Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 6.5 CVE-2026-73239 Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache All… Allura No fix yet Fix from $4,0002026-08-12 MEDIUM 5.4 CVE-2026-68076 Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to p… Airflow 3.3.1+ Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-68872 The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variabl… Apache Airflow Providers Amazon No fix yet Fix from $4,0002026-08-10 MEDIUM 6.5 CVE-2026-68871 The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic loo… Apache Airflow Providers Apache Yandex No fix yet Fix from $4,0002026-08-10 MEDIUM 6.5 CVE-2026-48912 Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar… Answer 2.0.2+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-49296 Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/… Airflow 3.3.0+ Fix from $1,6002026-07-07 MEDIUM 5.3 CVE-2026-48206 Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel JIRA component. The camel-jira producers r… Camel 4.14.8 / 4.18.3+ Fix from $1,6002026-07-06 MEDIUM 5.3 CVE-2026-49099 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorization Bypass Through User-Controlled Key … Camel 4.14.8 / 4.18.3+ Fix from $1,6002026-07-06 HIGH 7.5 CVE-2026-46585 Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Component. The camel-lucene produce… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 MEDIUM 5.3 CVE-2026-46453 Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel ElasticSearch Rest Client. The camel-elast… Camel 4.14.8 / 4.18.3+ Fix from $1,6002026-07-06 HIGH 7.5 CVE-2026-41084 A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstances`) evaluated authorization a… Airflow 3.2.2+ Fix from $1,9502026-06-01 HIGH 8.1 CVE-2025-58137 Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is … Fineract 1.12.1+ Fix from $1,9502025-12-12 MEDIUM 6.5 CVE-2024-34457 On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone'… Streampark 2.1.4+ Fix from $1,6002024-07-22 CRITICAL 9.8 CVE-2023-43668 Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,  some se… Inlong after 1.8.0 Fix from $2,3002023-10-16 CRITICAL 9.1 CVE-2023-44981 Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quoru… Zookeeper 3.7.2 / 3.8.3+ Fix from $2,3002023-10-11 MEDIUM 5.3 CVE-2020-13923EPSS 5% IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04 Ofbiz 17.12.04+ Fix from $1,6002020-07-15