Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Allura MEDIUM 6.5
CVE-2026-73239

Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache All…

No fix yet
Fix from $4,000 2026-08-12
Airflow MEDIUM 5.4
CVE-2026-68076

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to p…

Fix: 3.3.1+
Fix from $4,000 2026-08-12
Apache Airflow Providers Amazon MEDIUM 6.5
CVE-2026-68872

The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variabl…

No fix yet
Fix from $4,000 2026-08-10
Apache Airflow Providers Apache Yandex MEDIUM 6.5
CVE-2026-68871

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic loo…

No fix yet
Fix from $4,000 2026-08-10
Answer MEDIUM 6.5
CVE-2026-48912

Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar…

Fix: 2.0.2+
Fix from $1,600 2026-08-05
Airflow MEDIUM 6.5
CVE-2026-49296

Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/…

Fix: 3.3.0+
Fix from $1,600 2026-07-07
Camel MEDIUM 5.3
CVE-2026-48206

Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel JIRA component. The camel-jira producers r…

Fix: 4.14.8 / 4.18.3+
Fix from $1,600 2026-07-06
Camel MEDIUM 5.3
CVE-2026-49099

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorization Bypass Through User-Controlled Key …

Fix: 4.14.8 / 4.18.3+
Fix from $1,600 2026-07-06
Camel HIGH 7.5
CVE-2026-46585

Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Component. The camel-lucene produce…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel MEDIUM 5.3
CVE-2026-46453

Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel ElasticSearch Rest Client. The camel-elast…

Fix: 4.14.8 / 4.18.3+
Fix from $1,600 2026-07-06
Airflow HIGH 7.5
CVE-2026-41084

A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstances`) evaluated authorization a…

Fix: 3.2.2+
Fix from $1,950 2026-06-01
Fineract HIGH 8.1
CVE-2025-58137

Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is …

Fix: 1.12.1+
Fix from $1,950 2025-12-12
Streampark MEDIUM 6.5
CVE-2024-34457

On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone'…

Fix: 2.1.4+
Fix from $1,600 2024-07-22
Inlong CRITICAL 9.8
CVE-2023-43668

Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,  some se…

Fix: after 1.8.0
Fix from $2,300 2023-10-16
Zookeeper CRITICAL 9.1
CVE-2023-44981

Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quoru…

Fix: 3.7.2 / 3.8.3+
Fix from $2,300 2023-10-11
Ofbiz MEDIUM 5.3
CVE-2020-13923EPSS 5%

IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04

Fix: 17.12.04+
Fix from $1,600 2020-07-15