Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cxf HIGH 8.1
CVE-2026-50632

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, whi…

Fix: 4.1.7 / 4.2.2+
Fix from $1,950 2026-06-12
Cxf HIGH 8.1
CVE-2026-50633

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able…

Fix: 4.1.7 / 4.2.2+
Fix from $1,950 2026-06-12
Cxf HIGH 7.5
CVE-2026-50645

There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncon…

Fix: 4.1.7 / 4.2.2+
Fix from $1,950 2026-06-12
Cxf HIGH 7.4
CVE-2026-50631

A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate mul…

Fix: 4.1.7 / 4.2.2+
Fix from $1,950 2026-06-12
Cxf MEDIUM 6.5
CVE-2026-50634

A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the acc…

Fix: 4.1.7 / 4.2.2+
Fix from $1,600 2026-06-12
Cxf CRITICAL 9.8
CVE-2026-49875

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configuration…

Fix: 4.1.7 / 4.2.2+
Fix from $2,300 2026-06-12
Cxf CRITICAL 9.8
CVE-2026-50628

A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other…

Fix: 4.1.7 / 4.2.2+
Fix from $2,300 2026-06-12
Cxf CRITICAL 9.1
CVE-2026-50627

The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued…

Fix: 4.1.7 / 4.2.2+
Fix from $2,300 2026-06-12
Cxf MEDIUM 6.5
CVE-2026-50630

A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' par…

Fix: 4.1.7 / 4.2.2+
Fix from $1,600 2026-06-12
Cxf MEDIUM 5.3
CVE-2026-50629

The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control char…

Fix: 4.1.7 / 4.2.2+
Fix from $1,600 2026-06-12
Ofbiz HIGH 8.8
CVE-2026-50223

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataR…

Fix: 24.09.07+
Fix from $1,950 2026-06-10
Ofbiz HIGH 8.8
CVE-2026-47342

A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apa…

Fix: 24.09.07+
Fix from $1,950 2026-06-10
Answer HIGH 7.2
CVE-2026-25700

Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Previously issue…

Fix: 2.0.1+
Fix from $1,950 2026-06-10
Apache Airflow Providers Samba MEDIUM 6.5
CVE-2026-49818

The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an objec…

Fix: 4.12.6+
Fix from $1,600 2026-06-09
Answer MEDIUM 6.5
CVE-2026-33582

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF ima…

Fix: 2.0.1+
Fix from $1,600 2026-06-09
Answer MEDIUM 6.5
CVE-2026-34031

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not…

Fix: 2.0.1+
Fix from $1,600 2026-06-09
Answer MEDIUM 6.5
CVE-2026-34905

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unl…

Fix: 2.0.1+
Fix from $1,600 2026-06-09
Answer MEDIUM 5.4
CVE-2026-34033

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: thro…

Fix: 2.0.1+
Fix from $1,600 2026-06-09
Answer MEDIUM 6.1
CVE-2026-25688

Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated respo…

Fix: 2.0.1+
Fix from $1,600 2026-06-09
Answer MEDIUM 6.1
CVE-2026-25699

Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. …

Fix: 2.0.1+
Fix from $1,600 2026-06-09
HTTP Server HIGH 7.5
CVE-2026-49975EPSS 28%

Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. T…

Fix: 2.4.68+
Fix from $1,950 2026-06-08
HTTP Server HIGH 7.3
CVE-2026-48913

Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: …

Fix: 2.4.68+
Fix from $1,950 2026-06-08
HTTP Server CRITICAL 9.8
CVE-2026-44631

Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: fr…

Fix: 2.4.68+
Fix from $2,300 2026-06-08
HTTP Server HIGH 7.3
CVE-2026-44185

Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP…

Fix: 2.4.68+
Fix from $1,950 2026-06-08
HTTP Server HIGH 7.3
CVE-2026-44186

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled ba…

Fix: 2.4.68+
Fix from $1,950 2026-06-08
HTTP Server MEDIUM 6.5
CVE-2026-43951

Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP…

Fix: after 2.4.67
Fix from $1,600 2026-06-08
HTTP Server MEDIUM 5.5
CVE-2026-44119

Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges…

Fix: 2.4.68+
Fix from $1,600 2026-06-08
HTTP Server CRITICAL 9.1
CVE-2026-42535

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases…

Fix: 2.4.68+
Fix from $2,300 2026-06-08
HTTP Server HIGH 7.5
CVE-2026-42536

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTT…

Fix: 2.4.68+
Fix from $1,950 2026-06-08
HTTP Server HIGH 7.5
CVE-2026-34355

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgra…

Fix: 2.4.68+
Fix from $1,950 2026-06-08