Vulnerability index

Browse CVEs

258 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2026-49434 Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to publish or m… Activemq 5.19.8 / 6.2.7+ Fix from $1,9502026-06-30 HIGH 8.8 CVE-2026-39998 Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to spoof i… Apisix 3.17.0+ Fix from $1,9502026-06-19 HIGH 8.1 CVE-2026-50632 A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, whi… Cxf 4.1.7 / 4.2.2+ Fix from $1,9502026-06-12 HIGH 8.1 CVE-2026-50633 A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able… Cxf 4.1.7 / 4.2.2+ Fix from $1,9502026-06-12 CRITICAL 9.8 CVE-2026-50628 A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other… Cxf 4.1.7 / 4.2.2+ Fix from $2,3002026-06-12 HIGH 7.5 CVE-2026-47430 ## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body to `commandDelegate sendPlugi… Cordova Inappbrowser 6.0.1+ Fix from $1,9502026-06-08 HIGH 8.8 CVE-2026-45505 Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap… Activemq 5.19.7 / 6.2.6+ Fix from $1,9502026-06-01 HIGH 8.1 CVE-2026-42588 Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap… Activemq 5.19.7 / 6.2.6+ Fix from $1,9502026-06-01 HIGH 7.5 CVE-2026-44417 The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lea… Cxf 3.6.11 / 4.1.6+ Fix from $1,9502026-05-22 MEDIUM 6.5 CVE-2026-31378 Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to vers… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 CRITICAL 9.8 CVE-2026-41293 Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 1… Tomcat 9.0.118 / 10.1.55+ Fix from $2,3002026-05-12 CRITICAL 9.9 CVE-2026-42809 Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been val… Polaris 1.4.1+ Fix from $2,3002026-05-04 CRITICAL 9.9 CVE-2026-42810 Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table acc… Polaris 1.4.1+ Fix from $2,3002026-05-04 CRITICAL 9.9 CVE-2026-42811 In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or tabl… Polaris 1.4.1+ Fix from $2,3002026-05-04 CRITICAL 9.9 CVE-2026-42812 In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to re… Polaris 1.4.1+ Fix from $2,3002026-05-04 HIGH 8.8 CVE-2026-40466 Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap… Activemq 5.19.6 / 6.2.5+ Fix from $1,9502026-04-24 HIGH 8.8 CVE-2026-41044 Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache… Activemq 5.19.6 / 6.2.5+ Fix from $1,9502026-04-24 MEDIUM 5.3 CVE-2026-32990 Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 … Tomcat 9.0.116 / 10.1.53+ Fix from $1,6002026-04-09 HIGH 8.8 CVE-2026-34197 KEVEPSS 97% Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apach… Activemq 5.19.4 / 6.2.3+ Fix from $1,9502026-04-07 MEDIUM 6.3 CVE-2025-60012 Malicious configuration can lead to unauthorized file access in Apache Livy. This issue affects Apache Livy 0.7.0 and 0.8.0 when connecting to Apach… Livy 0.9.0+ Fix from $1,6002026-03-13 CRITICAL 9.8 CVE-2026-24713 Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users a… Iotdb 1.3.7 / 2.0.7+ Fix from $2,3002026-03-09 HIGH 7.5 CVE-2026-24734 Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port o… Tomcat 1.3.5 / 2.0.12+ Fix from $1,9502026-02-17 CRITICAL 9.1 CVE-2025-66614 Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.… Tomcat 9.0.113 / 10.1.50+ Fix from $2,3002026-02-17 HIGH 7.1 CVE-2026-22444 The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient input validation on some API parameters, which can cause Solr to check the e… Solr 9.10.1+ Fix from $1,9502026-01-21 HIGH 7.5 CVE-2025-29847 A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and data source functionality, if… Linkis 1.8.0+ Fix from $1,9502026-01-19 HIGH 8.8 CVE-2024-43115 Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This… Dolphinscheduler 3.2.2+ Fix from $1,9502025-09-03 CRITICAL 9.8 CVE-2025-48913 If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution cap… Cxf 3.6.8 / 4.0.9+ Fix from $2,3002025-08-08 MEDIUM 5.3 CVE-2024-52279 Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not account for URL encoded input. … Zeppelin 0.12.0+ Fix from $1,6002025-08-03 HIGH 8.8 CVE-2025-50151 File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to… Jena 5.5.0+ Fix from $1,9502025-07-21 HIGH 7.5 CVE-2024-42516 HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hos… HTTP Server 2.4.64+ Fix from $1,9502025-07-10