Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-44416
Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0.
Users are recommended to upgra…
Ranger
No fix yet
CRITICAL 9.8
CVE-2026-55799
Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0
Users are recommended to upgrade to version 2.9.0, which fi…
Ranger
No fix yet
HIGH 7.5
CVE-2026-55814
Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0.
Users are recommended to upgrade to version 2.9.0, which fixes this issue.
Ranger
No fix yet
CRITICAL 9.8
CVE-2026-28672
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger.
This issue affects Apache Ranger…
Ranger
No fix yet
CRITICAL 9.8
CVE-2026-71558
Heap type confusion vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafte…
Fory
1.5.0+
CRITICAL 9.1
CVE-2026-71560
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deser…
Fory
1.5.0+
HIGH 7.5
CVE-2026-71559
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying …
Fory
1.5.0+
CRITICAL 9.1
CVE-2026-32327
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources an…
Apr Util
1.6.4+
CRITICAL 9.1
CVE-2026-34191
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_ora…
Apr Util
after 1.6.3
HIGH 7.5
CVE-2026-34501
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client.
This issue affects Apache Portable Runtime Utility: from 1…
Apr Util
1.6.4+
HIGH 7.5
CVE-2026-34502
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client
This issue affects Apache Portable Runtime Utility: fro…
Apr Util
after 1.6.3
HIGH 7.5
CVE-2025-49506
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potenti…
Apr Util
1.6.4+
CRITICAL 9.8
CVE-2026-68079
In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the im…
Cxf
3.6.12 / 4.1.8+
HIGH 7.5
CVE-2026-68481
In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:tr…
Cxf
3.6.12 / 4.1.8+
CRITICAL 9.1
CVE-2026-61466
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client reg…
Cxf
3.6.12 / 4.1.8+
CRITICAL 9.1
CVE-2026-63687
Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensiti…
Cxf
3.6.12 / 4.1.8+
CRITICAL 9.1
CVE-2026-65583
Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/…
Cxf
3.6.12 / 4.1.8+
HIGH 8.1
CVE-2026-57818
A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting…
Cxf
3.6.12 / 4.1.8+
CRITICAL 9.8
CVE-2026-66909
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in pla…
Cxf
3.6.12 / 4.1.8+
HIGH 8.1
CVE-2026-57817
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache C…
Cxf
3.6.12 / 4.1.8+
HIGH 7.5
CVE-2026-54225
Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no …
Cxf
3.6.12 / 4.1.8+
HIGH 7.5
CVE-2026-57819
Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, …
Cxf
3.6.12 / 4.1.8+
HIGH 7.5
CVE-2026-64958
An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with ma…
Cxf
3.6.12 / 4.1.8+
HIGH 7.5
CVE-2026-65432
Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <…
Cxf
3.6.12 / 4.1.8+
MEDIUM 6.5
CVE-2026-64640
Apache Polaris did not consistently validate storage locations supplied during table and view registration.
An authenticated principal with permissi…
Polaris
after 1.6.0
CRITICAL 9.1
CVE-2026-60053
Insufficient Session Expiration vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
Administrative API keys remained u…
Answer
2.0.2+
HIGH 7.5
CVE-2026-60023
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
Deleted…
Answer
2.0.2+
HIGH 7.5
CVE-2026-48911
Insufficient Verification of Data Authenticity vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
A missing authoriza…
Answer
2.0.2+
MEDIUM 6.5
CVE-2026-48912
Improper Input Validation vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
A missing ownership check in the avatar…
Answer
2.0.2+
MEDIUM 6.5
CVE-2026-50749
Improper Authorization vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
Any authenticated user can reject arbitrary…
Answer
2.0.2+