Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2025-48977
Relative Path Traversal vulnerability in Apache Ignite REST API.
Authenticated REST API users can read any file on the server with "cmd=log" command…
Ignite
2.18.0+
MEDIUM 6.5
CVE-2026-40564
Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator.
The Flink…
Flink Kubernetes Operator
1.15.0+
MEDIUM 5.4
CVE-2026-48589
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login.
In affected versions, insufficie…
Shiro
2.2.1+
MEDIUM 6.5
CVE-2026-43827
Default configurations of Apache Shiro have a session fixation vulnerability.
This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1.
…
Shiro
2.1.1+
MEDIUM 6.5
CVE-2026-43828
Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute.
This issue affects Apache Shiro from 1.…
Shiro
2.1.1+
MEDIUM 5.4
CVE-2026-44598
With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro.
…
Shiro
2.1.1+
HIGH 7.2
CVE-2026-42782
Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements for Implementations can crea…
Syncope
4.0.6+
MEDIUM 5.3
CVE-2026-46745
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate director…
Apache Airflow Providers Fab
3.6.4+
HIGH 8.1
CVE-2026-45361
Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worke…
Apache Airflow Providers Google
22.0.0+
MEDIUM 6.1
CVE-2026-45249
A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic.
This issue affects Apache EChart…
Echarts
6.1.0+
CRITICAL 9.8
CVE-2026-44930
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certi…
Cxf
3.6.11 / 4.1.6+
HIGH 7.5
CVE-2026-44417
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lea…
Cxf
3.6.11 / 4.1.6+
MEDIUM 5.3
CVE-2026-44618
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to …
Cxf
3.6.11 / 4.1.6+
CRITICAL 9.8
CVE-2026-48207
Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks dur…
Fory
1.0.0+
MEDIUM 5.3
CVE-2026-42526
In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0, the team-scoping logic coul…
Apache Airflow Providers Amazon
9.28.0+
HIGH 8.7
CVE-2026-27173
JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow…
Apache Airflow Providers Cncf Kubernetes
10.17.0+
CRITICAL 9.8
CVE-2026-47323
Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering
The CXF and Knative HeaderFilterStrategy implementations (CxfRsHe…
Camel
4.14.6 / 4.18.2+
CRITICAL 9.8
CVE-2026-45434EPSS 22%
Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution
This issue affects Apache OFBi…
Ofbiz
24.09.06+
CRITICAL 9.1
CVE-2026-31986
Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgra…
Ofbiz
24.09.06+
CRITICAL 9.1
CVE-2026-41919
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz:…
Ofbiz
24.09.06+
HIGH 8.8
CVE-2026-46586
Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vul…
Ofbiz
24.09.06+
HIGH 7.5
CVE-2026-31910
Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrad…
Ofbiz
24.09.06+
MEDIUM 6.5
CVE-2026-35086
Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz.
This issue affects Apache OFBiz: before 2…
Ofbiz
24.09.06+
MEDIUM 6.5
CVE-2026-45187
Improper Authorization vulnerability in Apache OFBiz Webtools.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade t…
Ofbiz
24.09.06+
HIGH 7.5
CVE-2026-31909
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users a…
Ofbiz
24.09.06+
MEDIUM 6.5
CVE-2026-31378
Improper Input Validation vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to vers…
Ofbiz
24.09.06+
MEDIUM 6.5
CVE-2026-31380
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in Apache OFBiz.…
Ofbiz
24.09.06+
MEDIUM 6.1
CVE-2026-31379
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('P…
Ofbiz
24.09.06+
MEDIUM 6.1
CVE-2026-31906
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz:…
Ofbiz
24.09.06+
MEDIUM 5.3
CVE-2026-31387
Improper Authentication vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to versio…
Ofbiz
24.09.06+