Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-73634 Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violatio… Struts Fix unknown Fix from $4,9002026-08-15 HIGH 7.5 CVE-2026-73635 Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localize… Struts Fix unknown Fix from $4,9002026-08-15 HIGH 7.5 CVE-2026-73633 Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSO… Struts No fix yet Fix from $4,9002026-08-14 CRITICAL 9.8 CVE-2026-73240 Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recomme… Allura No fix yet Fix from $5,7502026-08-12 MEDIUM 6.5 CVE-2026-73239 Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache All… Allura No fix yet Fix from $4,0002026-08-12 MEDIUM 6.1 CVE-2026-73238 XSS vulnerability in code display in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.… Allura No fix yet Fix from $4,0002026-08-12 MEDIUM 6.1 CVE-2026-73237 XSS vulnerability in Markdown handling in Apache Allura. This issue affects Apache Allura: from 1.10.0 before 1.19.1. Users are recommended to upgr… Allura No fix yet Fix from $4,0002026-08-12 HIGH 7.5 CVE-2026-68968 Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. T… Airflow 3.3.1+ Fix from $4,9002026-08-12 MEDIUM 6.5 CVE-2026-68970 Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext i… Airflow 3.3.1+ Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-68969 Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoint… Airflow 3.3.1+ Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-68971 Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finis… Airflow 3.3.1+ Fix from $4,0002026-08-12 HIGH 8.8 CVE-2026-67587 Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the store… Airflow No fix yet Fix from $4,9002026-08-12 MEDIUM 5.4 CVE-2026-68076 Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to p… Airflow 3.3.1+ Fix from $4,0002026-08-12 HIGH 7.3 CVE-2026-67260 Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deseria… Airflow No fix yet Fix from $4,9002026-08-12 MEDIUM 6.5 CVE-2026-65017 Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled mult… Airflow 3.3.1+ Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-59244 Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an… Airflow 3.3.1+ Fix from $4,0002026-08-12 MEDIUM 5.4 CVE-2026-59242 Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_v… Airflow 3.3.1+ Fix from $4,0002026-08-12 HIGH 8.8 CVE-2026-58076 Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and in… Airflow 3.3.1+ Fix from $4,9002026-08-12 MEDIUM 6.5 CVE-2026-68868 The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Varia… Apache Airflow Providers Google No fix yet Fix from $4,0002026-08-12 CRITICAL 9.1 CVE-2026-71290 Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effe… Httpclient No fix yet Fix from $5,7502026-08-11 CRITICAL 9.1 CVE-2026-69223 Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommend… Allura No fix yet Fix from $5,7502026-08-11 MEDIUM 6.5 CVE-2026-68872 The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variabl… Apache Airflow Providers Amazon No fix yet Fix from $4,0002026-08-10 MEDIUM 6.5 CVE-2026-68871 The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic loo… Apache Airflow Providers Apache Yandex No fix yet Fix from $4,0002026-08-10 HIGH 7.5 CVE-2026-61899 Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs. Us… Tapestry No fix yet Fix from $4,9002026-08-10 HIGH 7.5 CVE-2026-65942 TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes thi… Ranger No fix yet Fix from $4,9002026-08-10 HIGH 7.3 CVE-2026-65948 UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:  UnixAuth is NOT a recommended option for production deployments.  U… Ranger No fix yet Fix from $4,9002026-08-10 MEDIUM 6.5 CVE-2026-65945 Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. Ranger No fix yet Fix from $4,0002026-08-10 CRITICAL 9.8 CVE-2026-32227 SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the… Ranger No fix yet Fix from $5,7502026-08-10 CRITICAL 9.8 CVE-2026-40920 Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixe… Ranger No fix yet Fix from $5,7502026-08-10 CRITICAL 9.8 CVE-2026-42537 Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. Ranger No fix yet Fix from $5,7502026-08-10