Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ranger CRITICAL 9.8
CVE-2026-44416

Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgra…

No fix yet
Fix from $5,750 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-55799

Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fi…

No fix yet
Fix from $5,750 2026-08-10
Ranger HIGH 7.5
CVE-2026-55814

Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

No fix yet
Fix from $4,900 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-28672

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger…

No fix yet
Fix from $5,750 2026-08-10
Fory CRITICAL 9.8
CVE-2026-71558

Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafte…

Fix: 1.5.0+
Fix from $2,300 2026-08-07
Fory CRITICAL 9.1
CVE-2026-71560

Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deser…

Fix: 1.5.0+
Fix from $2,300 2026-08-07
Fory HIGH 7.5
CVE-2026-71559

Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying …

Fix: 1.5.0+
Fix from $1,950 2026-08-07
Apr Util CRITICAL 9.1
CVE-2026-32327

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources an…

Fix: 1.6.4+
Fix from $2,300 2026-08-06
Apr Util CRITICAL 9.1
CVE-2026-34191

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_ora…

Fix: after 1.6.3
Fix from $2,300 2026-08-06
Apr Util HIGH 7.5
CVE-2026-34501

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1…

Fix: 1.6.4+
Fix from $1,950 2026-08-06
Apr Util HIGH 7.5
CVE-2026-34502

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: fro…

Fix: after 1.6.3
Fix from $1,950 2026-08-06
Apr Util HIGH 7.5
CVE-2025-49506

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potenti…

Fix: 1.6.4+
Fix from $1,950 2026-08-06
Cxf CRITICAL 9.8
CVE-2026-68079

In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the im…

Fix: 3.6.12 / 4.1.8+
Fix from $2,300 2026-08-06
Cxf HIGH 7.5
CVE-2026-68481

In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:tr…

Fix: 3.6.12 / 4.1.8+
Fix from $1,950 2026-08-06
Cxf CRITICAL 9.1
CVE-2026-61466

In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client reg…

Fix: 3.6.12 / 4.1.8+
Fix from $2,300 2026-08-06
Cxf CRITICAL 9.1
CVE-2026-63687

Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensiti…

Fix: 3.6.12 / 4.1.8+
Fix from $2,300 2026-08-06
Cxf CRITICAL 9.1
CVE-2026-65583

Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/…

Fix: 3.6.12 / 4.1.8+
Fix from $2,300 2026-08-06
Cxf HIGH 8.1
CVE-2026-57818

A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting…

Fix: 3.6.12 / 4.1.8+
Fix from $1,950 2026-08-06
Cxf CRITICAL 9.8
CVE-2026-66909

Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in pla…

Fix: 3.6.12 / 4.1.8+
Fix from $2,300 2026-08-06
Cxf HIGH 8.1
CVE-2026-57817

The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache C…

Fix: 3.6.12 / 4.1.8+
Fix from $1,950 2026-08-06
Cxf HIGH 7.5
CVE-2026-54225

Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no …

Fix: 3.6.12 / 4.1.8+
Fix from $1,950 2026-08-06
Cxf HIGH 7.5
CVE-2026-57819

Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, …

Fix: 3.6.12 / 4.1.8+
Fix from $1,950 2026-08-06
Cxf HIGH 7.5
CVE-2026-64958

An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with ma…

Fix: 3.6.12 / 4.1.8+
Fix from $1,950 2026-08-06
Cxf HIGH 7.5
CVE-2026-65432

Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <…

Fix: 3.6.12 / 4.1.8+
Fix from $1,950 2026-08-06
Polaris MEDIUM 6.5
CVE-2026-64640

Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permissi…

Fix: after 1.6.0
Fix from $1,600 2026-08-06
Answer CRITICAL 9.1
CVE-2026-60053

Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained u…

Fix: 2.0.2+
Fix from $2,300 2026-08-05
Answer HIGH 7.5
CVE-2026-60023

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Deleted…

Fix: 2.0.2+
Fix from $1,950 2026-08-05
Answer HIGH 7.5
CVE-2026-48911

Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing authoriza…

Fix: 2.0.2+
Fix from $1,950 2026-08-05
Answer MEDIUM 6.5
CVE-2026-48912

Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar…

Fix: 2.0.2+
Fix from $1,600 2026-08-05
Answer MEDIUM 6.5
CVE-2026-50749

Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary…

Fix: 2.0.2+
Fix from $1,600 2026-08-05