Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ignite MEDIUM 6.5
CVE-2025-48977

Relative Path Traversal vulnerability in Apache Ignite REST API. Authenticated REST API users can read any file on the server with "cmd=log" command…

Fix: 2.18.0+
Fix from $1,600 2026-05-28
Flink Kubernetes Operator MEDIUM 6.5
CVE-2026-40564

Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The Flink…

Fix: 1.15.0+
Fix from $1,600 2026-05-26
Shiro MEDIUM 5.4
CVE-2026-48589

Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficie…

Fix: 2.2.1+
Fix from $1,600 2026-05-25
Shiro MEDIUM 6.5
CVE-2026-43827

Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. …

Fix: 2.1.1+
Fix from $1,600 2026-05-25
Shiro MEDIUM 6.5
CVE-2026-43828

Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.…

Fix: 2.1.1+
Fix from $1,600 2026-05-25
Shiro MEDIUM 5.4
CVE-2026-44598

With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro. …

Fix: 2.1.1+
Fix from $1,600 2026-05-25
Syncope HIGH 7.2
CVE-2026-42782

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can crea…

Fix: 4.0.6+
Fix from $1,950 2026-05-25
Apache Airflow Providers Fab MEDIUM 5.3
CVE-2026-46745

Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate director…

Fix: 3.6.4+
Fix from $1,600 2026-05-25
Apache Airflow Providers Google HIGH 8.1
CVE-2026-45361

Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worke…

Fix: 22.0.0+
Fix from $1,950 2026-05-25
Echarts MEDIUM 6.1
CVE-2026-45249

A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic. This issue affects Apache EChart…

Fix: 6.1.0+
Fix from $1,600 2026-05-25
Cxf CRITICAL 9.8
CVE-2026-44930

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certi…

Fix: 3.6.11 / 4.1.6+
Fix from $2,300 2026-05-22
Cxf HIGH 7.5
CVE-2026-44417

The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lea…

Fix: 3.6.11 / 4.1.6+
Fix from $1,950 2026-05-22
Cxf MEDIUM 5.3
CVE-2026-44618

Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users are recommended to upgrade to …

Fix: 3.6.11 / 4.1.6+
Fix from $1,600 2026-05-22
Fory CRITICAL 9.8
CVE-2026-48207

Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks dur…

Fix: 1.0.0+
Fix from $2,300 2026-05-21
Apache Airflow Providers Amazon MEDIUM 5.3
CVE-2026-42526

In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0, the team-scoping logic coul…

Fix: 9.28.0+
Fix from $1,600 2026-05-19
Apache Airflow Providers Cncf Kubernetes HIGH 8.7
CVE-2026-27173

JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow…

Fix: 10.17.0+
Fix from $1,950 2026-05-19
Camel CRITICAL 9.8
CVE-2026-47323

Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStrategy implementations (CxfRsHe…

Fix: 4.14.6 / 4.18.2+
Fix from $2,300 2026-05-19
Ofbiz CRITICAL 9.8
CVE-2026-45434EPSS 22%

Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBi…

Fix: 24.09.06+
Fix from $2,300 2026-05-19
Ofbiz CRITICAL 9.1
CVE-2026-31986

Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgra…

Fix: 24.09.06+
Fix from $2,300 2026-05-19
Ofbiz CRITICAL 9.1
CVE-2026-41919

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz:…

Fix: 24.09.06+
Fix from $2,300 2026-05-19
Ofbiz HIGH 8.8
CVE-2026-46586

Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vul…

Fix: 24.09.06+
Fix from $1,950 2026-05-19
Ofbiz HIGH 7.5
CVE-2026-31910

Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrad…

Fix: 24.09.06+
Fix from $1,950 2026-05-19
Ofbiz MEDIUM 6.5
CVE-2026-35086

Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue affects Apache OFBiz: before 2…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Ofbiz MEDIUM 6.5
CVE-2026-45187

Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade t…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Ofbiz HIGH 7.5
CVE-2026-31909

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users a…

Fix: 24.09.06+
Fix from $1,950 2026-05-19
Ofbiz MEDIUM 6.5
CVE-2026-31378

Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to vers…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Ofbiz MEDIUM 6.5
CVE-2026-31380

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in Apache OFBiz.…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Ofbiz MEDIUM 6.1
CVE-2026-31379

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('P…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Ofbiz MEDIUM 6.1
CVE-2026-31906

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz. This issue affects Apache OFBiz:…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Ofbiz MEDIUM 5.3
CVE-2026-31387

Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to versio…

Fix: 24.09.06+
Fix from $1,600 2026-05-19