Vulnerability index

Browse CVEs

72 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2026-40920 Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixe… Ranger No fix yet Fix from $5,7502026-08-10 CRITICAL 9.8 CVE-2026-53913 Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak C… Camel 4.18.3 / 4.21.0+ Fix from $2,3002026-07-06 MEDIUM 6.5 CVE-2026-55955 Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issu… Tomcat 9.0.119 / 10.1.56+ Fix from $1,6002026-06-29 HIGH 8.1 CVE-2026-49872 Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can possibly authenticate itself wi… Apisix 3.17.0+ Fix from $1,9502026-06-19 CRITICAL 9.8 CVE-2026-45434EPSS 22% Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBi… Ofbiz 24.09.06+ Fix from $2,3002026-05-19 MEDIUM 5.3 CVE-2026-31387 Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to versio… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 MEDIUM 6.5 CVE-2026-41081 Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Des… Storm 2.8.7+ Fix from $1,6002026-04-27 MEDIUM 6.5 CVE-2026-34500 CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affe… Tomcat 9.0.117 / 10.1.54+ Fix from $1,6002026-04-09 CRITICAL 9.1 CVE-2026-29145 CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Nati… Tomcat 1.3.7 / 2.0.14+ Fix from $2,3002026-04-09 CRITICAL 9.8 CVE-2026-23906 Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * d… Druid 36.0.0+ Fix from $2,3002026-02-10 HIGH 7.4 CVE-2025-49812 In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker… HTTP Server 2.4.64+ Fix from $1,9502025-07-10 MEDIUM 6.5 CVE-2025-46548 If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authen… Pekko Management 1.6.1+ Fix from $1,6002025-06-03 MEDIUM 5.3 CVE-2024-27137 In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI… Cassandra 4.0.15 / 4.1.8+ Fix from $1,6002025-02-04 HIGH 8.1 CVE-2024-45106 Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate t… Ozone Mitigation only Fix from $1,9502024-12-03 CRITICAL 9.8 CVE-2024-45216EPSS 91% Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authen… Solr 8.11.4 / 9.7.0+ Fix from $2,3002024-10-16 CRITICAL 9.8 CVE-2024-36264 ** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submari… Submarine Patch available Fix from $2,3002024-06-12 MEDIUM 5.3 CVE-2023-39196 Improper Authentication vulnerability in Apache Ozone. The vulnerability allows an attacker to download metadata internal to the Storage Container M… Ozone after 1.3.0 Fix from $1,6002024-02-07 HIGH 7.5 CVE-2023-37544 Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication… Pulsar 2.10.5 / 2.11.2+ Fix from $1,9502023-12-20 HIGH 8.8 CVE-2022-41678EPSS 86% Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution.  In details, in ActiveMQ configurations, jetty allows… Activemq 5.16.6 / 5.17.4+ Fix from $1,9502023-11-28 MEDIUM 6.5 CVE-2023-31007 Improper Authentication vulnerability in Apache Software Foundation Apache Pulsar Broker allows a client to stay connected to a broker after authenti… Pulsar 2.9.5+ Fix from $1,6002023-07-12 CRITICAL 9.8 CVE-2023-34340 Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo: 2.1.0. Accumulo 2.1.0 conta… Accumulo Mitigation only Fix from $2,3002023-06-21 HIGH 8.1 CVE-2023-29032 An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache Software Foundation Version… Openmeetings 7.1.0+ Fix from $1,9502023-05-12 CRITICAL 9.8 CVE-2023-24831 Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana Connector: from 0.13.0 throu… Iotdb after 0.13.3 Fix from $2,3002023-04-17 HIGH 7.5 CVE-2023-24830 Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench component: from 0.13.0 before… Iotdb 0.13.3+ Fix from $1,9502023-01-30 CRITICAL 9.8 CVE-2022-40664 Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher. Shiro 1.10.0+ Fix from $2,3002022-10-12 HIGH 8.1 CVE-2021-44759 Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This… Traffic Server after 8.1.0 Fix from $1,9502022-03-23 HIGH 8.8 CVE-2021-43999 Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allo… Guacamole Mitigation only Fix from $1,9502022-01-11 CRITICAL 9.8 CVE-2021-37580EPSS 40% A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue aff… Shenyu Mitigation only Fix from $2,3002021-11-16 HIGH 8.1 CVE-2021-38161 Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Ap… Traffic Server after 8.0.8 Fix from $1,9502021-11-03 CRITICAL 9.8 CVE-2021-41303EPSS 77% Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users shoul… Shiro 1.8.0+ Fix from $2,3002021-09-17