Fix: 3.17.0+
Fix from $1,950 2026-06-19
Cxf HIGH 8.1
CVE-2026-50632

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, whi…

Fix: 4.1.7 / 4.2.2+
Fix from $1,950 2026-06-12
Cxf HIGH 8.1
CVE-2026-50633

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able…

Fix: 4.1.7 / 4.2.2+
Fix from $1,950 2026-06-12
Cxf CRITICAL 9.8
CVE-2026-50628

A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other…

Fix: 4.1.7 / 4.2.2+
Fix from $2,300 2026-06-12
Cordova Inappbrowser HIGH 7.5
CVE-2026-47430

## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body to `commandDelegate sendPlugi…

Fix: 6.0.1+
Fix from $1,950 2026-06-08
Activemq HIGH 8.8
CVE-2026-45505

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap…

Fix: 5.19.7 / 6.2.6+
Fix from $1,950 2026-06-01
Activemq HIGH 8.1
CVE-2026-42588

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap…

Fix: 5.19.7 / 6.2.6+
Fix from $1,950 2026-06-01
Cxf HIGH 7.5
CVE-2026-44417

The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lea…

Fix: 3.6.11 / 4.1.6+
Fix from $1,950 2026-05-22
Ofbiz MEDIUM 6.5
CVE-2026-31378

Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to vers…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Tomcat CRITICAL 9.8
CVE-2026-41293

Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 1…

Fix: 9.0.118 / 10.1.55+
Fix from $2,300 2026-05-12
Polaris CRITICAL 9.9
CVE-2026-42809

Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been val…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Polaris CRITICAL 9.9
CVE-2026-42810

Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table acc…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Polaris CRITICAL 9.9
CVE-2026-42811

In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or tabl…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Polaris CRITICAL 9.9
CVE-2026-42812

In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to re…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Activemq HIGH 8.8
CVE-2026-40466

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap…

Fix: 5.19.6 / 6.2.5+
Fix from $1,950 2026-04-24
Activemq HIGH 8.8
CVE-2026-41044

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache…

Fix: 5.19.6 / 6.2.5+
Fix from $1,950 2026-04-24
Tomcat MEDIUM 5.3
CVE-2026-32990

Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 …

Fix: 9.0.116 / 10.1.53+
Fix from $1,600 2026-04-09
Activemq HIGH 8.8
CVE-2026-34197 KEVEPSS 97%

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apach…

Fix: 5.19.4 / 6.2.3+
Fix from $1,950 2026-04-07
Livy MEDIUM 6.3
CVE-2025-60012

Malicious configuration can lead to unauthorized file access in Apache Livy. This issue affects Apache Livy 0.7.0 and 0.8.0 when connecting to Apach…

Fix: 0.9.0+
Fix from $1,600 2026-03-13
Iotdb CRITICAL 9.8
CVE-2026-24713

Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users a…

Fix: 1.3.7 / 2.0.7+
Fix from $2,300 2026-03-09
Tomcat HIGH 7.5
CVE-2026-24734

Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port o…

Fix: 1.3.5 / 2.0.12+
Fix from $1,950 2026-02-17
Tomcat CRITICAL 9.1
CVE-2025-66614

Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.…

Fix: 9.0.113 / 10.1.50+
Fix from $2,300 2026-02-17
Solr HIGH 7.1
CVE-2026-22444

The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient input validation on some API parameters, which can cause Solr to check the e…

Fix: 9.10.1+
Fix from $1,950 2026-01-21
Linkis HIGH 7.5
CVE-2025-29847

A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and data source functionality, if…

Fix: 1.8.0+
Fix from $1,950 2026-01-19
Dolphinscheduler HIGH 8.8
CVE-2024-43115

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This…

Fix: 3.2.2+
Fix from $1,950 2025-09-03
Cxf CRITICAL 9.8
CVE-2025-48913

If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution cap…

Fix: 3.6.8 / 4.0.9+
Fix from $2,300 2025-08-08
Zeppelin MEDIUM 5.3
CVE-2024-52279

Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not account for URL encoded input. …

Fix: 0.12.0+
Fix from $1,600 2025-08-03
Jena HIGH 8.8
CVE-2025-50151

File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to…

Fix: 5.5.0+
Fix from $1,950 2025-07-21
HTTP Server HIGH 7.5
CVE-2024-42516

HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hos…

Fix: 2.4.64+
Fix from $1,950 2025-07-10