Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.1
CVE-2026-50632
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, whi…
Cxf
4.1.7 / 4.2.2+
HIGH 8.1
CVE-2026-50633
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able…
Cxf
4.1.7 / 4.2.2+
HIGH 7.5
CVE-2026-50645
There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncon…
Cxf
4.1.7 / 4.2.2+
HIGH 7.4
CVE-2026-50631
A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate mul…
Cxf
4.1.7 / 4.2.2+
MEDIUM 6.5
CVE-2026-50634
A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the acc…
Cxf
4.1.7 / 4.2.2+
CRITICAL 9.8
CVE-2026-49875
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configuration…
Cxf
4.1.7 / 4.2.2+
CRITICAL 9.8
CVE-2026-50628
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other…
Cxf
4.1.7 / 4.2.2+
CRITICAL 9.1
CVE-2026-50627
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued…
Cxf
4.1.7 / 4.2.2+
MEDIUM 6.5
CVE-2026-50630
A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' par…
Cxf
4.1.7 / 4.2.2+
MEDIUM 5.3
CVE-2026-50629
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control char…
Cxf
4.1.7 / 4.2.2+
HIGH 8.8
CVE-2026-50223
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataR…
Ofbiz
24.09.07+
HIGH 8.8
CVE-2026-47342
A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges
This issue affects Apa…
Ofbiz
24.09.07+
HIGH 7.2
CVE-2026-25700
Improper Restriction of Security Token Assignment vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
Previously issue…
Answer
2.0.1+
MEDIUM 6.5
CVE-2026-49818
The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an objec…
Apache Airflow Providers Samba
4.12.6+
MEDIUM 6.5
CVE-2026-33582
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
A crafted TIFF ima…
Answer
2.0.1+
MEDIUM 6.5
CVE-2026-34031
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
The server did not…
Answer
2.0.1+
MEDIUM 6.5
CVE-2026-34905
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
The unl…
Answer
2.0.1+
MEDIUM 5.4
CVE-2026-34033
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer.
This issue affects Apache Answer: thro…
Answer
2.0.1+
MEDIUM 6.1
CVE-2026-25688
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
AI-generated respo…
Answer
2.0.1+
MEDIUM 6.1
CVE-2026-25699
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
…
Answer
2.0.1+
HIGH 7.5
CVE-2026-49975EPSS 28%
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.
T…
HTTP Server
2.4.68+
HIGH 7.3
CVE-2026-48913
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.
This issue affects Apache HTTP Server: …
HTTP Server
2.4.68+
CRITICAL 9.8
CVE-2026-44631
Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.
This issue affects Apache HTTP Server: fr…
HTTP Server
2.4.68+
HIGH 7.3
CVE-2026-44185
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server
This issue affects Apache HTTP…
HTTP Server
2.4.68+
HIGH 7.3
CVE-2026-44186
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled ba…
HTTP Server
2.4.68+
MEDIUM 6.5
CVE-2026-43951
Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages.
This issue affects Apache HTTP…
HTTP Server
after 2.4.67
MEDIUM 5.5
CVE-2026-44119
Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges…
HTTP Server
2.4.68+
CRITICAL 9.1
CVE-2026-42535
A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases…
HTTP Server
2.4.68+
HIGH 7.5
CVE-2026-42536
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content
This issue affects Apache HTT…
HTTP Server
2.4.68+
HIGH 7.5
CVE-2026-34355
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend.
Users are recommended to upgra…
HTTP Server
2.4.68+