Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ofbiz MEDIUM 5.3
CVE-2026-31388

Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affects Apache OFBiz: before 24.09.06. Users are reco…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Ofbiz HIGH 7.3
CVE-2026-29226

Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations. This issue affects Apache OFBiz: before 24.09.06.…

Fix: 24.09.06+
Fix from $1,950 2026-05-19
Ofbiz MEDIUM 6.5
CVE-2026-29207

Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.0…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Ofbiz MEDIUM 6.5
CVE-2026-29220

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: befor…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Flink HIGH 8.1
CVE-2026-35194

Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission pr…

Fix: 1.20.4 / 2.0.2+
Fix from $1,950 2026-05-15
Commons Configuration MEDIUM 5.3
CVE-2026-45205

Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOve…

Fix: 2.15.0+
Fix from $1,600 2026-05-14
Tomcat CRITICAL 9.1
CVE-2026-43515

Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affe…

Fix: 9.0.118 / 10.1.55+
Fix from $2,300 2026-05-12
Tomcat HIGH 7.5
CVE-2026-43513

Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.…

Fix: 9.0.118 / 10.1.55+
Fix from $1,950 2026-05-12
Tomcat CRITICAL 9.8
CVE-2026-41293

Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 1…

Fix: 9.0.118 / 10.1.55+
Fix from $2,300 2026-05-12
Tomcat CRITICAL 9.8
CVE-2026-43512

DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 t…

Fix: 9.0.118 / 10.1.55+
Fix from $2,300 2026-05-12
Tomcat HIGH 7.3
CVE-2026-42498

Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache…

Fix: 9.0.118 / 10.1.55+
Fix from $1,950 2026-05-12
Tomcat HIGH 7.5
CVE-2026-41284

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2…

Fix: 9.0.118 / 10.1.55+
Fix from $1,950 2026-05-12
Apache Airflow Providers Opensearch MEDIUM 6.5
CVE-2026-43826

The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:[email protected]:920…

Fix: 1.9.1+
Fix from $1,600 2026-05-11
Apache Airflow Providers Elasticsearch MEDIUM 6.5
CVE-2026-41018

The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:[email protected]:…

Fix: 6.5.3+
Fix from $1,600 2026-05-11
Nifi HIGH 8.8
CVE-2026-39816

The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi…

Fix: 2.9.0+
Fix from $1,950 2026-05-08
Cloudstack CRITICAL 9.1
CVE-2026-25199

Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudSt…

Fix: 4.22.0.1+
Fix from $2,300 2026-05-08
Cloudstack HIGH 8.8
CVE-2026-25077

Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hyp…

Fix: 4.20.3.0 / 4.22.0.1+
Fix from $1,950 2026-05-08
Cloudstack HIGH 8.1
CVE-2025-66172

The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudSt…

Fix: 4.22.0.1+
Fix from $1,950 2026-05-08
Cloudstack HIGH 8.1
CVE-2025-66467

Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If anothe…

Fix: 4.20.3.0 / 4.22.0.1+
Fix from $1,950 2026-05-08
Cloudstack MEDIUM 6.5
CVE-2025-66170

The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in …

Fix: 4.22.0.1+
Fix from $1,600 2026-05-08
Cloudstack MEDIUM 6.5
CVE-2025-66171

The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudSt…

Fix: 4.22.0.1+
Fix from $1,600 2026-05-08
Cloudstack MEDIUM 5.3
CVE-2025-69233

Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of t…

Fix: 4.20.3.0 / 4.22.0.1+
Fix from $1,600 2026-05-08
Wicket HIGH 7.5
CVE-2026-43646

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17…

Fix: 10.9.0+
Fix from $1,950 2026-05-06
Wicket MEDIUM 6.5
CVE-2026-43975

FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file p…

Fix: 10.9.0+
Fix from $1,600 2026-05-06
Wicket CRITICAL 9.1
CVE-2026-40010

Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache …

Fix: 10.9.0+
Fix from $2,300 2026-05-06
Wicket MEDIUM 6.1
CVE-2026-42509

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicke…

Fix: 10.9.0+
Fix from $1,600 2026-05-06
HTTP Server CRITICAL 9.8
CVE-2026-28780

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server …

Fix: 2.4.67+
Fix from $2,300 2026-05-05
HTTP Server HIGH 7.3
CVE-2026-29168

Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data. This issue affects Apache…

Fix: 2.4.67+
Fix from $1,950 2026-05-05
Thrift HIGH 7.3
CVE-2026-43870

Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in…

Fix: 0.23.0+
Fix from $1,950 2026-05-05
Thrift MEDIUM 5.3
CVE-2026-43868

Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended …

Fix: 0.23.0+
Fix from $1,600 2026-05-05