Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2026-65017
Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled mult…
Airflow
3.3.1+
HIGH 7.5
CVE-2026-61899
Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs.
Us…
Tapestry
No fix yet
HIGH 7.5
CVE-2026-60023
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
Deleted…
Answer
2.0.2+
HIGH 8.7
CVE-2026-58157
Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections.
This issue affects Apache Traffic S…
Traffic Server
9.2.15 / 10.1.4+
MEDIUM 6.5
CVE-2026-48828
The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (…
Airflow
3.3.0+
MEDIUM 6.5
CVE-2026-48892
The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` …
Airflow
3.3.0+
MEDIUM 6.5
CVE-2026-49487
In Apache Airflow before 3.3.0, the REST API task-instance detail and list
endpoints returned a deferred task's trigger kwargs without masking. When …
Airflow
3.3.0+
HIGH 7.5
CVE-2026-55994
Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…
Camel
4.18.3 / 4.21.0+
HIGH 7.5
CVE-2026-55993
Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…
Camel
4.14.8 / 4.18.3+
HIGH 7.5
CVE-2026-46726
Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…
Camel
4.14.8 / 4.18.3+
MEDIUM 6.5
CVE-2026-47340
Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler.
…
Dolphinscheduler
3.4.2+
MEDIUM 6.5
CVE-2026-34905
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
The unl…
Answer
2.0.1+
MEDIUM 6.5
CVE-2026-42360
A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` / `token` / `secret` / `api_ke…
Airflow
3.2.2+
MEDIUM 6.5
CVE-2026-42358
A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names like `password`, `token`, `sec…
Airflow
3.2.2+
MEDIUM 6.5
CVE-2026-45192
A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed an authenticated UI/API user with Connection-read …
Airflow
3.2.2+
HIGH 7.5
CVE-2026-31909
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users a…
Ofbiz
24.09.06+
HIGH 7.3
CVE-2026-42498
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat.
This issue affects Apache…
Tomcat
9.0.118 / 10.1.55+
CRITICAL 9.1
CVE-2026-25199
Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants.
This issue affects Apache CloudSt…
Cloudstack
4.22.0.1+
HIGH 7.5
CVE-2026-43646
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket.
This issue affects Apache Wicket: from 8.0.0 through 8.17…
Wicket
10.9.0+
MEDIUM 6.5
CVE-2026-25219
The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read p…
Airflow
3.2.0+
HIGH 7.5
CVE-2025-62188
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler.
This vulnerability may allow unauthor…
Dolphinscheduler
3.2.0+
MEDIUM 6.5
CVE-2026-23983
A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoi…
Superset
6.0.0+
MEDIUM 6.5
CVE-2026-24098
Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view impo…
Airflow
3.1.7+
HIGH 7.5
CVE-2025-68438
In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length, sensitive values could be e…
Airflow
3.1.6+
HIGH 8.1
CVE-2025-26521
When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the API key and the secret key of the 'kubeadmin' user of…
Cloudstack
4.19.3.0 / 4.20.1.0+
HIGH 7.5
CVE-2025-26864
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of…
Iotdb
1.3.4+
HIGH 7.5
CVE-2025-26795
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC drive…
Iotdb
1.3.4 / 2.0.2+
MEDIUM 5.0
CVE-2025-30474
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS.
The FtpFileObject class can throw an exception when …
Commons Vfs
2.10.0+
HIGH 7.5
CVE-2024-45791
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat.
This issue affects Apache HertzBeat: before 1.6.1.
Us…
Hertzbeat
1.6.1+
HIGH 7.5
CVE-2024-47197
Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin.
This …
Maven Archetype
Mitigation only