Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-23980 Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user wit… Superset 6.0.0+ Fix from $1,6002026-02-24 MEDIUM 6.5 CVE-2026-23982 An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a d… Superset 6.0.0+ Fix from $1,6002026-02-24 HIGH 8.4 CVE-2024-56373 DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server… Airflow 2.11.1+ Fix from $1,9502026-02-24 MEDIUM 6.5 CVE-2025-27555 Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which… Airflow 2.11.1+ Fix from $1,6002026-02-24 HIGH 8.8 CVE-2026-25747 Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes dat… Camel 4.10.9 / 4.14.5+ Fix from $1,9502026-02-23 CRITICAL 9.1 CVE-2026-23552 Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.  The Camel-Keycloak KeycloakSecurityPolicy does not v… Camel 4.18.0+ Fix from $2,3002026-02-23 MEDIUM 6.5 CVE-2025-65995 When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operators. If those kwargs containe… Airflow 2.11.1 / 3.1.4+ Fix from $1,6002026-02-21 HIGH 7.5 CVE-2026-24734 Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port o… Tomcat 1.3.5 / 2.0.12+ Fix from $1,9502026-02-17 CRITICAL 9.1 CVE-2025-66614 Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.… Tomcat 9.0.113 / 10.1.50+ Fix from $2,3002026-02-17 HIGH 7.0 CVE-2026-25087 Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading a… Arrow 23.0.1+ Fix from $1,9502026-02-17 MEDIUM 6.6 CVE-2026-25903 Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required … Nifi 2.8.0+ Fix from $1,6002026-02-17 HIGH 7.3 CVE-2025-33042 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro … Avro 1.11.5+ Fix from $1,9502026-02-13 CRITICAL 9.8 CVE-2026-23906 Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * d… Druid 36.0.0+ Fix from $2,3002026-02-10 HIGH 8.8 CVE-2026-24343 Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat:… Hertzbeat 1.8.0+ Fix from $1,9502026-02-10 MEDIUM 6.5 CVE-2026-24098 Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view impo… Airflow 3.1.7+ Fix from $1,6002026-02-09 MEDIUM 6.5 CVE-2026-22922 Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that can allow an authenticated user with custom permissions limited to tas… Airflow 3.1.7+ Fix from $1,6002026-02-09 MEDIUM 5.3 CVE-2026-23903 Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are recommended to upgr… Shiro 2.0.7+ Fix from $1,6002026-02-09 HIGH 7.5 CVE-2026-24735 Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 1.7.1. … Answer 2.0.0+ Fix from $1,9502026-02-04 MEDIUM 6.8 CVE-2026-23794 Reflected XSS in Apache Syncope's Enduser Login page. An attacker that tricks a legitimate user into clicking a malicious link and logging in to Sync… Syncope 3.0.16 / 4.0.4+ Fix from $1,6002026-02-03 CRITICAL 9.9 CVE-2016-15057 ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum… Continuum Mitigation only Fix from $2,3002026-01-26 HIGH 7.3 CVE-2025-27821 Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client. This issue affects Apache Hadoop: from 3.2.0 before 3.4.2. Users are recomme… Hadoop 3.4.2+ Fix from $1,9502026-01-26 HIGH 8.2 CVE-2026-22022 Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule Based Authorization Plugin" are vulnerable to allowing unauthorized access … Solr 9.10.1+ Fix from $1,9502026-01-21 HIGH 7.1 CVE-2026-22444 The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient input validation on some API parameters, which can cause Solr to check the e… Solr 9.10.1+ Fix from $1,9502026-01-21 MEDIUM 6.5 CVE-2025-59355 A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records the complete input parameter s… Linkis 1.8.0+ Fix from $1,6002026-01-19 HIGH 7.5 CVE-2025-29847 A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and data source functionality, if… Linkis 1.8.0+ Fix from $1,9502026-01-19 HIGH 7.5 CVE-2025-68438 In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length, sensitive values could be e… Airflow 3.1.6+ Fix from $1,9502026-01-16 HIGH 7.5 CVE-2025-68675 In Apache Airflow versions before 3.1.6, and 2.11.1 the proxies and proxy fields within a Connection may include proxy URLs containing embedded authe… Airflow 3.1.6+ Fix from $1,9502026-01-16 CRITICAL 9.8 CVE-2025-60021EPSS 25% Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to … Brpc 1.15.0+ Fix from $2,3002026-01-16 MEDIUM 5.3 CVE-2025-66169 Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before… Camel 4.10.8 / 4.14.3+ Fix from $1,6002026-01-14 HIGH 8.1 CVE-2025-68493EPSS 37% Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from… Struts 6.1.1+ Fix from $1,9502026-01-11