Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Skywalking HIGH 7.5
CVE-2026-30778

The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. This issue affects Apache SkyWa…

Fix: 10.4.0+
Fix from $1,950 2026-04-15
Airflow HIGH 8.1
CVE-2025-54550

The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xcom in the way that could be ex…

Fix: 3.2.0+
Fix from $1,950 2026-04-15
Apisix CRITICAL 9.1
CVE-2026-31908

Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious…

Fix: 3.16.0+
Fix from $2,300 2026-04-14
Apisix HIGH 7.5
CVE-2026-31923

Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configur…

Fix: 3.16.0+
Fix from $1,950 2026-04-14
Apisix MEDIUM 5.3
CVE-2026-31924

Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plaintext HTTP This issue affects …

Fix: 3.16.0+
Fix from $1,600 2026-04-14
Airflow HIGH 8.8
CVE-2026-33858

Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbit…

Fix: 3.2.0+
Fix from $1,950 2026-04-13
Airflow HIGH 7.5
CVE-2025-66236

Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to …

Fix: 3.2.0+
Fix from $1,950 2026-04-13
Skywalking Mcp HIGH 7.1
CVE-2026-34476

Server-Side Request Forgery via SW-URL Header vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are re…

Fix: 0.2.0+
Fix from $1,950 2026-04-13
Storm HIGH 8.8
CVE-2026-35337

Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credential…

Fix: 2.8.6+
Fix from $1,950 2026-04-13
Storm MEDIUM 5.4
CVE-2026-35565

Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6 Description: The Storm UI …

Fix: 2.8.6+
Fix from $1,600 2026-04-13
Log4net MEDIUM 5.3
CVE-2026-40021

Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J https://loggi…

Fix: 3.3.0+
Fix from $1,600 2026-04-10
Log4cxx MEDIUM 5.3
CVE-2026-40023

Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions before 1.7.0, fails to sanit…

Fix: 1.7.0+
Fix from $1,600 2026-04-10
Log4j HIGH 7.5
CVE-2026-34478

Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vul…

Fix: 2.25.4+
Fix from $1,950 2026-04-10
Log4j HIGH 7.5
CVE-2026-34479

The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML o…

Fix: 2.25.4+
Fix from $1,950 2026-04-10
Log4j HIGH 7.5
CVE-2026-34480

Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to …

Fix: 2.25.4+
Fix from $1,950 2026-04-10
Log4j HIGH 7.5
CVE-2026-34481

Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, pr…

Fix: 2.25.4+
Fix from $1,950 2026-04-10
Log4j MEDIUM 5.9
CVE-2026-34477

The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when ena…

Fix: 2.25.4+
Fix from $1,600 2026-04-10
Activemq HIGH 7.5
CVE-2026-39304

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do…

Fix: 5.19.4 / 6.2.4+
Fix from $1,950 2026-04-10
Tomcat HIGH 7.5
CVE-2026-34486 KEVEPSS 83%

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. …

Mitigation only
Fix from $1,950 2026-04-09
Tomcat HIGH 7.5
CVE-2026-34487

Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernet…

Fix: 9.0.117 / 10.1.54+
Fix from $1,950 2026-04-09
Tomcat MEDIUM 6.5
CVE-2026-34500

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affe…

Fix: 9.0.117 / 10.1.54+
Fix from $1,600 2026-04-09
Tomcat CRITICAL 9.1
CVE-2026-29145

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Nati…

Fix: 1.3.7 / 2.0.14+
Fix from $2,300 2026-04-09
Tomcat HIGH 7.5
CVE-2026-29146EPSS 6%

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 thro…

Fix: 9.0.116 / 10.1.53+
Fix from $1,950 2026-04-09
Tomcat HIGH 7.5
CVE-2026-24880

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This is…

Fix: 9.0.116 / 10.1.53+
Fix from $1,950 2026-04-09
Tomcat HIGH 7.5
CVE-2026-29129

Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, fro…

Fix: 9.0.116 / 10.1.53+
Fix from $1,950 2026-04-09
Tomcat HIGH 7.5
CVE-2026-34483

Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 1…

Fix: 9.0.117 / 10.1.54+
Fix from $1,950 2026-04-09
Tomcat MEDIUM 6.1
CVE-2026-25854

Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects …

Fix: 9.0.116 / 10.1.53+
Fix from $1,600 2026-04-09
Tomcat MEDIUM 5.3
CVE-2026-32990

Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 …

Fix: 9.0.116 / 10.1.53+
Fix from $1,600 2026-04-09
Openmeetings HIGH 7.5
CVE-2026-34020

Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint uses HTTP GET method with usern…

Fix: 9.0.0+
Fix from $1,950 2026-04-09
Openmeetings HIGH 7.5
CVE-2026-33266

Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set to default value in openmeeti…

Fix: 9.0.0+
Fix from $1,950 2026-04-09