Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2026-30778
The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.
This issue affects Apache SkyWa…
Skywalking
10.4.0+
HIGH 8.1
CVE-2025-54550
The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value
from xcom in the way that could be ex…
Airflow
3.2.0+
CRITICAL 9.1
CVE-2026-31908
Header injection vulnerability in Apache APISIX.
The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious…
Apisix
3.16.0+
HIGH 7.5
CVE-2026-31923
Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX.
This can occur due to `ssl_verify` in openid-connect plugin configur…
Apisix
3.16.0+
MEDIUM 5.3
CVE-2026-31924
Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX.
tencent-cloud-cls log export uses plaintext HTTP
This issue affects …
Apisix
3.16.0+
HIGH 8.8
CVE-2026-33858
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbit…
Airflow
3.2.0+
HIGH 7.5
CVE-2025-66236
Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to …
Airflow
3.2.0+
HIGH 7.1
CVE-2026-34476
Server-Side Request Forgery via SW-URL Header vulnerability in Apache SkyWalking MCP.
This issue affects Apache SkyWalking MCP: 0.1.0.
Users are re…
Skywalking Mcp
0.2.0+
HIGH 8.8
CVE-2026-35337
Deserialization of Untrusted Data vulnerability in Apache Storm.
Versions Affected:
before 2.8.6.
Description:
When processing topology credential…
Storm
2.8.6+
MEDIUM 5.4
CVE-2026-35565
Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI
Versions Affected: before 2.8.6
Description: The Storm UI …
Storm
2.8.6+
MEDIUM 5.3
CVE-2026-40021
Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J https://loggi…
Log4net
3.3.0+
MEDIUM 5.3
CVE-2026-40023
Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions before 1.7.0, fails to sanit…
Log4cxx
1.7.0+
HIGH 7.5
CVE-2026-34478
Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vul…
Log4j
2.25.4+
HIGH 7.5
CVE-2026-34479
The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML o…
Log4j
2.25.4+
HIGH 7.5
CVE-2026-34480
Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to …
Log4j
2.25.4+
HIGH 7.5
CVE-2026-34481
Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, pr…
Log4j
2.25.4+
MEDIUM 5.9
CVE-2026-34477
The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when ena…
Log4j
2.25.4+
HIGH 7.5
CVE-2026-39304
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ.
ActiveMQ NIO SSL transports do…
Activemq
5.19.4 / 6.2.4+
HIGH 7.5
CVE-2026-34486 KEVEPSS 83%
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.
…
Tomcat
Mitigation only
HIGH 7.5
CVE-2026-34487
Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernet…
Tomcat
9.0.117 / 10.1.54+
MEDIUM 6.5
CVE-2026-34500
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat.
This issue affe…
Tomcat
9.0.117 / 10.1.54+
CRITICAL 9.1
CVE-2026-29145
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Nati…
Tomcat
1.3.7 / 2.0.14+
HIGH 7.5
CVE-2026-29146EPSS 6%
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.
This issue affects Apache Tomcat: from 11.0.0-M1 thro…
Tomcat
9.0.116 / 10.1.53+
HIGH 7.5
CVE-2026-24880
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension.
This is…
Tomcat
9.0.116 / 10.1.53+
HIGH 7.5
CVE-2026-29129
Configured cipher preference order not preserved vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, fro…
Tomcat
9.0.116 / 10.1.53+
HIGH 7.5
CVE-2026-34483
Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat.
This issue affects Apache Tomcat: from 1…
Tomcat
9.0.117 / 10.1.54+
MEDIUM 6.1
CVE-2026-25854
Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve.
This issue affects …
Tomcat
9.0.116 / 10.1.53+
MEDIUM 5.3
CVE-2026-32990
Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614.
This issue affects Apache Tomcat: from 11.0.15 …
Tomcat
9.0.116 / 10.1.53+
HIGH 7.5
CVE-2026-34020
Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings.
The REST login endpoint uses HTTP GET method with usern…
Openmeetings
9.0.0+
HIGH 7.5
CVE-2026-33266
Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings.
The remember-me cookie encryption key is set to default value in openmeeti…
Openmeetings
9.0.0+