Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-44416 Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgra… Ranger No fix yet Fix from $5,7502026-08-10 CRITICAL 9.8 CVE-2026-55799 Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fi… Ranger No fix yet Fix from $5,7502026-08-10 HIGH 7.5 CVE-2026-55814 Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. Ranger No fix yet Fix from $4,9002026-08-10 CRITICAL 9.8 CVE-2026-28672 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger… Ranger No fix yet Fix from $5,7502026-08-10 CRITICAL 9.8 CVE-2026-71558 Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafte… Fory 1.5.0+ Fix from $2,3002026-08-07 CRITICAL 9.1 CVE-2026-71560 Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deser… Fory 1.5.0+ Fix from $2,3002026-08-07 HIGH 7.5 CVE-2026-71559 Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying … Fory 1.5.0+ Fix from $1,9502026-08-07 CRITICAL 9.1 CVE-2026-32327 A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources an… Apr Util 1.6.4+ Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-34191 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_ora… Apr Util after 1.6.3 Fix from $2,3002026-08-06 HIGH 7.5 CVE-2026-34501 Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1… Apr Util 1.6.4+ Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-34502 Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: fro… Apr Util after 1.6.3 Fix from $1,9502026-08-06 HIGH 7.5 CVE-2025-49506 APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potenti… Apr Util 1.6.4+ Fix from $1,9502026-08-06 CRITICAL 9.8 CVE-2026-68079 In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the im… Cxf 3.6.12 / 4.1.8+ Fix from $2,3002026-08-06 HIGH 7.5 CVE-2026-68481 In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:tr… Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 CRITICAL 9.1 CVE-2026-61466 In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client reg… Cxf 3.6.12 / 4.1.8+ Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-63687 Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensiti… Cxf 3.6.12 / 4.1.8+ Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-65583 Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/… Cxf 3.6.12 / 4.1.8+ Fix from $2,3002026-08-06 HIGH 8.1 CVE-2026-57818 A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting… Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 CRITICAL 9.8 CVE-2026-66909 Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in pla… Cxf 3.6.12 / 4.1.8+ Fix from $2,3002026-08-06 HIGH 8.1 CVE-2026-57817 The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache C… Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-54225 Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no … Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-57819 Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, … Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-64958 An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with ma… Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-65432 Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <… Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 MEDIUM 6.5 CVE-2026-64640 Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permissi… Polaris after 1.6.0 Fix from $1,6002026-08-06 CRITICAL 9.1 CVE-2026-60053 Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained u… Answer 2.0.2+ Fix from $2,3002026-08-05 HIGH 7.5 CVE-2026-60023 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Deleted… Answer 2.0.2+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-48911 Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing authoriza… Answer 2.0.2+ Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-48912 Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar… Answer 2.0.2+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-50749 Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary… Answer 2.0.2+ Fix from $1,6002026-08-05