Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2026-55955
Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component.
This issu…
Tomcat
9.0.119 / 10.1.56+
MEDIUM 6.5
CVE-2026-55956
Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method o…
Tomcat
9.0.119 / 10.1.56+
CRITICAL 9.1
CVE-2026-53434
Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.
This issue affects Apach…
Tomcat
9.0.119 / 10.1.56+
HIGH 7.3
CVE-2026-53404
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched,…
Tomcat
9.0.119 / 10.1.56+
MEDIUM 6.1
CVE-2026-50229
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat.
This issu…
Tomcat
9.0.119 / 10.1.56+
HIGH 7.5
CVE-2026-49486
The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control c…
Apache Airflow Providers Ftp
3.15.1+
MEDIUM 5.3
CVE-2026-54665
Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard …
Nifi
2.10.0+
HIGH 7.2
CVE-2026-44913
Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL …
Nifi
2.10.0+
HIGH 7.2
CVE-2026-44914
Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Per…
Nifi
2.10.0+
MEDIUM 6.3
CVE-2026-44911
Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submi…
Nifi
2.10.0+
HIGH 8.1
CVE-2025-66336
Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated int…
Doris Mcp Server
0.6.1+
MEDIUM 5.4
CVE-2025-62198
An authenticated user can perform XSS.
This issue affects Apache Atlas versions 2.4.0 and earlier.
Users are recommended to upgrade to version 2.5.…
Atlas
2.5.0+
CRITICAL 9.3
CVE-2026-49871
Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations.
This defect allows a remote attacker that manag…
Apisix
3.17.0+
CRITICAL 9.1
CVE-2026-49230
Improper Validation of Integrity Check Value vulnerability in Apache APISIX.
The jwe-decrypt plugin under default configuration is vulnerable to aut…
Apisix
3.17.0+
HIGH 8.1
CVE-2026-49872
Improper Authentication vulnerability in Apache APISIX.
When the cas-auth plugin is used in a route, an attacker can possibly authenticate itself wi…
Apisix
3.17.0+
HIGH 7.2
CVE-2026-48895
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX.
The attacker could manipulate some client headers to perform an …
Apisix
3.17.0+
MEDIUM 5.4
CVE-2026-49231
Authentication Bypass by Spoofing vulnerability in opa plugin.
An attacker could relay spoofed identity headers to upstream capitalising on non-defa…
Apisix
3.17.0+
CRITICAL 9.1
CVE-2026-44087
Insufficient Verification of Data Authenticity vulnerability in Apache APISIX.
The openid-connect plugin under default configuration has an attack s…
Apisix
3.17.0+
HIGH 8.1
CVE-2026-47339
Incorrect Authorization vulnerability in Apache APISIX.
An attacker can capitalise on authz-casdoor plugin under default configuration to authentica…
Apisix
3.17.0+
MEDIUM 6.5
CVE-2026-47341
Authentication Bypass by Capture-replay vulnerability in Apache APISIX.
Attacker can benefit from certain configurations in hmac-auth to re-use a to…
Apisix
3.17.0+
MEDIUM 6.1
CVE-2026-44915
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX.
The default configuration of cas-auth in Apache APISIX is vulner…
Apisix
3.17.0+
MEDIUM 5.8
CVE-2026-44046
Use of Less Trusted Source vulnerability in Apache APISIX.
Attacker can take advantage of wolf-rbac plugin under default configuration to potentiall…
Apisix
3.17.0+
CRITICAL 9.1
CVE-2026-39999
Authentication Bypass by Spoofing vulnerability in Apache APISIX.
The attacker can completely bypass authentication capitalising on certain configur…
Apisix
3.17.0+
HIGH 8.8
CVE-2026-39998
Improper Input Validation vulnerability in Apache APISIX.
The attacker can take advantage of certain configuration in forward-auth plugin to spoof i…
Apisix
3.17.0+
CRITICAL 9.1
CVE-2026-49268
A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username …
Shiro
2.2.1+
CRITICAL 9.1
CVE-2026-50203
A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP serv…
Apache Airflow Providers Sftp
5.8.1+
MEDIUM 6.5
CVE-2026-47340
Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler.
…
Dolphinscheduler
3.4.2+
MEDIUM 6.5
CVE-2026-42357
Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to acces…
Dolphinscheduler
3.4.2+
CRITICAL 9.8
CVE-2026-32966
DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler.
This issue affects Apache …
Dolphinscheduler
3.4.2+
CRITICAL 9.1
CVE-2026-32967
Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler.
This issue affects Apache DolphinScheduler: before…
Dolphinscheduler
3.4.2+