Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Superset MEDIUM 6.5
CVE-2026-23980

Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user wit…

Fix: 6.0.0+
Fix from $1,600 2026-02-24
Superset MEDIUM 6.5
CVE-2026-23982

An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a d…

Fix: 6.0.0+
Fix from $1,600 2026-02-24
Airflow HIGH 8.4
CVE-2024-56373

DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server…

Fix: 2.11.1+
Fix from $1,950 2026-02-24
Airflow MEDIUM 6.5
CVE-2025-27555

Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which…

Fix: 2.11.1+
Fix from $1,600 2026-02-24
Camel HIGH 8.8
CVE-2026-25747

Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes dat…

Fix: 4.10.9 / 4.14.5+
Fix from $1,950 2026-02-23
Camel CRITICAL 9.1
CVE-2026-23552

Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.  The Camel-Keycloak KeycloakSecurityPolicy does not v…

Fix: 4.18.0+
Fix from $2,300 2026-02-23
Airflow MEDIUM 6.5
CVE-2025-65995

When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operators. If those kwargs containe…

Fix: 2.11.1 / 3.1.4+
Fix from $1,600 2026-02-21
Tomcat HIGH 7.5
CVE-2026-24734

Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port o…

Fix: 1.3.5 / 2.0.12+
Fix from $1,950 2026-02-17
Tomcat CRITICAL 9.1
CVE-2025-66614

Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.…

Fix: 9.0.113 / 10.1.50+
Fix from $2,300 2026-02-17
Arrow HIGH 7.0
CVE-2026-25087

Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading a…

Fix: 23.0.1+
Fix from $1,950 2026-02-17
Nifi MEDIUM 6.6
CVE-2026-25903

Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required …

Fix: 2.8.0+
Fix from $1,600 2026-02-17
Avro HIGH 7.3
CVE-2025-33042

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro …

Fix: 1.11.5+
Fix from $1,950 2026-02-13
Druid CRITICAL 9.8
CVE-2026-23906

Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * d…

Fix: 36.0.0+
Fix from $2,300 2026-02-10
Hertzbeat HIGH 8.8
CVE-2026-24343

Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat:…

Fix: 1.8.0+
Fix from $1,950 2026-02-10
Airflow MEDIUM 6.5
CVE-2026-24098

Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view impo…

Fix: 3.1.7+
Fix from $1,600 2026-02-09
Airflow MEDIUM 6.5
CVE-2026-22922

Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that can allow an authenticated user with custom permissions limited to tas…

Fix: 3.1.7+
Fix from $1,600 2026-02-09
Shiro MEDIUM 5.3
CVE-2026-23903

Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are recommended to upgr…

Fix: 2.0.7+
Fix from $1,600 2026-02-09
Answer HIGH 7.5
CVE-2026-24735

Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 1.7.1. …

Fix: 2.0.0+
Fix from $1,950 2026-02-04
Syncope MEDIUM 6.8
CVE-2026-23794

Reflected XSS in Apache Syncope's Enduser Login page. An attacker that tricks a legitimate user into clicking a malicious link and logging in to Sync…

Fix: 3.0.16 / 4.0.4+
Fix from $1,600 2026-02-03
Continuum CRITICAL 9.9
CVE-2016-15057

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum…

Mitigation only
Fix from $2,300 2026-01-26
Hadoop HIGH 7.3
CVE-2025-27821

Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client. This issue affects Apache Hadoop: from 3.2.0 before 3.4.2. Users are recomme…

Fix: 3.4.2+
Fix from $1,950 2026-01-26
Solr HIGH 8.2
CVE-2026-22022

Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule Based Authorization Plugin" are vulnerable to allowing unauthorized access …

Fix: 9.10.1+
Fix from $1,950 2026-01-21
Solr HIGH 7.1
CVE-2026-22444

The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient input validation on some API parameters, which can cause Solr to check the e…

Fix: 9.10.1+
Fix from $1,950 2026-01-21
Linkis MEDIUM 6.5
CVE-2025-59355

A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records the complete input parameter s…

Fix: 1.8.0+
Fix from $1,600 2026-01-19
Linkis HIGH 7.5
CVE-2025-29847

A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and data source functionality, if…

Fix: 1.8.0+
Fix from $1,950 2026-01-19
Airflow HIGH 7.5
CVE-2025-68438

In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length, sensitive values could be e…

Fix: 3.1.6+
Fix from $1,950 2026-01-16
Airflow HIGH 7.5
CVE-2025-68675

In Apache Airflow versions before 3.1.6, and 2.11.1 the proxies and proxy fields within a Connection may include proxy URLs containing embedded authe…

Fix: 3.1.6+
Fix from $1,950 2026-01-16
Brpc CRITICAL 9.8
CVE-2025-60021EPSS 25%

Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to …

Fix: 1.15.0+
Fix from $2,300 2026-01-16
Camel MEDIUM 5.3
CVE-2025-66169

Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before…

Fix: 4.10.8 / 4.14.3+
Fix from $1,600 2026-01-14
Struts HIGH 8.1
CVE-2025-68493EPSS 37%

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from…

Fix: 6.1.1+
Fix from $1,950 2026-01-11