Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-40920
Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0.
Users are recommended to upgrade to version 2.9.0, which fixe…
Ranger
No fix yet
CRITICAL 9.8
CVE-2026-53913
Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak C…
Camel
4.18.3 / 4.21.0+
MEDIUM 6.5
CVE-2026-55955
Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component.
This issu…
Tomcat
9.0.119 / 10.1.56+
HIGH 8.1
CVE-2026-49872
Improper Authentication vulnerability in Apache APISIX.
When the cas-auth plugin is used in a route, an attacker can possibly authenticate itself wi…
Apisix
3.17.0+
CRITICAL 9.8
CVE-2026-45434EPSS 22%
Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution
This issue affects Apache OFBi…
Ofbiz
24.09.06+
MEDIUM 5.3
CVE-2026-31387
Improper Authentication vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to versio…
Ofbiz
24.09.06+
MEDIUM 6.5
CVE-2026-41081
Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm
Versions Affected: up to 2.8.7
Des…
Storm
2.8.7+
MEDIUM 6.5
CVE-2026-34500
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat.
This issue affe…
Tomcat
9.0.117 / 10.1.54+
CRITICAL 9.1
CVE-2026-29145
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Nati…
Tomcat
1.3.7 / 2.0.14+
CRITICAL 9.8
CVE-2026-23906
Affected Products and Versions
* Apache Druid
* Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0)
* Prerequisites: * d…
Druid
36.0.0+
HIGH 7.4
CVE-2025-49812
In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker…
HTTP Server
2.4.64+
MEDIUM 6.5
CVE-2025-46548
If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied.
Users that rely on authen…
Pekko Management
1.6.1+
MEDIUM 5.3
CVE-2024-27137
In Apache Cassandra it is possible for a local attacker without access
to the Apache Cassandra process or configuration files to manipulate
the RMI…
Cassandra
4.0.15 / 4.1.8+
HIGH 8.1
CVE-2024-45106
Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate t…
Ozone
Mitigation only
CRITICAL 9.8
CVE-2024-45216EPSS 91%
Improper Authentication vulnerability in Apache Solr.
Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authen…
Solr
8.11.4 / 9.7.0+
CRITICAL 9.8
CVE-2024-36264
** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils.
If the user doesn't explicitly set `submari…
Submarine
Patch available
MEDIUM 5.3
CVE-2023-39196
Improper Authentication vulnerability in Apache Ozone.
The vulnerability allows an attacker to download metadata internal to the Storage Container M…
Ozone
after 1.3.0
HIGH 7.5
CVE-2023-37544
Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication…
Pulsar
2.10.5 / 2.11.2+
HIGH 8.8
CVE-2022-41678EPSS 86%
Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution.
In details, in ActiveMQ configurations, jetty allows…
Activemq
5.16.6 / 5.17.4+
MEDIUM 6.5
CVE-2023-31007
Improper Authentication vulnerability in Apache Software Foundation Apache Pulsar Broker allows a client to stay connected to a broker after authenti…
Pulsar
2.9.5+
CRITICAL 9.8
CVE-2023-34340
Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo.
This issue affects Apache Accumulo: 2.1.0.
Accumulo 2.1.0 conta…
Accumulo
Mitigation only
HIGH 8.1
CVE-2023-29032
An attacker that has gained access to certain private information can use this to act as other user.
Vendor: The Apache Software Foundation
Version…
Openmeetings
7.1.0+
CRITICAL 9.8
CVE-2023-24831
Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana Connector: from 0.13.0 throu…
Iotdb
after 0.13.3
HIGH 7.5
CVE-2023-24830
Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench component: from 0.13.0 before…
Iotdb
0.13.3+
CRITICAL 9.8
CVE-2022-40664
Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.
Shiro
1.10.0+
HIGH 8.1
CVE-2021-44759
Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This…
Traffic Server
after 8.1.0
HIGH 8.8
CVE-2021-43999
Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allo…
Guacamole
Mitigation only
CRITICAL 9.8
CVE-2021-37580EPSS 40%
A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue aff…
Shenyu
Mitigation only
HIGH 8.1
CVE-2021-38161
Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Ap…
Traffic Server
after 8.0.8
CRITICAL 9.8
CVE-2021-41303EPSS 77%
Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users shoul…
Shiro
1.8.0+