Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2025-62235 Authentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could lead to removal of original bon… Nimble 1.9.0+ Fix from $1,9502026-01-10 HIGH 7.5 CVE-2025-52435 J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE. Improper handling of Pause Encryption procedure on Link … Nimble 1.9.0+ Fix from $1,9502026-01-10 HIGH 7.5 CVE-2025-53477 NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL p… Nimble 1.9.0+ Fix from $1,9502026-01-10 CRITICAL 9.1 CVE-2025-68637 The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This insecure configuration expos… Uniffle 0.10.0+ Fix from $2,3002026-01-07 MEDIUM 6.5 CVE-2025-68280 Improper Restriction of XML External Entity Reference vulnerability in Apache SIS. It is possible to write XML files in such a way that, when pars… Spatial Information System after 1.5 Fix from $1,6002026-01-05 HIGH 8.8 CVE-2025-66518 Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and… Kyuubi 1.10.3+ Fix from $1,9502026-01-05 HIGH 8.1 CVE-2025-48769 Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer us… Nuttx 12.11.0+ Fix from $1,9502026-01-01 MEDIUM 6.5 CVE-2025-48768 Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX RTOS that allowed root files… Nuttx 12.10.0+ Fix from $1,6002026-01-01 HIGH 8.1 CVE-2025-47411EPSS 15% A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows th… Streampipes 0.98.0+ Fix from $1,9502026-01-01 HIGH 8.8 CVE-2025-66524 Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Ser… Nifi 2.7.0+ Fix from $1,9502025-12-19 CRITICAL 9.8 CVE-2025-67895 Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on … Apache Airflow Providers Edge3 2.0.0+ Fix from $2,3002025-12-17 MEDIUM 6.5 CVE-2025-66388 A vulnerability in Apache Airflow allowed authenticated UI users to view secret values in rendered templates due to secrets not being properly redact… Airflow 3.1.4+ Fix from $1,6002025-12-15 MEDIUM 5.9 CVE-2025-53960 When issuing JSON Web Tokens (JWT), Apache StreamPark directly uses the user's password as the HMAC signing key (e.g., with the HS256 algorithm). An … Streampark 2.1.7+ Fix from $1,6002025-12-12 CRITICAL 9.8 CVE-2025-54947 In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs b… Streampark 2.1.7+ Fix from $2,3002025-12-12 HIGH 7.5 CVE-2025-54981 Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, inclu… Streampark 2.1.7+ Fix from $1,9502025-12-12 CRITICAL 9.1 CVE-2025-58130 Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in ver… Fineract 1.12.1+ Fix from $2,3002025-12-12 HIGH 8.8 CVE-2025-26866 A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix en… Hugegraph 1.7.0+ Fix from $1,9502025-12-12 HIGH 8.1 CVE-2025-58137 Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is … Fineract 1.12.1+ Fix from $1,9502025-12-12 MEDIUM 6.5 CVE-2025-23408 Weak Password Requirements vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.10.1. The issue is fixed in version 1.11.… Fineract 1.11.0+ Fix from $1,6002025-12-12 HIGH 8.2 CVE-2025-66675 Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts… Struts 6.8.0 / 7.1.1+ Fix from $1,9502025-12-10 HIGH 8.3 CVE-2025-58098 Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to… HTTP Server 2.4.66+ Fix from $1,9502025-12-05 HIGH 7.5 CVE-2025-59775 Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off  allows to po… HTTP Server 2.4.66+ Fix from $1,9502025-12-05 MEDIUM 6.5 CVE-2025-65082 Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache co… HTTP Server 2.4.66+ Fix from $1,6002025-12-05 MEDIUM 5.4 CVE-2025-66200 mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in hta… HTTP Server 2.4.66+ Fix from $1,6002025-12-05 HIGH 7.5 CVE-2025-55753 An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the bac… HTTP Server 2.4.66+ Fix from $1,9502025-12-05 CRITICAL 9.8 CVE-2025-66516EPSS 79% Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an a… Tika 3.2.2+ Fix from $2,3002025-12-04 HIGH 7.5 CVE-2025-64775 Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts… Struts 6.8.0 / 7.1.1+ Fix from $1,9502025-12-01 HIGH 7.5 CVE-2025-59789 Uncontrolled recursion in the json2pb component in Apache bRPC (version < 1.15.0) on all platforms allows remote attackers to make the server crash v… Brpc 1.15.0+ Fix from $1,9502025-12-01 MEDIUM 5.3 CVE-2025-59792 Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. … Kvrocks 2.14.0+ Fix from $1,6002025-11-28 MEDIUM 5.4 CVE-2025-59790 Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommende… Kvrocks 2.14.0+ Fix from $1,6002025-11-28