Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-73634
Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violatio…
Struts
Fix unknown
HIGH 7.5
CVE-2026-73635
Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localize…
Struts
Fix unknown
HIGH 7.5
CVE-2026-73633
Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSO…
Struts
No fix yet
CRITICAL 9.8
CVE-2026-73240
Specifically crafted inputs may lead to git argument injection in Apache Allura.
This issue affects Apache Allura: before 1.19.1.
Users are recomme…
Allura
No fix yet
MEDIUM 6.5
CVE-2026-73239
Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura.
This issue affects Apache All…
Allura
No fix yet
MEDIUM 6.1
CVE-2026-73238
XSS vulnerability in code display in Apache Allura.
This issue affects Apache Allura: before 1.19.1.
Users are recommended to upgrade to version 1.…
Allura
No fix yet
MEDIUM 6.1
CVE-2026-73237
XSS vulnerability in Markdown handling in Apache Allura.
This issue affects Apache Allura: from 1.10.0 before 1.19.1.
Users are recommended to upgr…
Allura
No fix yet
HIGH 7.5
CVE-2026-68968
Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. T…
Airflow
3.3.1+
MEDIUM 6.5
CVE-2026-68970
Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext i…
Airflow
3.3.1+
MEDIUM 6.5
CVE-2026-68969
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoint…
Airflow
3.3.1+
MEDIUM 6.5
CVE-2026-68971
Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finis…
Airflow
3.3.1+
HIGH 8.8
CVE-2026-67587
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the store…
Airflow
No fix yet
MEDIUM 5.4
CVE-2026-68076
Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to p…
Airflow
3.3.1+
HIGH 7.3
CVE-2026-67260
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deseria…
Airflow
No fix yet
MEDIUM 6.5
CVE-2026-65017
Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled mult…
Airflow
3.3.1+
MEDIUM 6.5
CVE-2026-59244
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an…
Airflow
3.3.1+
MEDIUM 5.4
CVE-2026-59242
Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_v…
Airflow
3.3.1+
HIGH 8.8
CVE-2026-58076
Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and in…
Airflow
3.3.1+
MEDIUM 6.5
CVE-2026-68868
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Varia…
Apache Airflow Providers Google
No fix yet
CRITICAL 9.1
CVE-2026-71290
Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effe…
Httpclient
No fix yet
CRITICAL 9.1
CVE-2026-69223
Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF).
This issue affects Apache Allura: before 1.19.1.
Users are recommend…
Allura
No fix yet
MEDIUM 6.5
CVE-2026-68872
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variabl…
Apache Airflow Providers Amazon
No fix yet
MEDIUM 6.5
CVE-2026-68871
The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic loo…
Apache Airflow Providers Apache Yandex
No fix yet
HIGH 7.5
CVE-2026-61899
Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs.
Us…
Tapestry
No fix yet
HIGH 7.5
CVE-2026-65942
TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0.
Users are recommended to upgrade to version 2.9.0, which fixes thi…
Ranger
No fix yet
HIGH 7.3
CVE-2026-65948
UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.
Note: UnixAuth is NOT a recommended option for production deployments.
U…
Ranger
No fix yet
MEDIUM 6.5
CVE-2026-65945
Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0
Users are recommended to upgrade to version 2.9.0, which fixes this issue.
Ranger
No fix yet
CRITICAL 9.8
CVE-2026-32227
SQL Injection vulnerability vulnerability in Apache Ranger.
This issue affects .
Users are recommended to upgrade to version 2.9.0, which fixes the…
Ranger
No fix yet
CRITICAL 9.8
CVE-2026-40920
Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0.
Users are recommended to upgrade to version 2.9.0, which fixe…
Ranger
No fix yet
CRITICAL 9.8
CVE-2026-42537
Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0
Users are recommended to upgrade to version 2.9.0, which fixes this issue.
Ranger
No fix yet