Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nimble HIGH 8.1
CVE-2025-62235

Authentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could lead to removal of original bon…

Fix: 1.9.0+
Fix from $1,950 2026-01-10
Nimble HIGH 7.5
CVE-2025-52435

J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE. Improper handling of Pause Encryption procedure on Link …

Fix: 1.9.0+
Fix from $1,950 2026-01-10
Nimble HIGH 7.5
CVE-2025-53477

NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL p…

Fix: 1.9.0+
Fix from $1,950 2026-01-10
Uniffle CRITICAL 9.1
CVE-2025-68637

The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This insecure configuration expos…

Fix: 0.10.0+
Fix from $2,300 2026-01-07
Spatial Information System MEDIUM 6.5
CVE-2025-68280

Improper Restriction of XML External Entity Reference vulnerability in Apache SIS. It is possible to write XML files in such a way that, when pars…

Fix: after 1.5
Fix from $1,600 2026-01-05
Kyuubi HIGH 8.8
CVE-2025-66518

Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and…

Fix: 1.10.3+
Fix from $1,950 2026-01-05
Nuttx HIGH 8.1
CVE-2025-48769

Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer us…

Fix: 12.11.0+
Fix from $1,950 2026-01-01
Nuttx MEDIUM 6.5
CVE-2025-48768

Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX RTOS that allowed root files…

Fix: 12.10.0+
Fix from $1,600 2026-01-01
Streampipes HIGH 8.1
CVE-2025-47411EPSS 15%

A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows th…

Fix: 0.98.0+
Fix from $1,950 2026-01-01
Nifi HIGH 8.8
CVE-2025-66524

Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Ser…

Fix: 2.7.0+
Fix from $1,950 2025-12-19
Apache Airflow Providers Edge3 CRITICAL 9.8
CVE-2025-67895

Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on …

Fix: 2.0.0+
Fix from $2,300 2025-12-17
Airflow MEDIUM 6.5
CVE-2025-66388

A vulnerability in Apache Airflow allowed authenticated UI users to view secret values in rendered templates due to secrets not being properly redact…

Fix: 3.1.4+
Fix from $1,600 2025-12-15
Streampark MEDIUM 5.9
CVE-2025-53960

When issuing JSON Web Tokens (JWT), Apache StreamPark directly uses the user's password as the HMAC signing key (e.g., with the HS256 algorithm). An …

Fix: 2.1.7+
Fix from $1,600 2025-12-12
Streampark CRITICAL 9.8
CVE-2025-54947

In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs b…

Fix: 2.1.7+
Fix from $2,300 2025-12-12
Streampark HIGH 7.5
CVE-2025-54981

Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, inclu…

Fix: 2.1.7+
Fix from $1,950 2025-12-12
Fineract CRITICAL 9.1
CVE-2025-58130

Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in ver…

Fix: 1.12.1+
Fix from $2,300 2025-12-12
Hugegraph HIGH 8.8
CVE-2025-26866

A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix en…

Fix: 1.7.0+
Fix from $1,950 2025-12-12
Fineract HIGH 8.1
CVE-2025-58137

Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is …

Fix: 1.12.1+
Fix from $1,950 2025-12-12
Fineract MEDIUM 6.5
CVE-2025-23408

Weak Password Requirements vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.10.1. The issue is fixed in version 1.11.…

Fix: 1.11.0+
Fix from $1,600 2025-12-12
Struts HIGH 8.2
CVE-2025-66675

Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts…

Fix: 6.8.0 / 7.1.1+
Fix from $1,950 2025-12-10
HTTP Server HIGH 8.3
CVE-2025-58098

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to…

Fix: 2.4.66+
Fix from $1,950 2025-12-05
HTTP Server HIGH 7.5
CVE-2025-59775

Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off  allows to po…

Fix: 2.4.66+
Fix from $1,950 2025-12-05
HTTP Server MEDIUM 6.5
CVE-2025-65082

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache co…

Fix: 2.4.66+
Fix from $1,600 2025-12-05
HTTP Server MEDIUM 5.4
CVE-2025-66200

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in hta…

Fix: 2.4.66+
Fix from $1,600 2025-12-05
HTTP Server HIGH 7.5
CVE-2025-55753

An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the bac…

Fix: 2.4.66+
Fix from $1,950 2025-12-05
Tika CRITICAL 9.8
CVE-2025-66516EPSS 79%

Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an a…

Fix: 3.2.2+
Fix from $2,300 2025-12-04
Struts HIGH 7.5
CVE-2025-64775

Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts…

Fix: 6.8.0 / 7.1.1+
Fix from $1,950 2025-12-01
Brpc HIGH 7.5
CVE-2025-59789

Uncontrolled recursion in the json2pb component in Apache bRPC (version < 1.15.0) on all platforms allows remote attackers to make the server crash v…

Fix: 1.15.0+
Fix from $1,950 2025-12-01
Kvrocks MEDIUM 5.3
CVE-2025-59792

Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. …

Fix: 2.14.0+
Fix from $1,600 2025-11-28
Kvrocks MEDIUM 5.4
CVE-2025-59790

Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommende…

Fix: 2.14.0+
Fix from $1,600 2025-11-28