Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2026-50632 A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, whi… Cxf 4.1.7 / 4.2.2+ Fix from $1,9502026-06-12 HIGH 8.1 CVE-2026-50633 A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able… Cxf 4.1.7 / 4.2.2+ Fix from $1,9502026-06-12 HIGH 7.5 CVE-2026-50645 There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncon… Cxf 4.1.7 / 4.2.2+ Fix from $1,9502026-06-12 HIGH 7.4 CVE-2026-50631 A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate mul… Cxf 4.1.7 / 4.2.2+ Fix from $1,9502026-06-12 MEDIUM 6.5 CVE-2026-50634 A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the acc… Cxf 4.1.7 / 4.2.2+ Fix from $1,6002026-06-12 CRITICAL 9.8 CVE-2026-49875 Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configuration… Cxf 4.1.7 / 4.2.2+ Fix from $2,3002026-06-12 CRITICAL 9.8 CVE-2026-50628 A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other… Cxf 4.1.7 / 4.2.2+ Fix from $2,3002026-06-12 CRITICAL 9.1 CVE-2026-50627 The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued… Cxf 4.1.7 / 4.2.2+ Fix from $2,3002026-06-12 MEDIUM 6.5 CVE-2026-50630 A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' par… Cxf 4.1.7 / 4.2.2+ Fix from $1,6002026-06-12 MEDIUM 5.3 CVE-2026-50629 The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control char… Cxf 4.1.7 / 4.2.2+ Fix from $1,6002026-06-12 HIGH 8.8 CVE-2026-50223 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataR… Ofbiz 24.09.07+ Fix from $1,9502026-06-10 HIGH 8.8 CVE-2026-47342 A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apa… Ofbiz 24.09.07+ Fix from $1,9502026-06-10 HIGH 7.2 CVE-2026-25700 Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Previously issue… Answer 2.0.1+ Fix from $1,9502026-06-10 MEDIUM 6.5 CVE-2026-49818 The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an objec… Apache Airflow Providers Samba 4.12.6+ Fix from $1,6002026-06-09 MEDIUM 6.5 CVE-2026-33582 Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF ima… Answer 2.0.1+ Fix from $1,6002026-06-09 MEDIUM 6.5 CVE-2026-34031 Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not… Answer 2.0.1+ Fix from $1,6002026-06-09 MEDIUM 6.5 CVE-2026-34905 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unl… Answer 2.0.1+ Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-34033 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: thro… Answer 2.0.1+ Fix from $1,6002026-06-09 MEDIUM 6.1 CVE-2026-25688 Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated respo… Answer 2.0.1+ Fix from $1,6002026-06-09 MEDIUM 6.1 CVE-2026-25699 Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. … Answer 2.0.1+ Fix from $1,6002026-06-09 HIGH 7.5 CVE-2026-49975EPSS 28% Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. T… HTTP Server 2.4.68+ Fix from $1,9502026-06-08 HIGH 7.3 CVE-2026-48913 Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: … HTTP Server 2.4.68+ Fix from $1,9502026-06-08 CRITICAL 9.8 CVE-2026-44631 Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: fr… HTTP Server 2.4.68+ Fix from $2,3002026-06-08 HIGH 7.3 CVE-2026-44185 Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP… HTTP Server 2.4.68+ Fix from $1,9502026-06-08 HIGH 7.3 CVE-2026-44186 Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled ba… HTTP Server 2.4.68+ Fix from $1,9502026-06-08 MEDIUM 6.5 CVE-2026-43951 Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP… HTTP Server after 2.4.67 Fix from $1,6002026-06-08 MEDIUM 5.5 CVE-2026-44119 Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges… HTTP Server 2.4.68+ Fix from $1,6002026-06-08 CRITICAL 9.1 CVE-2026-42535 A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases… HTTP Server 2.4.68+ Fix from $2,3002026-06-08 HIGH 7.5 CVE-2026-42536 Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTT… HTTP Server 2.4.68+ Fix from $1,9502026-06-08 HIGH 7.5 CVE-2026-34355 A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgra… HTTP Server 2.4.68+ Fix from $1,9502026-06-08