Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-31388 Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affects Apache OFBiz: before 24.09.06. Users are reco… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 HIGH 7.3 CVE-2026-29226 Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations. This issue affects Apache OFBiz: before 24.09.06.… Ofbiz 24.09.06+ Fix from $1,9502026-05-19 MEDIUM 6.5 CVE-2026-29207 Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.0… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 MEDIUM 6.5 CVE-2026-29220 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: befor… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 HIGH 8.1 CVE-2026-35194 Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission pr… Flink 1.20.4 / 2.0.2+ Fix from $1,9502026-05-15 MEDIUM 5.3 CVE-2026-45205 Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOve… Commons Configuration 2.15.0+ Fix from $1,6002026-05-14 CRITICAL 9.1 CVE-2026-43515 Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affe… Tomcat 9.0.118 / 10.1.55+ Fix from $2,3002026-05-12 HIGH 7.5 CVE-2026-43513 Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.… Tomcat 9.0.118 / 10.1.55+ Fix from $1,9502026-05-12 CRITICAL 9.8 CVE-2026-41293 Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 1… Tomcat 9.0.118 / 10.1.55+ Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-43512 DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 t… Tomcat 9.0.118 / 10.1.55+ Fix from $2,3002026-05-12 HIGH 7.3 CVE-2026-42498 Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache… Tomcat 9.0.118 / 10.1.55+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-41284 Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2… Tomcat 9.0.118 / 10.1.55+ Fix from $1,9502026-05-12 MEDIUM 6.5 CVE-2026-43826 The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:[email protected]:920… Apache Airflow Providers Opensearch 1.9.1+ Fix from $1,6002026-05-11 MEDIUM 6.5 CVE-2026-41018 The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:[email protected]:… Apache Airflow Providers Elasticsearch 6.5.3+ Fix from $1,6002026-05-11 HIGH 8.8 CVE-2026-39816 The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi… Nifi 2.9.0+ Fix from $1,9502026-05-08 CRITICAL 9.1 CVE-2026-25199 Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudSt… Cloudstack 4.22.0.1+ Fix from $2,3002026-05-08 HIGH 8.8 CVE-2026-25077 Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hyp… Cloudstack 4.20.3.0 / 4.22.0.1+ Fix from $1,9502026-05-08 HIGH 8.1 CVE-2025-66172 The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudSt… Cloudstack 4.22.0.1+ Fix from $1,9502026-05-08 HIGH 8.1 CVE-2025-66467 Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If anothe… Cloudstack 4.20.3.0 / 4.22.0.1+ Fix from $1,9502026-05-08 MEDIUM 6.5 CVE-2025-66170 The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in … Cloudstack 4.22.0.1+ Fix from $1,6002026-05-08 MEDIUM 6.5 CVE-2025-66171 The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudSt… Cloudstack 4.22.0.1+ Fix from $1,6002026-05-08 MEDIUM 5.3 CVE-2025-69233 Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of t… Cloudstack 4.20.3.0 / 4.22.0.1+ Fix from $1,6002026-05-08 HIGH 7.5 CVE-2026-43646 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17… Wicket 10.9.0+ Fix from $1,9502026-05-06 MEDIUM 6.5 CVE-2026-43975 FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file p… Wicket 10.9.0+ Fix from $1,6002026-05-06 CRITICAL 9.1 CVE-2026-40010 Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache … Wicket 10.9.0+ Fix from $2,3002026-05-06 MEDIUM 6.1 CVE-2026-42509 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicke… Wicket 10.9.0+ Fix from $1,6002026-05-06 CRITICAL 9.8 CVE-2026-28780 Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server … HTTP Server 2.4.67+ Fix from $2,3002026-05-05 HIGH 7.3 CVE-2026-29168 Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data. This issue affects Apache… HTTP Server 2.4.67+ Fix from $1,9502026-05-05 HIGH 7.3 CVE-2026-43870 Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in… Thrift 0.23.0+ Fix from $1,9502026-05-05 MEDIUM 5.3 CVE-2026-43868 Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended … Thrift 0.23.0+ Fix from $1,6002026-05-05