Vulnerability index

Browse CVEs

130 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Airflow MEDIUM 6.5
CVE-2026-65017

Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled mult…

Fix: 3.3.1+
Fix from $4,000 2026-08-12
Tapestry HIGH 7.5
CVE-2026-61899

Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs. Us…

No fix yet
Fix from $4,900 2026-08-10
Answer HIGH 7.5
CVE-2026-60023

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Deleted…

Fix: 2.0.2+
Fix from $1,950 2026-08-05
Traffic Server HIGH 8.7
CVE-2026-58157

Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections. This issue affects Apache Traffic S…

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Airflow MEDIUM 6.5
CVE-2026-48828

The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (…

Fix: 3.3.0+
Fix from $1,600 2026-07-07
Airflow MEDIUM 6.5
CVE-2026-48892

The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` …

Fix: 3.3.0+
Fix from $1,600 2026-07-07
Airflow MEDIUM 6.5
CVE-2026-49487

In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When …

Fix: 3.3.0+
Fix from $1,600 2026-07-07
Camel HIGH 7.5
CVE-2026-55994

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…

Fix: 4.18.3 / 4.21.0+
Fix from $1,950 2026-07-06
Camel HIGH 7.5
CVE-2026-55993

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel HIGH 7.5
CVE-2026-46726

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Dolphinscheduler MEDIUM 6.5
CVE-2026-47340

Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. …

Fix: 3.4.2+
Fix from $1,600 2026-06-17
Answer MEDIUM 6.5
CVE-2026-34905

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unl…

Fix: 2.0.1+
Fix from $1,600 2026-06-09
Airflow MEDIUM 6.5
CVE-2026-42360

A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` / `token` / `secret` / `api_ke…

Fix: 3.2.2+
Fix from $1,600 2026-06-01
Airflow MEDIUM 6.5
CVE-2026-42358

A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names like `password`, `token`, `sec…

Fix: 3.2.2+
Fix from $1,600 2026-06-01
Airflow MEDIUM 6.5
CVE-2026-45192

A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed an authenticated UI/API user with Connection-read …

Fix: 3.2.2+
Fix from $1,600 2026-06-01
Ofbiz HIGH 7.5
CVE-2026-31909

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users a…

Fix: 24.09.06+
Fix from $1,950 2026-05-19
Tomcat HIGH 7.3
CVE-2026-42498

Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache…

Fix: 9.0.118 / 10.1.55+
Fix from $1,950 2026-05-12
Cloudstack CRITICAL 9.1
CVE-2026-25199

Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudSt…

Fix: 4.22.0.1+
Fix from $2,300 2026-05-08
Wicket HIGH 7.5
CVE-2026-43646

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17…

Fix: 10.9.0+
Fix from $1,950 2026-05-06
Airflow MEDIUM 6.5
CVE-2026-25219

The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read p…

Fix: 3.2.0+
Fix from $1,600 2026-04-15
Dolphinscheduler HIGH 7.5
CVE-2025-62188

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vulnerability may allow unauthor…

Fix: 3.2.0+
Fix from $1,950 2026-04-09
Superset MEDIUM 6.5
CVE-2026-23983

A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoi…

Fix: 6.0.0+
Fix from $1,600 2026-02-24
Airflow MEDIUM 6.5
CVE-2026-24098

Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view impo…

Fix: 3.1.7+
Fix from $1,600 2026-02-09
Airflow HIGH 7.5
CVE-2025-68438

In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length, sensitive values could be e…

Fix: 3.1.6+
Fix from $1,950 2026-01-16
Cloudstack HIGH 8.1
CVE-2025-26521

When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the API key and the secret key of the 'kubeadmin' user of…

Fix: 4.19.3.0 / 4.20.1.0+
Fix from $1,950 2025-06-10
Iotdb HIGH 7.5
CVE-2025-26864

Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of…

Fix: 1.3.4+
Fix from $1,950 2025-05-14
Iotdb HIGH 7.5
CVE-2025-26795

Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC drive…

Fix: 1.3.4 / 2.0.2+
Fix from $1,950 2025-05-14
Commons Vfs MEDIUM 5.0
CVE-2025-30474

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when …

Fix: 2.10.0+
Fix from $1,600 2025-03-23
Hertzbeat HIGH 7.5
CVE-2024-45791

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: before 1.6.1. Us…

Fix: 1.6.1+
Fix from $1,950 2024-11-18
Maven Archetype HIGH 7.5
CVE-2024-47197

Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin. This …

Mitigation only
Fix from $1,950 2024-09-26