Vulnerability index

Browse CVEs

8 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Apache Airflow Providers Fab CRITICAL 9.8
CVE-2026-59243

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or…

Fix: 3.7.3+
Fix from $2,300 2026-07-29
Cxf MEDIUM 6.5
CVE-2026-50634

A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the acc…

Fix: 4.1.7 / 4.2.2+
Fix from $1,600 2026-06-12
Spark MEDIUM 6.5
CVE-2025-55039

This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure defau…

Fix: 3.4.4 / 3.5.2+
Fix from $1,600 2025-10-15
Openoffice HIGH 7.5
CVE-2021-41832

It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apache OpenOffice up to 4.1.10 are…

Fix: 4.1.11+
Fix from $1,950 2021-10-11
Openoffice HIGH 7.5
CVE-2021-41830

It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All versions of Apache OpenOffice u…

Fix: 4.1.11+
Fix from $1,950 2021-10-11
Openoffice MEDIUM 5.3
CVE-2021-41831

It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to 4.1.10 are affected. Users ar…

Fix: 4.1.11+
Fix from $1,600 2021-10-11
Pulsar CRITICAL 9.8
CVE-2021-22160EPSS 53%

If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if th…

Fix: 2.7.1+
Fix from $2,300 2021-05-26
Netbeans HIGH 7.5
CVE-2019-17561

The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional c…

Fix: after 11.2
Fix from $1,950 2020-03-30