Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Camel CRITICAL 9.8
CVE-2026-46454

Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeux (CometD) message headers in…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.8
CVE-2026-46455

Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper KeycloakSecurityHelper.parseAnd…

Fix: 4.18.3 / 4.21.0+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.8
CVE-2026-46456

Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs component map inbound message attributes into the Ca…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Camel HIGH 7.5
CVE-2026-46457

Improper Input Validation vulnerability in Apache Camel NATS component. The camel-nats component maps inbound NATS message headers into the Camel Ex…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel MEDIUM 5.3
CVE-2026-46453

Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel ElasticSearch Rest Client. The camel-elast…

Fix: 4.14.8 / 4.18.3+
Fix from $1,600 2026-07-06
Iotdb CRITICAL 9.8
CVE-2026-24014

Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without suffici…

Fix: 2.0.8+
Fix from $2,300 2026-07-06
Iotdb CRITICAL 9.1
CVE-2026-24013

Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter.…

Fix: 2.0.8+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.1
CVE-2026-40047

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. The camel-doclin…

Fix: 4.18.3+
Fix from $2,300 2026-07-06
Camel HIGH 8.1
CVE-2026-42527

Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several Apache Camel components …

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel HIGH 8.1
CVE-2026-43865

Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component creates and manages Hazelcast ins…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel HIGH 8.1
CVE-2026-40859

Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP response bodies carrying the Conte…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Iotdb HIGH 7.5
CVE-2026-24012

Uncontrolled Resource Consumption vulnerability in Apache IoTDB.  Some interface fails to impose reasonable limits on the time span and aggregation …

Fix: 2.0.8+
Fix from $1,950 2026-07-06
Camel HIGH 7.3
CVE-2026-43866

Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. JmsBinding.extractBodyFromJms() in camel-jms - and the …

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Lucene.net HIGH 7.5
CVE-2026-47896

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). T…

Mitigation only
Fix from $1,950 2026-07-03
Lucene.net CRITICAL 9.8
CVE-2026-47898

Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Ap…

Mitigation only
Fix from $2,300 2026-07-03
Lucene.net HIGH 7.5
CVE-2026-47897

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). T…

Mitigation only
Fix from $1,950 2026-07-03
Httpcomponents Core HIGH 7.5
CVE-2026-54428

Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earl…

Fix: after 5.4.2
Fix from $1,950 2026-07-01
Httpcomponents Core HIGH 7.5
CVE-2026-54399

Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlie…

Fix: after 5.4.2
Fix from $1,950 2026-07-01
Gravitino MEDIUM 5.4
CVE-2025-53648

SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files. Users are recommended to…

Fix: 1.0.0+
Fix from $1,600 2026-06-30
Activemq HIGH 7.5
CVE-2026-53916

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. An unauthenticated client…

Fix: 5.19.8 / 6.2.7+
Fix from $1,950 2026-06-30
Activemq HIGH 7.5
CVE-2026-53917

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker. A…

Fix: 5.19.8 / 6.2.7+
Fix from $1,950 2026-06-30
Activemq HIGH 7.5
CVE-2026-54475

Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic temporary destinations …

Fix: 5.19.8 / 6.2.7+
Fix from $1,950 2026-06-30
Activemq MEDIUM 6.1
CVE-2026-52760

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console. …

Fix: 5.19.8 / 6.2.7+
Fix from $1,600 2026-06-30
Activemq HIGH 8.1
CVE-2026-49877

Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can access /admin/* paths in the…

Fix: 5.19.8 / 6.2.7+
Fix from $1,950 2026-06-30
Activemq HIGH 7.5
CVE-2026-49432

Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. A remote unauthenticated peer that can reach…

Fix: 5.19.8 / 6.2.7+
Fix from $1,950 2026-06-30
Activemq HIGH 7.5
CVE-2026-49434

Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to publish or m…

Fix: 5.19.8 / 6.2.7+
Fix from $1,950 2026-06-30
Activemq HIGH 7.5
CVE-2026-50734

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All. An unauthenticated networ…

Fix: 5.19.8 / 6.2.7+
Fix from $1,950 2026-06-30
Activemq HIGH 7.5
CVE-2026-50750

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Following the fix for CVE-2026-4…

Mitigation only
Fix from $1,950 2026-06-30
Tomcat CRITICAL 9.1
CVE-2026-55276

Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not inc…

Fix: 9.0.119 / 10.1.56+
Fix from $2,300 2026-06-29
Tomcat HIGH 7.3
CVE-2026-55957

Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed a…

Fix: 9.0.101 / 10.1.37+
Fix from $1,950 2026-06-29