Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-30778 The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. This issue affects Apache SkyWa… Skywalking 10.4.0+ Fix from $1,9502026-04-15 HIGH 8.1 CVE-2025-54550 The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xcom in the way that could be ex… Airflow 3.2.0+ Fix from $1,9502026-04-15 CRITICAL 9.1 CVE-2026-31908 Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious… Apisix 3.16.0+ Fix from $2,3002026-04-14 HIGH 7.5 CVE-2026-31923 Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configur… Apisix 3.16.0+ Fix from $1,9502026-04-14 MEDIUM 5.3 CVE-2026-31924 Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plaintext HTTP This issue affects … Apisix 3.16.0+ Fix from $1,6002026-04-14 HIGH 8.8 CVE-2026-33858 Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbit… Airflow 3.2.0+ Fix from $1,9502026-04-13 HIGH 7.5 CVE-2025-66236 Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to … Airflow 3.2.0+ Fix from $1,9502026-04-13 HIGH 7.1 CVE-2026-34476 Server-Side Request Forgery via SW-URL Header vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are re… Skywalking Mcp 0.2.0+ Fix from $1,9502026-04-13 HIGH 8.8 CVE-2026-35337 Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credential… Storm 2.8.6+ Fix from $1,9502026-04-13 MEDIUM 5.4 CVE-2026-35565 Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6 Description: The Storm UI … Storm 2.8.6+ Fix from $1,6002026-04-13 MEDIUM 5.3 CVE-2026-40021 Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J https://loggi… Log4net 3.3.0+ Fix from $1,6002026-04-10 MEDIUM 5.3 CVE-2026-40023 Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions before 1.7.0, fails to sanit… Log4cxx 1.7.0+ Fix from $1,6002026-04-10 HIGH 7.5 CVE-2026-34478 Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vul… Log4j 2.25.4+ Fix from $1,9502026-04-10 HIGH 7.5 CVE-2026-34479 The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML o… Log4j 2.25.4+ Fix from $1,9502026-04-10 HIGH 7.5 CVE-2026-34480 Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to … Log4j 2.25.4+ Fix from $1,9502026-04-10 HIGH 7.5 CVE-2026-34481 Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, pr… Log4j 2.25.4+ Fix from $1,9502026-04-10 MEDIUM 5.9 CVE-2026-34477 The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when ena… Log4j 2.25.4+ Fix from $1,6002026-04-10 HIGH 7.5 CVE-2026-39304 Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do… Activemq 5.19.4 / 6.2.4+ Fix from $1,9502026-04-10 HIGH 7.5 CVE-2026-34486 KEVEPSS 83% Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. … Tomcat Mitigation only Fix from $1,9502026-04-09 HIGH 7.5 CVE-2026-34487 Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernet… Tomcat 9.0.117 / 10.1.54+ Fix from $1,9502026-04-09 MEDIUM 6.5 CVE-2026-34500 CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affe… Tomcat 9.0.117 / 10.1.54+ Fix from $1,6002026-04-09 CRITICAL 9.1 CVE-2026-29145 CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Nati… Tomcat 1.3.7 / 2.0.14+ Fix from $2,3002026-04-09 HIGH 7.5 CVE-2026-29146EPSS 6% Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 thro… Tomcat 9.0.116 / 10.1.53+ Fix from $1,9502026-04-09 HIGH 7.5 CVE-2026-24880 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This is… Tomcat 9.0.116 / 10.1.53+ Fix from $1,9502026-04-09 HIGH 7.5 CVE-2026-29129 Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, fro… Tomcat 9.0.116 / 10.1.53+ Fix from $1,9502026-04-09 HIGH 7.5 CVE-2026-34483 Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 1… Tomcat 9.0.117 / 10.1.54+ Fix from $1,9502026-04-09 MEDIUM 6.1 CVE-2026-25854 Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects … Tomcat 9.0.116 / 10.1.53+ Fix from $1,6002026-04-09 MEDIUM 5.3 CVE-2026-32990 Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 … Tomcat 9.0.116 / 10.1.53+ Fix from $1,6002026-04-09 HIGH 7.5 CVE-2026-34020 Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint uses HTTP GET method with usern… Openmeetings 9.0.0+ Fix from $1,9502026-04-09 HIGH 7.5 CVE-2026-33266 Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set to default value in openmeeti… Openmeetings 9.0.0+ Fix from $1,9502026-04-09