Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2025-48988EPSS 57% Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7… Tomcat 9.0.106 / 10.1.42+ Fix from $1,9502025-06-16 HIGH 7.5 CVE-2025-49125 Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat.  When using PreResources or PostResources mounted other than… Tomcat 9.0.106 / 10.1.42+ Fix from $1,9502025-06-16 CRITICAL 9.8 CVE-2025-47868 Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that… Nuttx 12.9.0+ Fix from $2,3002025-06-16 CRITICAL 9.8 CVE-2025-47869 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability was discovered in Apache NuttX RTOS apps/exapmles/xmlrpc applic… Nuttx 12.9.0+ Fix from $2,3002025-06-16 HIGH 8.8 CVE-2025-47713 A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT d… Cloudstack 4.19.3.0 / 4.20.1.0+ Fix from $1,9502025-06-10 HIGH 8.8 CVE-2025-47849 A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT d… Cloudstack 4.19.3.0 / 4.20.1.0+ Fix from $1,9502025-06-10 HIGH 8.1 CVE-2025-26521 When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the API key and the secret key of the 'kubeadmin' user of… Cloudstack 4.19.3.0 / 4.20.1.0+ Fix from $1,9502025-06-10 HIGH 8.8 CVE-2025-27818 A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connec… Kafka 3.9.1+ Fix from $1,9502025-06-10 HIGH 7.5 CVE-2025-27817EPSS 65% A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for … Kafka 3.9.1+ Fix from $1,9502025-06-10 HIGH 7.5 CVE-2025-27819 In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka… Kafka after 3.3.2 Fix from $1,9502025-06-10 CRITICAL 9.8 CVE-2025-27531 Deserialization of Untrusted Data vulnerability in Apache InLong.  This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would al… Inlong 2.1.0+ Fix from $2,3002025-06-06 MEDIUM 6.5 CVE-2025-46548 If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authen… Pekko Management 1.6.1+ Fix from $1,6002025-06-03 MEDIUM 6.5 CVE-2025-48912 An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression'… Superset 4.1.2+ Fix from $1,6002025-05-30 HIGH 7.3 CVE-2025-46701 Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that app… Tomcat 9.0.105 / 10.1.41+ Fix from $1,9502025-05-29 HIGH 8.8 CVE-2025-48734 Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop att… Commons Beanutils 1.11.0+ Fix from $1,9502025-05-28 CRITICAL 9.1 CVE-2025-27528 Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability … Inlong 2.2.0+ Fix from $2,3002025-05-28 MEDIUM 6.5 CVE-2025-27522 Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability is… Inlong 2.2.0+ Fix from $1,6002025-05-28 MEDIUM 6.5 CVE-2025-27526 Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability wh… Inlong 2.2.0+ Fix from $1,6002025-05-28 CRITICAL 9.8 CVE-2025-35003 Improper Restriction of Operations within the Bounds of a Memory Buffer and Stack-based Buffer Overflow vulnerabilities were discovered in Apache Nut… Nuttx 12.9.0+ Fix from $2,3002025-05-26 CRITICAL 9.8 CVE-2025-47436 Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially … Orc 1.8.9 / 1.9.6+ Fix from $2,3002025-05-14 HIGH 7.5 CVE-2025-26864 Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of… Iotdb 1.3.4+ Fix from $1,9502025-05-14 HIGH 7.5 CVE-2025-26795 Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC drive… Iotdb 1.3.4 / 2.0.2+ Fix from $1,9502025-05-14 CRITICAL 9.8 CVE-2024-24780 Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious fu… Iotdb 1.3.4+ Fix from $2,3002025-05-14 HIGH 8.8 CVE-2025-27696 Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read… Superset 4.1.2+ Fix from $1,9502025-05-13 MEDIUM 6.5 CVE-2025-46392 Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x. There are a number of issues in Apache Commons Configuration 1.… Commons Configuration 2.0+ Fix from $1,6002025-05-09 HIGH 7.5 CVE-2025-27533EPSS 9% Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers wa… Activemq 5.16.8 / 5.17.7+ Fix from $1,9502025-05-07 HIGH 8.1 CVE-2025-46762 Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code. While 1.15.1 i… Parquet 1.15.2+ Fix from $1,9502025-05-06 HIGH 7.5 CVE-2025-3891 A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service … HTTP Server Patch available Fix from $1,9502025-04-29 CRITICAL 9.8 CVE-2025-31651 Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, i… Tomcat 9.0.104 / 10.1.40+ Fix from $2,3002025-04-28 HIGH 7.5 CVE-2025-31650EPSS 60% Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clea… Tomcat 9.0.104 / 10.1.40+ Fix from $1,9502025-04-28