Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jspwiki HIGH 7.5
CVE-2025-24853

A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the v…

Fix: 2.12.3+
Fix from $1,950 2025-07-31
Struts Extras MEDIUM 6.5
CVE-2025-54656

** UNSUPPORTED WHEN ASSIGNED ** Improper Output Neutralization for Logs vulnerability in Apache Struts. This issue affects Apache Struts Extras: bef…

Fix: 2.0+
Fix from $1,600 2025-07-30
HTTP Server MEDIUM 6.3
CVE-2025-54090

A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2…

Patch available
Fix from $1,600 2025-07-23
Jena HIGH 8.8
CVE-2025-50151

File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to…

Fix: 5.5.0+
Fix from $1,950 2025-07-21
Jena HIGH 7.5
CVE-2025-49656

Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to…

Fix: 5.5.0+
Fix from $1,950 2025-07-21
Cxf MEDIUM 5.6
CVE-2025-48795

Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary …

Mitigation only
Fix from $1,600 2025-07-15
Jackrabbit HIGH 8.8
CVE-2025-53689

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to …

Fix: 2.20.17+
Fix from $1,950 2025-07-14
Zeppelin HIGH 7.5
CVE-2024-41169

The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files…

Fix: 0.12.0+
Fix from $1,950 2025-07-12
Commons Lang MEDIUM 5.3
CVE-2025-48924

Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to …

Fix: 2.6 / 3.18.0+
Fix from $1,600 2025-07-11
Tomcat HIGH 7.5
CVE-2025-53506

Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the …

Fix: after 11.0.8
Fix from $1,950 2025-07-10
Tomcat HIGH 7.5
CVE-2025-52434

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native …

Fix: 9.0.107+
Fix from $1,950 2025-07-10
Tomcat HIGH 7.5
CVE-2025-52520

For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size li…

Fix: 9.0.107 / 10.1.43+
Fix from $1,950 2025-07-10
HTTP Server HIGH 7.5
CVE-2025-49630

In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untruste…

Fix: 2.4.64+
Fix from $1,950 2025-07-10
HTTP Server HIGH 7.5
CVE-2025-53020

Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63…

Fix: 2.4.64+
Fix from $1,950 2025-07-10
HTTP Server HIGH 7.4
CVE-2025-49812

In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker…

Fix: 2.4.64+
Fix from $1,950 2025-07-10
HTTP Server CRITICAL 9.1
CVE-2025-23048

In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 …

Fix: 2.4.64+
Fix from $2,300 2025-07-10
HTTP Server HIGH 7.5
CVE-2024-43394

Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via  mod_rewrite or …

Fix: 2.4.64+
Fix from $1,950 2025-07-10
HTTP Server HIGH 7.5
CVE-2024-47252

Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape c…

Fix: 2.4.64+
Fix from $1,950 2025-07-10
HTTP Server HIGH 7.5
CVE-2024-42516

HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hos…

Fix: 2.4.64+
Fix from $1,950 2025-07-10
HTTP Server HIGH 7.5
CVE-2024-43204

SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker.  Requires an…

Fix: 2.4.64+
Fix from $1,950 2025-07-10
Apisix HIGH 7.8
CVE-2025-27446

Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listening file permissions in APISIX…

Fix: after 0.5
Fix from $1,950 2025-07-06
Apisix MEDIUM 5.3
CVE-2025-46647

A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an impact if all of the following conditions are met: 1…

Fix: 3.12.0+
Fix from $1,600 2025-07-02
Guacamole HIGH 7.5
CVE-2024-35164

The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers via text-based protocols lik…

Fix: 1.6.0+
Fix from $1,950 2025-07-02
Seata CRITICAL 9.8
CVE-2025-32897

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the ver…

Fix: 2.3.0+
Fix from $2,300 2025-06-28
Apache Airflow Providers Snowflake CRITICAL 9.8
CVE-2025-50213

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This is…

Fix: 6.4.0+
Fix from $2,300 2025-06-24
Seatunnel MEDIUM 6.5
CVE-2025-32896

# Summary Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api-v1. # Details Unauthorized …

Fix: 2.3.11+
Fix from $1,600 2025-06-19
Traffic Server HIGH 7.5
CVE-2025-49763

ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. …

Fix: 9.2.11 / 10.0.6+
Fix from $1,950 2025-06-19
Traffic Server HIGH 7.5
CVE-2025-31698

ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.…

Fix: 9.2.11 / 10.0.6+
Fix from $1,950 2025-06-19
Tomcat HIGH 8.4
CVE-2025-49124

Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe wit…

Fix: 9.0.106 / 10.1.42+
Fix from $1,950 2025-06-16
Commons Fileupload HIGH 7.5
CVE-2025-48976EPSS 68%

Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects …

Fix: 1.6+
Fix from $1,950 2025-06-16