Vulnerability index

Browse CVEs

258 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
CRITICAL 9.8 CVE-2026-40920 Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixe… Ranger No fix yet Fix from $5,7502026-08-10 CRITICAL 9.8 CVE-2026-42537 Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. Ranger No fix yet Fix from $5,7502026-08-10 HIGH 8.1 CVE-2026-57817 The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache C… Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-58183 The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apache Traffic Server: from 8.0.0 … Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-58186 The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Ser… Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 CRITICAL 9.1 CVE-2026-33267 Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 t… Traffic Server 9.2.15 / 10.1.4+ Fix from $2,3002026-07-29 HIGH 7.5 CVE-2026-59878 Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthenticated peer that can reach … Activemq 5.19.9 / 6.2.8+ Fix from $1,9502026-07-28 MEDIUM 5.3 CVE-2026-46452 Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken data toward application resultin… Nimble 1.10.0+ Fix from $1,6002026-07-24 MEDIUM 5.4 CVE-2026-58624 Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.… Mina Sshd 2.19.0+ Fix from $1,6002026-07-20 HIGH 7.3 CVE-2026-49042 Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: from 4.8.0 through 4.18.2, from 4.19.0 through 4.20.0. Us… Camel 4.18.3 / 4.21.0+ Fix from $1,9502026-07-06 HIGH 7.3 CVE-2026-46587 Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 th… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 HIGH 7.3 CVE-2026-46588 Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 th… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 CRITICAL 9.8 CVE-2026-56140 Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns component filters Camel headers through a component-s… Camel 4.14.8 / 4.18.3+ Fix from $2,3002026-07-06 HIGH 7.5 CVE-2026-55994 Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam… Camel 4.18.3 / 4.21.0+ Fix from $1,9502026-07-06 HIGH 7.5 CVE-2026-55993 Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 MEDIUM 6.5 CVE-2026-49086 Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel DAPR component. The camel-dapr Dapr Pu… Camel 4.14.8 / 4.18.3+ Fix from $1,6002026-07-06 MEDIUM 6.5 CVE-2026-49097 Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache… Camel 4.14.8 / 4.18.3+ Fix from $1,6002026-07-06 MEDIUM 5.3 CVE-2026-48206 Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel JIRA component. The camel-jira producers r… Camel 4.14.8 / 4.18.3+ Fix from $1,6002026-07-06 MEDIUM 5.3 CVE-2026-49098 Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache… Camel 4.14.8 / 4.18.3+ Fix from $1,6002026-07-06 CRITICAL 9.8 CVE-2026-48204 Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs produce… Camel 4.14.8 / 4.18.3+ Fix from $2,3002026-07-06 CRITICAL 9.1 CVE-2026-48203 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Fo… Camel 4.14.8 / 4.18.3+ Fix from $2,3002026-07-06 CRITICAL 9.1 CVE-2026-48205 Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. The camel-dns producers read DNS operatio… Camel 4.14.8 / 4.18.3+ Fix from $2,3002026-07-06 HIGH 7.5 CVE-2026-46585 Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Component. The camel-lucene produce… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 HIGH 7.5 CVE-2026-46592 Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF SOAP component. The camel-cxf prod… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 HIGH 7.5 CVE-2026-46726 Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 CRITICAL 9.8 CVE-2026-46454 Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeux (CometD) message headers in… Camel 4.14.8 / 4.18.3+ Fix from $2,3002026-07-06 CRITICAL 9.8 CVE-2026-46456 Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs component map inbound message attributes into the Ca… Camel 4.14.8 / 4.18.3+ Fix from $2,3002026-07-06 HIGH 7.5 CVE-2026-46457 Improper Input Validation vulnerability in Apache Camel NATS component. The camel-nats component maps inbound NATS message headers into the Camel Ex… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 MEDIUM 5.3 CVE-2026-46453 Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel ElasticSearch Rest Client. The camel-elast… Camel 4.14.8 / 4.18.3+ Fix from $1,6002026-07-06 HIGH 7.5 CVE-2026-49432 Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. A remote unauthenticated peer that can reach… Activemq 5.19.8 / 6.2.7+ Fix from $1,9502026-06-30