Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2025-48977 Relative Path Traversal vulnerability in Apache Ignite REST API. Authenticated REST API users can read any file on the server with "cmd=log" command… Ignite 2.18.0+ Fix from $1,6002026-05-28 MEDIUM 6.5 CVE-2026-40564 Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The Flink… Flink Kubernetes Operator 1.15.0+ Fix from $1,6002026-05-26 MEDIUM 5.4 CVE-2026-48589 Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficie… Shiro 2.2.1+ Fix from $1,6002026-05-25 MEDIUM 6.5 CVE-2026-43827 Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. … Shiro 2.1.1+ Fix from $1,6002026-05-25 MEDIUM 6.5 CVE-2026-43828 Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.… Shiro 2.1.1+ Fix from $1,6002026-05-25 MEDIUM 5.4 CVE-2026-44598 With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro. … Shiro 2.1.1+ Fix from $1,6002026-05-25 HIGH 7.2 CVE-2026-42782 Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can crea… Syncope 4.0.6+ Fix from $1,9502026-05-25 MEDIUM 5.3 CVE-2026-46745 Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate director… Apache Airflow Providers Fab 3.6.4+ Fix from $1,6002026-05-25 HIGH 8.1 CVE-2026-45361 Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worke… Apache Airflow Providers Google 22.0.0+ Fix from $1,9502026-05-25 MEDIUM 6.1 CVE-2026-45249 A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic. This issue affects Apache EChart… Echarts 6.1.0+ Fix from $1,6002026-05-25 CRITICAL 9.8 CVE-2026-44930 An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certi… Cxf 3.6.11 / 4.1.6+ Fix from $2,3002026-05-22 HIGH 7.5 CVE-2026-44417 The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lea… Cxf 3.6.11 / 4.1.6+ Fix from $1,9502026-05-22 MEDIUM 5.3 CVE-2026-44618 Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users are recommended to upgrade to … Cxf 3.6.11 / 4.1.6+ Fix from $1,6002026-05-22 CRITICAL 9.8 CVE-2026-48207 Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks dur… Fory 1.0.0+ Fix from $2,3002026-05-21 MEDIUM 5.3 CVE-2026-42526 In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0, the team-scoping logic coul… Apache Airflow Providers Amazon 9.28.0+ Fix from $1,6002026-05-19 HIGH 8.7 CVE-2026-27173 JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow… Apache Airflow Providers Cncf Kubernetes 10.17.0+ Fix from $1,9502026-05-19 CRITICAL 9.8 CVE-2026-47323 Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStrategy implementations (CxfRsHe… Camel 4.14.6 / 4.18.2+ Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-45434EPSS 22% Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBi… Ofbiz 24.09.06+ Fix from $2,3002026-05-19 CRITICAL 9.1 CVE-2026-31986 Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgra… Ofbiz 24.09.06+ Fix from $2,3002026-05-19 CRITICAL 9.1 CVE-2026-41919 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz:… Ofbiz 24.09.06+ Fix from $2,3002026-05-19 HIGH 8.8 CVE-2026-46586 Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vul… Ofbiz 24.09.06+ Fix from $1,9502026-05-19 HIGH 7.5 CVE-2026-31910 Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrad… Ofbiz 24.09.06+ Fix from $1,9502026-05-19 MEDIUM 6.5 CVE-2026-35086 Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue affects Apache OFBiz: before 2… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 MEDIUM 6.5 CVE-2026-45187 Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade t… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 HIGH 7.5 CVE-2026-31909 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users a… Ofbiz 24.09.06+ Fix from $1,9502026-05-19 MEDIUM 6.5 CVE-2026-31378 Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to vers… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 MEDIUM 6.5 CVE-2026-31380 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in Apache OFBiz.… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 MEDIUM 6.1 CVE-2026-31379 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('P… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 MEDIUM 6.1 CVE-2026-31906 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz. This issue affects Apache OFBiz:… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 MEDIUM 5.3 CVE-2026-31387 Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to versio… Ofbiz 24.09.06+ Fix from $1,6002026-05-19