Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2026-31388
Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments.
This issue affects Apache OFBiz: before 24.09.06.
Users are reco…
Ofbiz
24.09.06+
HIGH 7.3
CVE-2026-29226
Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations.
This issue affects Apache OFBiz: before 24.09.06.…
Ofbiz
24.09.06+
MEDIUM 6.5
CVE-2026-29207
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.0…
Ofbiz
24.09.06+
MEDIUM 6.5
CVE-2026-29220
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: befor…
Ofbiz
24.09.06+
HIGH 8.1
CVE-2026-35194
Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission pr…
Flink
1.20.4 / 2.0.2+
MEDIUM 5.3
CVE-2026-45205
Uncontrolled Recursion vulnerability in Apache Commons.
When processing an untrusted configuration file, Commons Configuration will throw a StackOve…
Commons Configuration
2.15.0+
CRITICAL 9.1
CVE-2026-43515
Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat.
This issue affe…
Tomcat
9.0.118 / 10.1.55+
HIGH 7.5
CVE-2026-43513
Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.…
Tomcat
9.0.118 / 10.1.55+
CRITICAL 9.8
CVE-2026-41293
Improper Input Validation vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 1…
Tomcat
9.0.118 / 10.1.55+
CRITICAL 9.8
CVE-2026-43512
DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 t…
Tomcat
9.0.118 / 10.1.55+
HIGH 7.3
CVE-2026-42498
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat.
This issue affects Apache…
Tomcat
9.0.118 / 10.1.55+
HIGH 7.5
CVE-2026-41284
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2…
Tomcat
9.0.118 / 10.1.55+
MEDIUM 6.5
CVE-2026-43826
The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:[email protected]:920…
Apache Airflow Providers Opensearch
1.9.1+
MEDIUM 6.5
CVE-2026-41018
The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:[email protected]:…
Apache Airflow Providers Elasticsearch
6.5.3+
HIGH 8.8
CVE-2026-39816
The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi…
Nifi
2.9.0+
CRITICAL 9.1
CVE-2026-25199
Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants.
This issue affects Apache CloudSt…
Cloudstack
4.22.0.1+
HIGH 8.8
CVE-2026-25077
Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hyp…
Cloudstack
4.20.3.0 / 4.22.0.1+
HIGH 8.1
CVE-2025-66172
The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudSt…
Cloudstack
4.22.0.1+
HIGH 8.1
CVE-2025-66467
Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If anothe…
Cloudstack
4.20.3.0 / 4.22.0.1+
MEDIUM 6.5
CVE-2025-66170
The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in …
Cloudstack
4.22.0.1+
MEDIUM 6.5
CVE-2025-66171
The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudSt…
Cloudstack
4.22.0.1+
MEDIUM 5.3
CVE-2025-69233
Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of t…
Cloudstack
4.20.3.0 / 4.22.0.1+
HIGH 7.5
CVE-2026-43646
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket.
This issue affects Apache Wicket: from 8.0.0 through 8.17…
Wicket
10.9.0+
MEDIUM 6.5
CVE-2026-43975
FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName
before constructing file p…
Wicket
10.9.0+
CRITICAL 9.1
CVE-2026-40010
Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache …
Wicket
10.9.0+
MEDIUM 6.1
CVE-2026-42509
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket.
This issue affects Apache Wicke…
Wicket
10.9.0+
CRITICAL 9.8
CVE-2026-28780
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.
If mod_proxy_ajp connects to a malicious AJP server this AJP server …
HTTP Server
2.4.67+
HIGH 7.3
CVE-2026-29168
Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data.
This issue affects Apache…
HTTP Server
2.4.67+
HIGH 7.3
CVE-2026-43870
Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in…
Thrift
0.23.0+
MEDIUM 5.3
CVE-2026-43868
Memory Allocation with Excessive Size Value vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended …
Thrift
0.23.0+