Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Answer HIGH 7.5
CVE-2026-48834

Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticate…

Fix: 2.0.2+
Fix from $1,950 2026-08-05
Lucy CRITICAL 9.8
CVE-2026-61484

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As th…

No fix yet
Fix from $2,300 2026-08-05
Lucy CRITICAL 9.8
CVE-2026-61486

** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this pro…

No fix yet
Fix from $2,300 2026-08-05
Lucy HIGH 7.5
CVE-2026-61485

** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue affects Apache Lucy: all versio…

No fix yet
Fix from $1,950 2026-08-05
Lucy HIGH 7.5
CVE-2026-61483

** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project …

No fix yet
Fix from $1,950 2026-08-05
Qpid Broker J MEDIUM 6.5
CVE-2026-68078

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso…

Fix: 10.1.0+
Fix from $1,600 2026-08-05
Qpid Broker J MEDIUM 6.5
CVE-2026-68080

It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resou…

Fix: 10.1.0+
Fix from $1,600 2026-08-05
Qpid Broker J MEDIUM 6.5
CVE-2026-68075

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache …

Fix: 10.1.0+
Fix from $1,600 2026-08-05
Qpid Broker J MEDIUM 6.5
CVE-2026-68077

An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading…

Fix: 10.1.0+
Fix from $1,600 2026-08-05
Qpid Protonj2 HIGH 7.5
CVE-2026-67592

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso…

Fix: 1.2.0+
Fix from $1,950 2026-08-05
Qpid Proton Dotnet HIGH 7.5
CVE-2026-67552

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects…

Fix: 1.1.0+
Fix from $1,950 2026-08-05
Qpid Protonj2 HIGH 7.5
CVE-2026-67590

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects…

Fix: 1.2.0+
Fix from $1,950 2026-08-05
Qpid Broker J HIGH 7.5
CVE-2026-68073

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects…

Fix: 10.1.0+
Fix from $1,950 2026-08-05
Qpid Proton Dotnet MEDIUM 6.5
CVE-2026-67554

An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading…

Fix: 1.1.0+
Fix from $1,600 2026-08-05
Qpid Proton Dotnet MEDIUM 6.5
CVE-2026-67555

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso…

Fix: 1.1.0+
Fix from $1,600 2026-08-05
Qpid Proton Dotnet MEDIUM 6.5
CVE-2026-67553

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache …

Fix: 1.1.0+
Fix from $1,600 2026-08-05
Qpid Protonj2 MEDIUM 6.5
CVE-2026-67591

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache …

Fix: 1.2.0+
Fix from $1,600 2026-08-05
Qpid Proton J HIGH 7.5
CVE-2026-66274

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects…

Fix: 0.35.0+
Fix from $1,950 2026-08-05
Qpid Proton J MEDIUM 6.5
CVE-2026-66277

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso…

Fix: 0.35.0+
Fix from $1,600 2026-08-05
Qpid Proton J MEDIUM 6.5
CVE-2026-66275

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache …

Fix: 0.35.0+
Fix from $1,600 2026-08-05
Qpid Proton J MEDIUM 6.5
CVE-2026-66276

An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading…

Fix: 0.35.0+
Fix from $1,600 2026-08-05
Qpid Proton Dotnet HIGH 7.5
CVE-2026-67465

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af…

Fix: 1.1.0+
Fix from $1,950 2026-08-05
Qpid Proton Dotnet HIGH 7.5
CVE-2026-67551

pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue…

Fix: 1.1.0+
Fix from $1,950 2026-08-05
Qpid Protonj2 HIGH 7.5
CVE-2026-67588

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af…

Fix: 1.2.0+
Fix from $1,950 2026-08-05
Qpid Protonj2 HIGH 7.5
CVE-2026-67589

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This iss…

Fix: 1.2.0+
Fix from $1,950 2026-08-05
Qpid Broker J HIGH 7.5
CVE-2026-68060

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This iss…

Fix: 10.1.0+
Fix from $1,950 2026-08-05
Qpid Broker J HIGH 7.5
CVE-2026-68074

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af…

Fix: 10.1.0+
Fix from $1,950 2026-08-05
Qpid Proton J HIGH 7.5
CVE-2026-66257

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af…

Fix: 0.35.0+
Fix from $1,950 2026-08-05
Qpid Proton J HIGH 7.5
CVE-2026-66273

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This iss…

Fix: 0.35.0+
Fix from $1,950 2026-08-05
Nifi CRITICAL 9.1
CVE-2026-68980

Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framewor…

Fix: 2.11.0+
Fix from $2,300 2026-08-03