Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2026-73239
Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura.
This issue affects Apache All…
Allura
No fix yet
MEDIUM 5.4
CVE-2026-68076
Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to p…
Airflow
3.3.1+
MEDIUM 6.5
CVE-2026-68872
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variabl…
Apache Airflow Providers Amazon
No fix yet
MEDIUM 6.5
CVE-2026-68871
The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic loo…
Apache Airflow Providers Apache Yandex
No fix yet
MEDIUM 6.5
CVE-2026-48912
Improper Input Validation vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
A missing ownership check in the avatar…
Answer
2.0.2+
MEDIUM 6.5
CVE-2026-49296
Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/…
Airflow
3.3.0+
MEDIUM 5.3
CVE-2026-48206
Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel JIRA component.
The camel-jira producers r…
Camel
4.14.8 / 4.18.3+
MEDIUM 5.3
CVE-2026-49099
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorization Bypass Through User-Controlled Key …
Camel
4.14.8 / 4.18.3+
HIGH 7.5
CVE-2026-46585
Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Component.
The camel-lucene produce…
Camel
4.14.8 / 4.18.3+
MEDIUM 5.3
CVE-2026-46453
Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel ElasticSearch Rest Client.
The camel-elast…
Camel
4.14.8 / 4.18.3+
HIGH 7.5
CVE-2026-41084
A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstances`) evaluated authorization a…
Airflow
3.2.2+
HIGH 8.1
CVE-2025-58137
Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract.
This issue affects Apache Fineract: through 1.11.0. The issue is …
Fineract
1.12.1+
MEDIUM 6.5
CVE-2024-34457
On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone'…
Streampark
2.1.4+
CRITICAL 9.8
CVE-2023-43668
Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,
some se…
Inlong
after 1.8.0
CRITICAL 9.1
CVE-2023-44981
Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quoru…
Zookeeper
3.7.2 / 3.8.3+
MEDIUM 5.3
CVE-2020-13923EPSS 5%
IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04
Ofbiz
17.12.04+