Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wicket MEDIUM 6.5
CVE-2026-66391

Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 throu…

Fix: 10.10.0+
Fix from $1,600 2026-07-27
Wicket MEDIUM 6.1
CVE-2026-66390

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicke…

Fix: 10.10.0+
Fix from $1,600 2026-07-27
Thrift MEDIUM 5.9
CVE-2026-66053

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.…

Fix: 0.24.0+
Fix from $1,600 2026-07-27
Thrift CRITICAL 9.8
CVE-2026-55971

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to u…

Fix: 0.24.0+
Fix from $2,300 2026-07-27
Thrift CRITICAL 9.1
CVE-2026-58023

Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrad…

Fix: 0.24.0+
Fix from $2,300 2026-07-27
Thrift CRITICAL 9.1
CVE-2026-58662

Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift…

Fix: 0.24.0+
Fix from $2,300 2026-07-27
Thrift HIGH 7.5
CVE-2026-58389

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. …

Fix: 0.24.0+
Fix from $1,950 2026-07-27
Thrift HIGH 7.5
CVE-2026-49158

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: bef…

Fix: 0.24.0+
Fix from $1,950 2026-07-27
Thrift HIGH 7.5
CVE-2026-55968

Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue…

Fix: 0.24.0+
Fix from $1,950 2026-07-27
Thrift HIGH 7.5
CVE-2026-55969

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: b…

Fix: 0.24.0+
Fix from $1,950 2026-07-27
Thrift MEDIUM 6.5
CVE-2026-55970

Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to …

Fix: 0.24.0+
Fix from $1,600 2026-07-27
Thrift CRITICAL 9.1
CVE-2026-48144

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.…

Fix: 0.24.0+
Fix from $2,300 2026-07-27
Thrift HIGH 7.5
CVE-2026-41608

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: b…

Fix: 0.24.0+
Fix from $1,950 2026-07-27
Thrift HIGH 7.5
CVE-2026-43871

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thr…

Fix: 0.24.0+
Fix from $1,950 2026-07-27
Thrift HIGH 7.5
CVE-2026-45112

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 bef…

Fix: 0.24.0+
Fix from $1,950 2026-07-27
Thrift HIGH 7.5
CVE-2026-48145

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. …

Fix: 0.24.0+
Fix from $1,950 2026-07-27
Thrift HIGH 7.5
CVE-2026-48586

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issu…

Fix: 0.24.0+
Fix from $1,950 2026-07-27
Hbase MEDIUM 6.5
CVE-2026-49326

Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest service has 3 steps, open, f…

Fix: 2.5.15 / 2.6.6+
Fix from $1,600 2026-07-24
Neethi HIGH 7.5
CVE-2026-66142

Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to …

Fix: 3.2.3+
Fix from $1,950 2026-07-24
Neethi HIGH 7.5
CVE-2026-66143

It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies…

No fix yet
Fix from $1,950 2026-07-24
Neethi HIGH 7.5
CVE-2026-66144

Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of …

Fix: 3.2.3+
Fix from $1,950 2026-07-24
Nimble MEDIUM 5.3
CVE-2026-46452

Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken data toward application resultin…

Fix: 1.10.0+
Fix from $1,600 2026-07-24
Nimble HIGH 8.8
CVE-2026-45813

Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS servic…

Fix: 1.10.0+
Fix from $1,950 2026-07-24
Nimble HIGH 7.5
CVE-2026-45815

Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigge…

Fix: 1.10.0+
Fix from $1,950 2026-07-24
Nimble HIGH 7.5
CVE-2026-45816

NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asserts (otherwise assert would tr…

Fix: 1.10.0+
Fix from $1,950 2026-07-24
Nimble HIGH 7.5
CVE-2026-45811

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether…

Fix: 1.10.0+
Fix from $1,950 2026-07-24
Nimble MEDIUM 6.5
CVE-2026-45812

Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event. When a single HCI advertisi…

Fix: 1.10.0+
Fix from $1,600 2026-07-24
Opennlp MEDIUM 5.6
CVE-2026-63317

Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected: - before 2.5.10 - before 3…

Fix: 2.5.11+
Fix from $1,600 2026-07-24
Fory HIGH 7.3
CVE-2026-60080

Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted …

Fix: 1.4.0+
Fix from $1,950 2026-07-21
Fory CRITICAL 9.8
CVE-2026-64606

Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lamb…

Fix: 1.4.0+
Fix from $2,300 2026-07-21