Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fory CRITICAL 9.1
CVE-2026-64609

Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the b…

Fix: 1.4.0+
Fix from $2,300 2026-07-21
Fory CRITICAL 9.8
CVE-2026-64608

Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip pa…

Fix: 1.4.0+
Fix from $2,300 2026-07-21
Mina Sshd HIGH 7.3
CVE-2026-56624

Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH. Server…

Fix: 2.19.0+
Fix from $1,950 2026-07-20
Mina Sshd MEDIUM 5.4
CVE-2026-58624

Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.…

Fix: 2.19.0+
Fix from $1,600 2026-07-20
Mina Sshd HIGH 7.5
CVE-2026-56452

Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The impleme…

Fix: 2.19.0+
Fix from $1,950 2026-07-20
Mina Sshd HIGH 7.1
CVE-2026-56623

Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH. A git s…

Fix: 2.19.0+
Fix from $1,950 2026-07-20
Syncope CRITICAL 9.8
CVE-2026-63071

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can crea…

Fix: 4.0.7 / 4.1.2+
Fix from $2,300 2026-07-20
Syncope CRITICAL 9.8
CVE-2026-57308

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate…

Fix: 4.0.7 / 4.1.2+
Fix from $2,300 2026-07-20
Syncope CRITICAL 9.8
CVE-2026-62183

Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user wor…

Fix: 4.0.7 / 4.1.2+
Fix from $2,300 2026-07-20
Syncope HIGH 8.1
CVE-2026-62418

Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue af…

Fix: 4.0.7 / 4.1.2+
Fix from $1,950 2026-07-20
Syncope CRITICAL 9.8
CVE-2026-53421

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code ex…

Fix: 4.0.7 / 4.1.2+
Fix from $2,300 2026-07-20
Syncope CRITICAL 9.8
CVE-2026-53405

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN pr…

Fix: 4.0.7 / 4.1.2+
Fix from $2,300 2026-07-20
Traffic Server HIGH 7.5
CVE-2026-59173

Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from …

Fix: 9.2.14 / 10.1.3+
Fix from $1,950 2026-07-18
Accumulo MEDIUM 6.5
CVE-2026-62764

Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user without system permissions m…

Fix: 2.1.6+
Fix from $1,600 2026-07-17
Ivy MEDIUM 5.4
CVE-2026-26032

The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repa…

Fix: 2.6.0+
Fix from $1,600 2026-07-15
Fineract HIGH 8.1
CVE-2026-56287

A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.…

Fix: 1.15.0+
Fix from $1,950 2026-07-15
Fineract HIGH 8.1
CVE-2026-57821

A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy…

Fix: 1.15.0+
Fix from $1,950 2026-07-15
Fineract HIGH 8.8
CVE-2026-35152

A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report p…

Fix: 1.15.0+
Fix from $1,950 2026-07-15
Kylin CRITICAL 9.8
CVE-2026-62390

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table ca…

Fix: 5.0.4+
Fix from $2,300 2026-07-14
Kylin CRITICAL 9.8
CVE-2026-62392

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job…

Fix: 5.0.4+
Fix from $2,300 2026-07-14
Openmeetings MEDIUM 6.5
CVE-2026-49488

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenM…

Fix: 9.1.0+
Fix from $1,600 2026-07-14
Doris CRITICAL 9.1
CVE-2026-58319

Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access …

Fix: 3.1.0+
Fix from $2,300 2026-07-14
Tomcat CRITICAL 9.1
CVE-2026-59083

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configura…

Fix: after 11.0.23
Fix from $2,300 2026-07-14
Tomcat CRITICAL 9.1
CVE-2026-59084

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clea…

Fix: after 11.0.23
Fix from $2,300 2026-07-14
Apache Airflow Providers Git HIGH 8.1
CVE-2026-58065

The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An …

Fix: 0.4.1+
Fix from $1,950 2026-07-13
Apache Airflow Providers Fab HIGH 8.1
CVE-2026-59245

In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resour…

Fix: 3.7.2+
Fix from $1,950 2026-07-13
Gravitino MEDIUM 6.5
CVE-2026-49876

Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job temp…

Fix: 1.3.0+
Fix from $1,600 2026-07-13
Gravitino CRITICAL 9.1
CVE-2026-41041

URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before…

Fix: 1.2.1+
Fix from $2,300 2026-07-13
Log4j MEDIUM 5.9
CVE-2026-49844

Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON…

Fix: 2.25.5+
Fix from $1,600 2026-07-10
Helix HIGH 7.5
CVE-2026-57111

Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through…

Fix: 2.0.1+
Fix from $1,950 2026-07-09