Vulnerability index

Browse CVEs

72 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Ranger CRITICAL 9.8
CVE-2026-40920

Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixe…

No fix yet
Fix from $5,750 2026-08-10
Camel CRITICAL 9.8
CVE-2026-53913

Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak C…

Fix: 4.18.3 / 4.21.0+
Fix from $2,300 2026-07-06
Tomcat MEDIUM 6.5
CVE-2026-55955

Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issu…

Fix: 9.0.119 / 10.1.56+
Fix from $1,600 2026-06-29
Apisix HIGH 8.1
CVE-2026-49872

Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can possibly authenticate itself wi…

Fix: 3.17.0+
Fix from $1,950 2026-06-19
Ofbiz CRITICAL 9.8
CVE-2026-45434EPSS 22%

Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBi…

Fix: 24.09.06+
Fix from $2,300 2026-05-19
Ofbiz MEDIUM 5.3
CVE-2026-31387

Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to versio…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Storm MEDIUM 6.5
CVE-2026-41081

Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Des…

Fix: 2.8.7+
Fix from $1,600 2026-04-27
Tomcat MEDIUM 6.5
CVE-2026-34500

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affe…

Fix: 9.0.117 / 10.1.54+
Fix from $1,600 2026-04-09
Tomcat CRITICAL 9.1
CVE-2026-29145

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Nati…

Fix: 1.3.7 / 2.0.14+
Fix from $2,300 2026-04-09
Druid CRITICAL 9.8
CVE-2026-23906

Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * d…

Fix: 36.0.0+
Fix from $2,300 2026-02-10
HTTP Server HIGH 7.4
CVE-2025-49812

In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker…

Fix: 2.4.64+
Fix from $1,950 2025-07-10
Pekko Management MEDIUM 6.5
CVE-2025-46548

If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authen…

Fix: 1.6.1+
Fix from $1,600 2025-06-03
Cassandra MEDIUM 5.3
CVE-2024-27137

In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI…

Fix: 4.0.15 / 4.1.8+
Fix from $1,600 2025-02-04
Ozone HIGH 8.1
CVE-2024-45106

Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate t…

Mitigation only
Fix from $1,950 2024-12-03
Solr CRITICAL 9.8
CVE-2024-45216EPSS 91%

Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authen…

Fix: 8.11.4 / 9.7.0+
Fix from $2,300 2024-10-16
Submarine CRITICAL 9.8
CVE-2024-36264

** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submari…

Patch available
Fix from $2,300 2024-06-12
Ozone MEDIUM 5.3
CVE-2023-39196

Improper Authentication vulnerability in Apache Ozone. The vulnerability allows an attacker to download metadata internal to the Storage Container M…

Fix: after 1.3.0
Fix from $1,600 2024-02-07
Pulsar HIGH 7.5
CVE-2023-37544

Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication…

Fix: 2.10.5 / 2.11.2+
Fix from $1,950 2023-12-20
Activemq HIGH 8.8
CVE-2022-41678EPSS 86%

Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution.  In details, in ActiveMQ configurations, jetty allows…

Fix: 5.16.6 / 5.17.4+
Fix from $1,950 2023-11-28
Pulsar MEDIUM 6.5
CVE-2023-31007

Improper Authentication vulnerability in Apache Software Foundation Apache Pulsar Broker allows a client to stay connected to a broker after authenti…

Fix: 2.9.5+
Fix from $1,600 2023-07-12
Accumulo CRITICAL 9.8
CVE-2023-34340

Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo: 2.1.0. Accumulo 2.1.0 conta…

Mitigation only
Fix from $2,300 2023-06-21
Openmeetings HIGH 8.1
CVE-2023-29032

An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache Software Foundation Version…

Fix: 7.1.0+
Fix from $1,950 2023-05-12
Iotdb CRITICAL 9.8
CVE-2023-24831

Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana Connector: from 0.13.0 throu…

Fix: after 0.13.3
Fix from $2,300 2023-04-17
Iotdb HIGH 7.5
CVE-2023-24830

Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench component: from 0.13.0 before…

Fix: 0.13.3+
Fix from $1,950 2023-01-30
Shiro CRITICAL 9.8
CVE-2022-40664

Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.

Fix: 1.10.0+
Fix from $2,300 2022-10-12
Traffic Server HIGH 8.1
CVE-2021-44759

Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This…

Fix: after 8.1.0
Fix from $1,950 2022-03-23
Guacamole HIGH 8.8
CVE-2021-43999

Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allo…

Mitigation only
Fix from $1,950 2022-01-11
Shenyu CRITICAL 9.8
CVE-2021-37580EPSS 40%

A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue aff…

Mitigation only
Fix from $2,300 2021-11-16
Traffic Server HIGH 8.1
CVE-2021-38161

Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Ap…

Fix: after 8.0.8
Fix from $1,950 2021-11-03
Shiro CRITICAL 9.8
CVE-2021-41303EPSS 77%

Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users shoul…

Fix: 1.8.0+
Fix from $2,300 2021-09-17