Vulnerability index

Browse CVEs

130 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 6.5 CVE-2026-65017 Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled mult… Airflow 3.3.1+ Fix from $4,0002026-08-12 HIGH 7.5 CVE-2026-61899 Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs. Us… Tapestry No fix yet Fix from $4,9002026-08-10 HIGH 7.5 CVE-2026-60023 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Deleted… Answer 2.0.2+ Fix from $1,9502026-08-05 HIGH 8.7 CVE-2026-58157 Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections. This issue affects Apache Traffic S… Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 MEDIUM 6.5 CVE-2026-48828 The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (… Airflow 3.3.0+ Fix from $1,6002026-07-07 MEDIUM 6.5 CVE-2026-48892 The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` … Airflow 3.3.0+ Fix from $1,6002026-07-07 MEDIUM 6.5 CVE-2026-49487 In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When … Airflow 3.3.0+ Fix from $1,6002026-07-07 HIGH 7.5 CVE-2026-55994 Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam… Camel 4.18.3 / 4.21.0+ Fix from $1,9502026-07-06 HIGH 7.5 CVE-2026-55993 Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 HIGH 7.5 CVE-2026-46726 Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 MEDIUM 6.5 CVE-2026-47340 Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. … Dolphinscheduler 3.4.2+ Fix from $1,6002026-06-17 MEDIUM 6.5 CVE-2026-34905 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unl… Answer 2.0.1+ Fix from $1,6002026-06-09 MEDIUM 6.5 CVE-2026-42360 A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` / `token` / `secret` / `api_ke… Airflow 3.2.2+ Fix from $1,6002026-06-01 MEDIUM 6.5 CVE-2026-42358 A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names like `password`, `token`, `sec… Airflow 3.2.2+ Fix from $1,6002026-06-01 MEDIUM 6.5 CVE-2026-45192 A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed an authenticated UI/API user with Connection-read … Airflow 3.2.2+ Fix from $1,6002026-06-01 HIGH 7.5 CVE-2026-31909 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users a… Ofbiz 24.09.06+ Fix from $1,9502026-05-19 HIGH 7.3 CVE-2026-42498 Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache… Tomcat 9.0.118 / 10.1.55+ Fix from $1,9502026-05-12 CRITICAL 9.1 CVE-2026-25199 Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudSt… Cloudstack 4.22.0.1+ Fix from $2,3002026-05-08 HIGH 7.5 CVE-2026-43646 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17… Wicket 10.9.0+ Fix from $1,9502026-05-06 MEDIUM 6.5 CVE-2026-25219 The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read p… Airflow 3.2.0+ Fix from $1,6002026-04-15 HIGH 7.5 CVE-2025-62188 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vulnerability may allow unauthor… Dolphinscheduler 3.2.0+ Fix from $1,9502026-04-09 MEDIUM 6.5 CVE-2026-23983 A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoi… Superset 6.0.0+ Fix from $1,6002026-02-24 MEDIUM 6.5 CVE-2026-24098 Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view impo… Airflow 3.1.7+ Fix from $1,6002026-02-09 HIGH 7.5 CVE-2025-68438 In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length, sensitive values could be e… Airflow 3.1.6+ Fix from $1,9502026-01-16 HIGH 8.1 CVE-2025-26521 When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the API key and the secret key of the 'kubeadmin' user of… Cloudstack 4.19.3.0 / 4.20.1.0+ Fix from $1,9502025-06-10 HIGH 7.5 CVE-2025-26864 Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of… Iotdb 1.3.4+ Fix from $1,9502025-05-14 HIGH 7.5 CVE-2025-26795 Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC drive… Iotdb 1.3.4 / 2.0.2+ Fix from $1,9502025-05-14 MEDIUM 5.0 CVE-2025-30474 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when … Commons Vfs 2.10.0+ Fix from $1,6002025-03-23 HIGH 7.5 CVE-2024-45791 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: before 1.6.1. Us… Hertzbeat 1.6.1+ Fix from $1,9502024-11-18 HIGH 7.5 CVE-2024-47197 Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin. This … Maven Archetype Mitigation only Fix from $1,9502024-09-26