Vulnerability index

Browse CVEs

398 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-66143 It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies… Neethi No fix yet Fix from $1,9502026-07-24 HIGH 7.3 CVE-2026-43825EPSS 9% Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected:   before 3.0.0-M4 (libsvm document categorization module; introdu… Opennlp Mitigation only Fix from $1,9502026-07-06 HIGH 7.5 CVE-2026-47896 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). T… Lucene.net Mitigation only Fix from $1,9502026-07-03 CRITICAL 9.8 CVE-2026-47898 Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Ap… Lucene.net Mitigation only Fix from $2,3002026-07-03 HIGH 7.5 CVE-2026-47897 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). T… Lucene.net Mitigation only Fix from $1,9502026-07-03 HIGH 7.5 CVE-2026-50750 Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Following the fix for CVE-2026-4… Activemq Mitigation only Fix from $1,9502026-06-30 CRITICAL 9.8 CVE-2026-47065 ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the seri… Mina Mitigation only Fix from $2,3002026-06-03 HIGH 8.8 CVE-2026-23918EPSS 50% Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are… HTTP Server Mitigation only Fix from $1,9502026-05-04 CRITICAL 9.8 CVE-2026-41873 ** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading t… Pony Mail Mitigation only Fix from $2,3002026-04-28 HIGH 7.3 CVE-2026-40542 Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication withou… Httpclient Mitigation only Fix from $1,9502026-04-22 HIGH 7.5 CVE-2026-34486 KEVEPSS 83% Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. … Tomcat Mitigation only Fix from $1,9502026-04-09 HIGH 8.7 CVE-2026-35554 A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. … Kafka Mitigation only Fix from $1,9502026-04-07 CRITICAL 9.9 CVE-2016-15057 ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum… Continuum Mitigation only Fix from $2,3002026-01-26 MEDIUM 5.4 CVE-2025-62728 SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thrift APIs. The vulnerability i… Hive Mitigation only Fix from $1,6002025-11-26 HIGH 8.8 CVE-2025-62228 Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name.… Flink Cdc Mitigation only Fix from $1,9502025-10-09 MEDIUM 6.5 CVE-2025-54831 Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict access to sensitive connecti… Airflow Mitigation only Fix from $1,6002025-09-26 HIGH 8.8 CVE-2025-53192 ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons OGNL. This issue affects Ap… Commons Ognl Mitigation only Fix from $1,9502025-08-18 CRITICAL 9.8 CVE-2025-53606 Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recomm… Seata Mitigation only Fix from $2,3002025-08-08 MEDIUM 5.6 CVE-2025-48795 Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary … Cxf Mitigation only Fix from $1,6002025-07-15 MEDIUM 5.4 CVE-2025-26796 ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Oozie. … Oozie Mitigation only Fix from $1,6002025-03-22 HIGH 7.5 CVE-2025-24783 ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Apache Cocoon. This issue affects… Cocoon Mitigation only Fix from $1,9502025-01-27 HIGH 8.1 CVE-2024-45106 Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate t… Ozone Mitigation only Fix from $1,9502024-12-03 MEDIUM 6.1 CVE-2024-52318 Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommend… Tomcat Mitigation only Fix from $1,6002024-11-18 HIGH 8.1 CVE-2024-43383 Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's Replicator library: from 4.8… Lucene.net Mitigation only Fix from $1,9502024-10-31 HIGH 7.5 CVE-2024-28168 Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: … Formatting Objects Processor Mitigation only Fix from $1,9502024-10-09 HIGH 7.5 CVE-2024-47197 Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin. This … Maven Archetype Mitigation only Fix from $1,9502024-09-26 HIGH 7.5 CVE-2023-49198 Mysql security vulnerability in Apache SeaTunnel. Attackers can read files on the MySQL server by modifying the information in the MySQL URL allow… Seatunnel Mitigation only Fix from $1,9502024-08-21 HIGH 7.5 CVE-2024-22281 ** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacker to spoof sessions by genera… Helix Mitigation only Fix from $1,9502024-08-20 HIGH 7.3 CVE-2024-36448 ** UNSUPPORTED WHEN ASSIGNED ** Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench. This issue affects Apache IoTDB Workbenc… Iotdb Workbench Mitigation only Fix from $1,9502024-08-05 CRITICAL 9.1 CVE-2023-48396 Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can forge any token to log in an… Seatunnel Mitigation only Fix from $2,3002024-07-30