Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Airflow CRITICAL 9.1
CVE-2025-57735

When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was inte…

Fix: 3.2.0+
Fix from $2,300 2026-04-09
Airflow MEDIUM 6.5
CVE-2026-34538

Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint returns XCom result values even to users who only have DAG Run read permissions, suc…

Fix: 3.2.0+
Fix from $1,600 2026-04-09
Dolphinscheduler HIGH 7.5
CVE-2025-62188

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vulnerability may allow unauthor…

Fix: 3.2.0+
Fix from $1,950 2026-04-09
Cassandra MEDIUM 6.5
CVE-2026-32588

Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes. Users …

Fix: 4.0.20 / 4.1.11+
Fix from $1,600 2026-04-07
Cassandra HIGH 8.8
CVE-2026-27314

Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associa…

Fix: 5.0.7+
Fix from $1,950 2026-04-07
Cassandra MEDIUM 5.5
CVE-2026-27315

Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from previously executed cqlsh co…

Fix: 4.0.20+
Fix from $1,600 2026-04-07
Kafka HIGH 8.7
CVE-2026-35554

A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. …

Fix: 3.9.2 / 4.0.2+
Fix from $1,950 2026-04-07
Activemq HIGH 8.8
CVE-2026-34197 KEVEPSS 97%

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apach…

Fix: 5.19.4 / 6.2.3+
Fix from $1,950 2026-04-07
Traffic Server HIGH 7.5
CVE-2025-65114

Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffic Server: from 9.0.0 through 9.2.…

Fix: 9.2.13 / 10.1.2+
Fix from $1,950 2026-04-02
Traffic Server HIGH 7.5
CVE-2025-58136

A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from …

Fix: 9.2.13 / 10.1.2+
Fix from $1,950 2026-04-02
Airflow HIGH 8.1
CVE-2026-30911

Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows…

Fix: 3.1.8+
Fix from $1,950 2026-03-17
Airflow HIGH 7.5
CVE-2026-28779

Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configured [webserver] base_url or […

Fix: 3.1.8+
Fix from $1,950 2026-03-17
Airflow MEDIUM 6.5
CVE-2026-26929

Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filtering when the request is made wi…

Fix: 3.1.8+
Fix from $1,600 2026-03-17
Spark HIGH 8.8
CVE-2025-54920EPSS 5%

This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue.…

Fix: 3.5.7+
Fix from $1,950 2026-03-16
Livy MEDIUM 6.3
CVE-2025-60012

Malicious configuration can lead to unauthorized file access in Apache Livy. This issue affects Apache Livy 0.7.0 and 0.8.0 when connecting to Apach…

Fix: 0.9.0+
Fix from $1,600 2026-03-13
Livy MEDIUM 6.3
CVE-2025-66249

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy. This issue affects Apache Livy: from 0.…

Fix: 0.9.0+
Fix from $1,600 2026-03-13
Pdfbox MEDIUM 5.3
CVE-2026-23907

This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFil…

Fix: after 3.0.7
Fix from $1,600 2026-03-10
Apache Airflow Providers Amazon MEDIUM 5.4
CVE-2026-25604

In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. …

Fix: 9.22.0+
Fix from $1,600 2026-03-09
Airflow Providers Http HIGH 8.8
CVE-2025-69219

A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives anyone who have access to DB…

Fix: 6.0.0+
Fix from $1,950 2026-03-09
Iotdb CRITICAL 9.8
CVE-2026-24015

A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrad…

Fix: 1.3.7 / 2.0.7+
Fix from $2,300 2026-03-09
Iotdb CRITICAL 9.8
CVE-2026-24713

Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users a…

Fix: 1.3.7 / 2.0.7+
Fix from $2,300 2026-03-09
Zookeeper HIGH 7.5
CVE-2026-24308

Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive inf…

Fix: 3.8.6 / 3.9.5+
Fix from $1,950 2026-03-07
Zookeeper HIGH 7.4
CVE-2026-24281

Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control…

Fix: 3.8.6 / 3.9.5+
Fix from $1,950 2026-03-07
Artemis CRITICAL 9.8
CVE-2026-27446EPSS 10%

Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker c…

Fix: after 2.44.0
Fix from $2,300 2026-03-04
Activemq HIGH 8.8
CVE-2025-66168

WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases. See the  following for more details: https:…

Fix: 5.19.2+
Fix from $1,950 2026-03-04
Ranger CRITICAL 9.8
CVE-2025-59059

Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to…

Fix: 2.8.0+
Fix from $2,300 2026-03-03
Ranger MEDIUM 5.3
CVE-2025-59060

Hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient is reported in Apache Ranger versions <= 2.7.0. Users are recommen…

Fix: 2.8.0+
Fix from $1,600 2026-03-03
Superset MEDIUM 6.5
CVE-2026-23983

A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoi…

Fix: 6.0.0+
Fix from $1,600 2026-02-24
Superset MEDIUM 6.5
CVE-2026-23984

An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab access to bypass the read-only ver…

Fix: 6.0.0+
Fix from $1,600 2026-02-24
Superset MEDIUM 6.5
CVE-2026-23969

Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within…

Fix: 4.1.2+
Fix from $1,600 2026-02-24