Vulnerability index

Browse CVEs

398 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Neethi HIGH 7.5
CVE-2026-66143

It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies…

No fix yet
Fix from $1,950 2026-07-24
Opennlp HIGH 7.3
CVE-2026-43825EPSS 9%

Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected:   before 3.0.0-M4 (libsvm document categorization module; introdu…

Mitigation only
Fix from $1,950 2026-07-06
Lucene.net HIGH 7.5
CVE-2026-47896

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). T…

Mitigation only
Fix from $1,950 2026-07-03
Lucene.net CRITICAL 9.8
CVE-2026-47898

Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Ap…

Mitigation only
Fix from $2,300 2026-07-03
Lucene.net HIGH 7.5
CVE-2026-47897

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). T…

Mitigation only
Fix from $1,950 2026-07-03
Activemq HIGH 7.5
CVE-2026-50750

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Following the fix for CVE-2026-4…

Mitigation only
Fix from $1,950 2026-06-30
Mina CRITICAL 9.8
CVE-2026-47065

ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the seri…

Mitigation only
Fix from $2,300 2026-06-03
HTTP Server HIGH 8.8
CVE-2026-23918EPSS 50%

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are…

Mitigation only
Fix from $1,950 2026-05-04
Pony Mail CRITICAL 9.8
CVE-2026-41873

** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading t…

Mitigation only
Fix from $2,300 2026-04-28
Httpclient HIGH 7.3
CVE-2026-40542

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication withou…

Mitigation only
Fix from $1,950 2026-04-22
Tomcat HIGH 7.5
CVE-2026-34486 KEVEPSS 83%

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. …

Mitigation only
Fix from $1,950 2026-04-09
Kafka HIGH 8.7
CVE-2026-35554

A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. …

Mitigation only
Fix from $1,950 2026-04-07
Continuum CRITICAL 9.9
CVE-2016-15057

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum…

Mitigation only
Fix from $2,300 2026-01-26
Hive MEDIUM 5.4
CVE-2025-62728

SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thrift APIs. The vulnerability i…

Mitigation only
Fix from $1,600 2025-11-26
Flink Cdc HIGH 8.8
CVE-2025-62228

Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name.…

Mitigation only
Fix from $1,950 2025-10-09
Airflow MEDIUM 6.5
CVE-2025-54831

Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict access to sensitive connecti…

Mitigation only
Fix from $1,600 2025-09-26
Commons Ognl HIGH 8.8
CVE-2025-53192

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons OGNL. This issue affects Ap…

Mitigation only
Fix from $1,950 2025-08-18
Seata CRITICAL 9.8
CVE-2025-53606

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recomm…

Mitigation only
Fix from $2,300 2025-08-08
Cxf MEDIUM 5.6
CVE-2025-48795

Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary …

Mitigation only
Fix from $1,600 2025-07-15
Oozie MEDIUM 5.4
CVE-2025-26796

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Oozie. …

Mitigation only
Fix from $1,600 2025-03-22
Cocoon HIGH 7.5
CVE-2025-24783

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Apache Cocoon. This issue affects…

Mitigation only
Fix from $1,950 2025-01-27
Ozone HIGH 8.1
CVE-2024-45106

Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate t…

Mitigation only
Fix from $1,950 2024-12-03
Tomcat MEDIUM 6.1
CVE-2024-52318

Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommend…

Mitigation only
Fix from $1,600 2024-11-18
Lucene.net HIGH 8.1
CVE-2024-43383

Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's Replicator library: from 4.8…

Mitigation only
Fix from $1,950 2024-10-31
Formatting Objects Processor HIGH 7.5
CVE-2024-28168

Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: …

Mitigation only
Fix from $1,950 2024-10-09
Maven Archetype HIGH 7.5
CVE-2024-47197

Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin. This …

Mitigation only
Fix from $1,950 2024-09-26
Seatunnel HIGH 7.5
CVE-2023-49198

Mysql security vulnerability in Apache SeaTunnel. Attackers can read files on the MySQL server by modifying the information in the MySQL URL allow…

Mitigation only
Fix from $1,950 2024-08-21
Helix HIGH 7.5
CVE-2024-22281

** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacker to spoof sessions by genera…

Mitigation only
Fix from $1,950 2024-08-20
Iotdb Workbench HIGH 7.3
CVE-2024-36448

** UNSUPPORTED WHEN ASSIGNED ** Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench. This issue affects Apache IoTDB Workbenc…

Mitigation only
Fix from $1,950 2024-08-05
Seatunnel CRITICAL 9.1
CVE-2023-48396

Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can forge any token to log in an…

Mitigation only
Fix from $2,300 2024-07-30