Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tomcat HIGH 7.5
CVE-2025-48988EPSS 57%

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7…

Fix: 9.0.106 / 10.1.42+
Fix from $1,950 2025-06-16
Tomcat HIGH 7.5
CVE-2025-49125

Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat.  When using PreResources or PostResources mounted other than…

Fix: 9.0.106 / 10.1.42+
Fix from $1,950 2025-06-16
Nuttx CRITICAL 9.8
CVE-2025-47868

Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that…

Fix: 12.9.0+
Fix from $2,300 2025-06-16
Nuttx CRITICAL 9.8
CVE-2025-47869

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability was discovered in Apache NuttX RTOS apps/exapmles/xmlrpc applic…

Fix: 12.9.0+
Fix from $2,300 2025-06-16
Cloudstack HIGH 8.8
CVE-2025-47713

A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT d…

Fix: 4.19.3.0 / 4.20.1.0+
Fix from $1,950 2025-06-10
Cloudstack HIGH 8.8
CVE-2025-47849

A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT d…

Fix: 4.19.3.0 / 4.20.1.0+
Fix from $1,950 2025-06-10
Cloudstack HIGH 8.1
CVE-2025-26521

When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the API key and the secret key of the 'kubeadmin' user of…

Fix: 4.19.3.0 / 4.20.1.0+
Fix from $1,950 2025-06-10
Kafka HIGH 8.8
CVE-2025-27818

A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connec…

Fix: 3.9.1+
Fix from $1,950 2025-06-10
Kafka HIGH 7.5
CVE-2025-27817EPSS 65%

A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for …

Fix: 3.9.1+
Fix from $1,950 2025-06-10
Kafka HIGH 7.5
CVE-2025-27819

In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka…

Fix: after 3.3.2
Fix from $1,950 2025-06-10
Inlong CRITICAL 9.8
CVE-2025-27531

Deserialization of Untrusted Data vulnerability in Apache InLong.  This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would al…

Fix: 2.1.0+
Fix from $2,300 2025-06-06
Pekko Management MEDIUM 6.5
CVE-2025-46548

If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authen…

Fix: 1.6.1+
Fix from $1,600 2025-06-03
Superset MEDIUM 6.5
CVE-2025-48912

An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression'…

Fix: 4.1.2+
Fix from $1,600 2025-05-30
Tomcat HIGH 7.3
CVE-2025-46701

Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that app…

Fix: 9.0.105 / 10.1.41+
Fix from $1,950 2025-05-29
Commons Beanutils HIGH 8.8
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop att…

Fix: 1.11.0+
Fix from $1,950 2025-05-28
Inlong CRITICAL 9.1
CVE-2025-27528

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability …

Fix: 2.2.0+
Fix from $2,300 2025-05-28
Inlong MEDIUM 6.5
CVE-2025-27522

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability is…

Fix: 2.2.0+
Fix from $1,600 2025-05-28
Inlong MEDIUM 6.5
CVE-2025-27526

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability wh…

Fix: 2.2.0+
Fix from $1,600 2025-05-28
Nuttx CRITICAL 9.8
CVE-2025-35003

Improper Restriction of Operations within the Bounds of a Memory Buffer and Stack-based Buffer Overflow vulnerabilities were discovered in Apache Nut…

Fix: 12.9.0+
Fix from $2,300 2025-05-26
Orc CRITICAL 9.8
CVE-2025-47436

Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially …

Fix: 1.8.9 / 1.9.6+
Fix from $2,300 2025-05-14
Iotdb HIGH 7.5
CVE-2025-26864

Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of…

Fix: 1.3.4+
Fix from $1,950 2025-05-14
Iotdb HIGH 7.5
CVE-2025-26795

Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC drive…

Fix: 1.3.4 / 2.0.2+
Fix from $1,950 2025-05-14
Iotdb CRITICAL 9.8
CVE-2024-24780

Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious fu…

Fix: 1.3.4+
Fix from $2,300 2025-05-14
Superset HIGH 8.8
CVE-2025-27696

Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read…

Fix: 4.1.2+
Fix from $1,950 2025-05-13
Commons Configuration MEDIUM 6.5
CVE-2025-46392

Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x. There are a number of issues in Apache Commons Configuration 1.…

Fix: 2.0+
Fix from $1,600 2025-05-09
Activemq HIGH 7.5
CVE-2025-27533EPSS 9%

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers wa…

Fix: 5.16.8 / 5.17.7+
Fix from $1,950 2025-05-07
Parquet HIGH 8.1
CVE-2025-46762

Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code. While 1.15.1 i…

Fix: 1.15.2+
Fix from $1,950 2025-05-06
HTTP Server HIGH 7.5
CVE-2025-3891

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service …

Patch available
Fix from $1,950 2025-04-29
Tomcat CRITICAL 9.8
CVE-2025-31651

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, i…

Fix: 9.0.104 / 10.1.40+
Fix from $2,300 2025-04-28
Tomcat HIGH 7.5
CVE-2025-31650EPSS 60%

Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clea…

Fix: 9.0.104 / 10.1.40+
Fix from $1,950 2025-04-28