Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tomcat MEDIUM 6.5
CVE-2026-55955

Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issu…

Fix: 9.0.119 / 10.1.56+
Fix from $1,600 2026-06-29
Tomcat MEDIUM 6.5
CVE-2026-55956

Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method o…

Fix: 9.0.119 / 10.1.56+
Fix from $1,600 2026-06-29
Tomcat CRITICAL 9.1
CVE-2026-53434

Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apach…

Fix: 9.0.119 / 10.1.56+
Fix from $2,300 2026-06-29
Tomcat HIGH 7.3
CVE-2026-53404

Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched,…

Fix: 9.0.119 / 10.1.56+
Fix from $1,950 2026-06-29
Tomcat MEDIUM 6.1
CVE-2026-50229

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issu…

Fix: 9.0.119 / 10.1.56+
Fix from $1,600 2026-06-29
Apache Airflow Providers Ftp HIGH 7.5
CVE-2026-49486

The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control c…

Fix: 3.15.1+
Fix from $1,950 2026-06-26
Nifi MEDIUM 5.3
CVE-2026-54665

Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard …

Fix: 2.10.0+
Fix from $1,600 2026-06-22
Nifi HIGH 7.2
CVE-2026-44913

Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL …

Fix: 2.10.0+
Fix from $1,950 2026-06-22
Nifi HIGH 7.2
CVE-2026-44914

Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Per…

Fix: 2.10.0+
Fix from $1,950 2026-06-22
Nifi MEDIUM 6.3
CVE-2026-44911

Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submi…

Fix: 2.10.0+
Fix from $1,600 2026-06-22
Doris Mcp Server HIGH 8.1
CVE-2025-66336

Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated int…

Fix: 0.6.1+
Fix from $1,950 2026-06-22
Atlas MEDIUM 5.4
CVE-2025-62198

An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier. Users are recommended to upgrade to version 2.5.…

Fix: 2.5.0+
Fix from $1,600 2026-06-22
Apisix CRITICAL 9.3
CVE-2026-49871

Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manag…

Fix: 3.17.0+
Fix from $2,300 2026-06-19
Apisix CRITICAL 9.1
CVE-2026-49230

Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default configuration is vulnerable to aut…

Fix: 3.17.0+
Fix from $2,300 2026-06-19
Apisix HIGH 8.1
CVE-2026-49872

Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can possibly authenticate itself wi…

Fix: 3.17.0+
Fix from $1,950 2026-06-19
Apisix HIGH 7.2
CVE-2026-48895

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some client headers to perform an …

Fix: 3.17.0+
Fix from $1,950 2026-06-19
Apisix MEDIUM 5.4
CVE-2026-49231

Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed identity headers to upstream capitalising on non-defa…

Fix: 3.17.0+
Fix from $1,600 2026-06-19
Apisix CRITICAL 9.1
CVE-2026-44087

Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default configuration has an attack s…

Fix: 3.17.0+
Fix from $2,300 2026-06-19
Apisix HIGH 8.1
CVE-2026-47339

Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authentica…

Fix: 3.17.0+
Fix from $1,950 2026-06-19
Apisix MEDIUM 6.5
CVE-2026-47341

Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from certain configurations in hmac-auth to re-use a to…

Fix: 3.17.0+
Fix from $1,600 2026-06-19
Apisix MEDIUM 6.1
CVE-2026-44915

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-auth in Apache APISIX is vulner…

Fix: 3.17.0+
Fix from $1,600 2026-06-19
Apisix MEDIUM 5.8
CVE-2026-44046

Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac plugin under default configuration to potentiall…

Fix: 3.17.0+
Fix from $1,600 2026-06-19
Apisix CRITICAL 9.1
CVE-2026-39999

Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configur…

Fix: 3.17.0+
Fix from $2,300 2026-06-19
Apisix HIGH 8.8
CVE-2026-39998

Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to spoof i…

Fix: 3.17.0+
Fix from $1,950 2026-06-19
Shiro CRITICAL 9.1
CVE-2026-49268

A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username …

Fix: 2.2.1+
Fix from $2,300 2026-06-17
Apache Airflow Providers Sftp CRITICAL 9.1
CVE-2026-50203

A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP serv…

Fix: 5.8.1+
Fix from $2,300 2026-06-17
Dolphinscheduler MEDIUM 6.5
CVE-2026-47340

Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. …

Fix: 3.4.2+
Fix from $1,600 2026-06-17
Dolphinscheduler MEDIUM 6.5
CVE-2026-42357

Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to acces…

Fix: 3.4.2+
Fix from $1,600 2026-06-17
Dolphinscheduler CRITICAL 9.8
CVE-2026-32966

DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache …

Fix: 3.4.2+
Fix from $2,300 2026-06-17
Dolphinscheduler CRITICAL 9.1
CVE-2026-32967

Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before…

Fix: 3.4.2+
Fix from $2,300 2026-06-17