Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nifi HIGH 7.5
CVE-2026-68981

Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforc…

Fix: 2.11.0+
Fix from $1,950 2026-08-03
Nifi CRITICAL 9.8
CVE-2026-68979

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components refer…

Fix: 2.11.0+
Fix from $2,300 2026-08-03
Jena Fuseki HIGH 7.5
CVE-2026-61372

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena F…

Fix: 6.2.0+
Fix from $1,950 2026-08-03
Kyuubi HIGH 8.1
CVE-2026-62391

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-…

Fix: 1.12.0+
Fix from $1,950 2026-07-31
Httpclient MEDIUM 5.3
CVE-2026-64607

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an inv…

Fix: 5.6.3+
Fix from $1,600 2026-07-31
Zeppelin MEDIUM 6.5
CVE-2026-44615

Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a not…

Fix: 0.12.1+
Fix from $1,600 2026-07-31
Tika CRITICAL 9.8
CVE-2026-66756

Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users a…

No fix yet
Fix from $2,300 2026-07-30
Tika HIGH 7.5
CVE-2026-66755

Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker…

Fix: 3.3.2+
Fix from $1,950 2026-07-30
Kyuubi CRITICAL 9.8
CVE-2026-52680

Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote …

Fix: 1.12.0+
Fix from $2,300 2026-07-30
Jspwiki MEDIUM 6.5
CVE-2026-48910

A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the markdown renderer, which could …

Fix: 2.12.4+
Fix from $1,600 2026-07-30
Zeppelin MEDIUM 6.5
CVE-2026-44616

LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, al…

Fix: 0.12.1+
Fix from $1,600 2026-07-30
Zeppelin MEDIUM 6.5
CVE-2026-44617

LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing LDAP search filters ins…

Fix: 0.12.1+
Fix from $1,600 2026-07-30
Zeppelin MEDIUM 6.1
CVE-2026-44613

Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and a…

Fix: 0.12.1+
Fix from $1,600 2026-07-30
Jspwiki HIGH 8.8
CVE-2026-28813

Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.…

Fix: 2.12.4+
Fix from $1,950 2026-07-30
Jspwiki HIGH 7.5
CVE-2026-28814

Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWi…

Fix: 2.12.4+
Fix from $1,950 2026-07-30
Jspwiki CRITICAL 9.8
CVE-2026-28812

UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommende…

Fix: 2.12.4+
Fix from $2,300 2026-07-30
Jspwiki HIGH 7.5
CVE-2026-28811

Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes this…

Fix: 2.12.4+
Fix from $1,950 2026-07-30
Superset MEDIUM 6.5
CVE-2026-23985

A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The vulnerability is located in …

Fix: 6.0.0+
Fix from $1,600 2026-07-30
Apache Airflow Providers Fab CRITICAL 9.8
CVE-2026-59243

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or…

Fix: 3.7.3+
Fix from $2,300 2026-07-29
Traffic Server HIGH 8.2
CVE-2026-58188

Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 …

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Traffic Server HIGH 7.5
CVE-2026-58189

Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traf…

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Traffic Server CRITICAL 9.8
CVE-2026-58185

The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 thro…

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29
Traffic Server HIGH 8.6
CVE-2026-58182

The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Serv…

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Traffic Server HIGH 7.5
CVE-2026-58181

The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue affects Apache Traffic Server…

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Traffic Server HIGH 7.5
CVE-2026-58183

The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apache Traffic Server: from 8.0.0 …

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Traffic Server HIGH 7.5
CVE-2026-58184

The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects…

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Traffic Server HIGH 7.5
CVE-2026-58186

The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Ser…

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Traffic Server HIGH 7.5
CVE-2026-58187

The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apac…

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Traffic Server CRITICAL 9.8
CVE-2026-58177

The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Se…

Fix: 10.1.4+
Fix from $2,300 2026-07-29
Traffic Server CRITICAL 9.8
CVE-2026-58179

The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: fro…

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29