Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HTTP Server HIGH 7.5
CVE-2026-34356

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache …

Fix: 2.4.68+
Fix from $1,950 2026-06-08
HTTP Server MEDIUM 6.1
CVE-2026-29170

A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing F…

Fix: 2.4.68+
Fix from $1,600 2026-06-08
HTTP Server CRITICAL 9.8
CVE-2026-29167

Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 th…

Fix: 2.4.68+
Fix from $2,300 2026-06-08
Cordova Inappbrowser HIGH 7.5
CVE-2026-47430

## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body to `commandDelegate sendPlugi…

Fix: 6.0.1+
Fix from $1,950 2026-06-08
Fory CRITICAL 9.1
CVE-2026-50076

Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remo…

Fix: 1.1.0+
Fix from $2,300 2026-06-04
Mina CRITICAL 9.8
CVE-2026-47065

ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the seri…

Mitigation only
Fix from $2,300 2026-06-03
Calcite MEDIUM 6.5
CVE-2026-46718

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite. This issue affects Apache Calcit…

Fix: 1.42.0+
Fix from $1,600 2026-06-02
Fesod MEDIUM 5.3
CVE-2026-49328

Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) fesod-sheet before 2.0.2-incubating allows attacke…

Fix: 2.0.2+
Fix from $1,600 2026-06-01
Activemq HIGH 8.8
CVE-2026-49157

Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The def…

Fix: 5.19.7 / 6.2.6+
Fix from $1,950 2026-06-01
Airflow HIGH 8.8
CVE-2026-49298

A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the work…

Fix: 3.2.2+
Fix from $1,950 2026-06-01
Fluss HIGH 7.5
CVE-2026-49361

Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing un…

Fix: 0.9.1+
Fix from $1,950 2026-06-01
Mina Sshd HIGH 7.1
CVE-2026-48827

Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operati…

Fix: 2.18.0+
Fix from $1,950 2026-06-01
Airflow MEDIUM 6.5
CVE-2026-48726

A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked logout in the UI: the logout fl…

Fix: 3.2.2+
Fix from $1,600 2026-06-01
Airflow MEDIUM 5.9
CVE-2026-49267

Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections without verifying the remote ce…

Fix: 3.2.2+
Fix from $1,600 2026-06-01
Activemq MEDIUM 5.9
CVE-2026-49270

Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are c…

Fix: 5.19.7 / 6.2.6+
Fix from $1,600 2026-06-01
Solr CRITICAL 9.8
CVE-2026-44825

Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a …

Fix: after 9.10.1
Fix from $2,300 2026-06-01
Activemq HIGH 8.8
CVE-2026-45505

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap…

Fix: 5.19.7 / 6.2.6+
Fix from $1,950 2026-06-01
Activemq HIGH 8.1
CVE-2026-42588

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap…

Fix: 5.19.7 / 6.2.6+
Fix from $1,950 2026-06-01
Airflow HIGH 7.3
CVE-2026-45360

Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported and dispatched arbitrary clas…

Fix: 3.2.2+
Fix from $1,950 2026-06-01
Airflow MEDIUM 6.5
CVE-2026-42360

A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` / `token` / `secret` / `api_ke…

Fix: 3.2.2+
Fix from $1,600 2026-06-01
Airflow CRITICAL 9.1
CVE-2026-42252

Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a verbatim `BashOperator(b…

Fix: 3.2.2+
Fix from $2,300 2026-06-01
Airflow HIGH 8.8
CVE-2026-42359

A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user with XCom write permission on a …

Fix: 3.2.2+
Fix from $1,950 2026-06-01
Airflow HIGH 7.5
CVE-2026-41084

A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstances`) evaluated authorization a…

Fix: 3.2.2+
Fix from $1,950 2026-06-01
Airflow HIGH 7.2
CVE-2026-40961

A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe_url` check, enabling redirec…

Fix: 3.2.2+
Fix from $1,950 2026-06-01
Airflow MEDIUM 6.5
CVE-2026-42358

A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names like `password`, `token`, `sec…

Fix: 3.2.2+
Fix from $1,600 2026-06-01
Activemq MEDIUM 6.1
CVE-2026-42253

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. The Mess…

Fix: 5.19.7 / 6.2.6+
Fix from $1,600 2026-06-01
Airflow MEDIUM 5.9
CVE-2026-41017

Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Airflow API server behind an HT…

Fix: 3.2.2+
Fix from $1,600 2026-06-01
Airflow MEDIUM 6.5
CVE-2026-40861

A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable by the API server process (rea…

Fix: 3.2.2+
Fix from $1,600 2026-06-01
Directory Ldap Api HIGH 8.5
CVE-2026-35563

It was identified that the LDAP client implementation in version 2.1.7 does not verify if the server certificate matches the intended LDAP hostname.…

Fix: 2.1.7+
Fix from $1,950 2026-06-01
Airflow MEDIUM 6.5
CVE-2026-45192

A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed an authenticated UI/API user with Connection-read …

Fix: 3.2.2+
Fix from $1,600 2026-06-01