Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-41606 Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version… Thrift 0.23.0+ Fix from $1,6002026-04-28 HIGH 7.5 CVE-2025-48431 Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Use… Thrift 0.23.0+ Fix from $1,9502026-04-28 MEDIUM 6.5 CVE-2026-41081 Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Des… Storm 2.8.7+ Fix from $1,6002026-04-27 CRITICAL 10.0 CVE-2026-33453EPSS 6% Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's ca… Camel after 4.14.5 Fix from $2,3002026-04-27 HIGH 8.8 CVE-2026-27172 The ConsulRegistry in the camel-consul component (class org.apache.camel.component.consul.ConsulRegistry and its inner ConsulRegistryUtils.deserializ… Camel 4.14.6 / 4.18.1+ Fix from $1,9502026-04-27 CRITICAL 9.8 CVE-2026-41409 The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized … Mina 2.0.28 / 2.1.11+ Fix from $2,3002026-04-27 HIGH 8.8 CVE-2026-40858 The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.… Camel 4.14.7 / 4.18.2+ Fix from $1,9502026-04-27 HIGH 8.2 CVE-2026-40022 When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root conte… Camel 4.14.6 / 4.18.2+ Fix from $1,9502026-04-27 CRITICAL 9.4 CVE-2026-33454 The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterSt… Camel 4.14.6 / 4.18.1+ Fix from $2,3002026-04-27 CRITICAL 9.9 CVE-2026-40453 The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable… Camel 4.14.6 / 4.18.2+ Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-40860 JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessa… Camel 4.14.7 / 4.18.2+ Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-41635 Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at … Mina 2.0.28 / 2.1.11+ Fix from $2,3002026-04-27 HIGH 8.8 CVE-2026-40473 The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any… Camel 4.14.6 / 4.18.2+ Fix from $1,9502026-04-27 HIGH 7.8 CVE-2026-40048 The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in the configured key directory using java.io.Objec… Camel 4.18.2+ Fix from $1,9502026-04-27 HIGH 8.1 CVE-2026-23902 Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not… Dolphinscheduler 3.4.1+ Fix from $1,9502026-04-24 HIGH 8.8 CVE-2026-40466 Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap… Activemq 5.19.6 / 6.2.5+ Fix from $1,9502026-04-24 HIGH 8.8 CVE-2026-41044 Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache… Activemq 5.19.6 / 6.2.5+ Fix from $1,9502026-04-24 MEDIUM 6.5 CVE-2026-41043 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticate… Activemq 5.19.6 / 6.2.5+ Fix from $1,6002026-04-24 MEDIUM 6.3 CVE-2025-62233 Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler:  Version >= 3.2.… Dolphinscheduler 3.3.1+ Fix from $1,6002026-04-24 HIGH 7.3 CVE-2026-40542 Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication withou… Httpclient Mitigation only Fix from $1,9502026-04-22 MEDIUM 5.3 CVE-2026-33558 Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire requests and responses inform… Kafka 3.9.2+ Fix from $1,6002026-04-20 CRITICAL 9.1 CVE-2026-33557 A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set… Kafka 4.1.2+ Fix from $2,3002026-04-20 MEDIUM 5.3 CVE-2025-66335 Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow executio… Doris Mcp Server 0.6.1+ Fix from $1,6002026-04-20 MEDIUM 5.4 CVE-2026-40948 The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on the login … Apache Airflow Providers Keycloak 0.7.0+ Fix from $1,6002026-04-18 HIGH 8.8 CVE-2026-30898 An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be … Airflow 3.2.0+ Fix from $1,9502026-04-18 HIGH 7.5 CVE-2026-30912 In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to expo… Airflow 3.2.0+ Fix from $1,9502026-04-18 HIGH 7.5 CVE-2026-32228 UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that … Airflow 3.2.0+ Fix from $1,9502026-04-18 HIGH 7.2 CVE-2026-25917 Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbit… Airflow 3.2.0+ Fix from $1,9502026-04-18 HIGH 7.5 CVE-2026-31987 JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that… Airflow 3.2.0+ Fix from $1,9502026-04-16 MEDIUM 6.5 CVE-2026-25219 The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read p… Airflow 3.2.0+ Fix from $1,6002026-04-15