Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2026-64640
Apache Polaris did not consistently validate storage locations supplied during table and view registration.
An authenticated principal with permissi…
Polaris
after 1.6.0
MEDIUM 6.5
CVE-2026-50749
Improper Authorization vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
Any authenticated user can reject arbitrary…
Answer
2.0.2+
CRITICAL 9.1
CVE-2026-68980
Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framewor…
Nifi
2.11.0+
HIGH 8.2
CVE-2026-58159
Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors.
This issue affects Apache Traffic Server: from…
Traffic Server
9.2.15 / 10.1.4+
MEDIUM 6.3
CVE-2026-44911
Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submi…
Nifi
2.10.0+
HIGH 8.1
CVE-2026-47339
Incorrect Authorization vulnerability in Apache APISIX.
An attacker can capitalise on authz-casdoor plugin under default configuration to authentica…
Apisix
3.17.0+
MEDIUM 6.5
CVE-2026-42357
Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to acces…
Dolphinscheduler
3.4.2+
CRITICAL 9.8
CVE-2026-32966
DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler.
This issue affects Apache …
Dolphinscheduler
3.4.2+
CRITICAL 9.1
CVE-2026-32967
Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler.
This issue affects Apache DolphinScheduler: before…
Dolphinscheduler
3.4.2+
MEDIUM 5.3
CVE-2026-42526
In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0, the team-scoping logic coul…
Apache Airflow Providers Amazon
9.28.0+
MEDIUM 6.5
CVE-2025-66170
The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in …
Cloudstack
4.22.0.1+
CRITICAL 9.9
CVE-2026-42812
In Apache Iceberg, the table's metadata files are control files: they tell readers
which data files belong to the table and which table version to re…
Polaris
1.4.1+
HIGH 8.1
CVE-2026-23902
Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not…
Dolphinscheduler
3.4.1+
HIGH 7.5
CVE-2026-32228
UI / API User with asset materialize permission could trigger dags they had no access to.
Users are advised to migrate to Airflow version 3.2.0 that …
Airflow
3.2.0+
MEDIUM 6.5
CVE-2026-23984
An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab access to bypass the read-only ver…
Superset
6.0.0+
MEDIUM 6.5
CVE-2026-23982
An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a d…
Superset
6.0.0+
HIGH 8.8
CVE-2025-27696
Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read…
Superset
4.1.2+
MEDIUM 5.4
CVE-2025-24860
Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when usi…
Cassandra
4.0.16 / 4.1.8+
MEDIUM 6.5
CVE-2024-55633
Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed…
Superset
4.1.0+
MEDIUM 6.5
CVE-2024-53949
Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users …
Superset
4.1.0+
HIGH 8.1
CVE-2024-45106
Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate t…
Ozone
Mitigation only
CRITICAL 9.8
CVE-2024-45216EPSS 91%
Improper Authentication vulnerability in Apache Solr.
Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authen…
Solr
8.11.4 / 9.7.0+
HIGH 7.2
CVE-2024-42062
CloudStack account-users by default use username and password based authentication for API and UI access. Account-users can generate and register ran…
Cloudstack
4.18.2.3 / 4.19.1.1+
CRITICAL 9.8
CVE-2024-38856 KEVEPSS 99%
Incorrect Authorization vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: through 18.12.14.
Users are recommended to upgrade to versi…
Ofbiz
18.12.15+
CRITICAL 9.8
CVE-2024-36265
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core.
This issue affects Apache Submarine Server Co…
Submarine
Mitigation only
HIGH 7.4
CVE-2024-27309
While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced.
Two preconditi…
Kafka
after 3.6.1
MEDIUM 6.4
CVE-2024-29834
This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as u…
Pulsar
3.0.4 / 3.2.2+
MEDIUM 5.4
CVE-2024-28098
The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and off…
Pulsar
2.10.6 / 2.11.4+
HIGH 7.5
CVE-2024-27139
** UNSUPPORTED WHEN ASSIGNED **
Incorrect Authorization vulnerability in Apache Archiva: a vulnerability in Apache Archiva allows an unauthenticated…
Archiva
Mitigation only
HIGH 7.5
CVE-2024-27138
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva.
Apache Archiva has a setting to disable user registration, …
Archiva
Mitigation only