Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Activemq MEDIUM 6.5
CVE-2026-61487

Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypas…

Fix: 5.19.9 / 6.2.8+
Fix from $1,600 2026-07-28
Activemq HIGH 8.1
CVE-2026-49877

Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can access /admin/* paths in the…

Fix: 5.19.8 / 6.2.7+
Fix from $1,950 2026-06-30
Tomcat MEDIUM 6.5
CVE-2026-55956

Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method o…

Fix: 9.0.119 / 10.1.56+
Fix from $1,600 2026-06-29
Ofbiz HIGH 8.8
CVE-2026-47342

A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apa…

Fix: 24.09.07+
Fix from $1,950 2026-06-10
Ofbiz MEDIUM 6.5
CVE-2026-45187

Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade t…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Tomcat CRITICAL 9.1
CVE-2026-43515

Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affe…

Fix: 9.0.118 / 10.1.55+
Fix from $2,300 2026-05-12
Solr HIGH 8.2
CVE-2026-22022

Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule Based Authorization Plugin" are vulnerable to allowing unauthorized access …

Fix: 9.10.1+
Fix from $1,950 2026-01-21
Superset MEDIUM 6.5
CVE-2025-55675

Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated use…

Fix: 5.0.0+
Fix from $1,600 2025-08-14
Traffic Control HIGH 8.8
CVE-2024-45387EPSS 42%

An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", …

Fix: 8.0.2+
Fix from $1,950 2024-12-23
Artemis HIGH 8.8
CVE-2023-50780EPSS 17%

Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia…

Fix: 2.29.0+
Fix from $1,950 2024-10-14
Ozone HIGH 7.5
CVE-2020-17517

The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The current security vulnerability allo…

Fix: 1.1.0+
Fix from $1,950 2021-04-27