Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-48834 Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticate… Answer 2.0.2+ Fix from $1,9502026-08-05 CRITICAL 9.8 CVE-2026-61484 ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As th… Lucy No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-61486 ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this pro… Lucy No fix yet Fix from $2,3002026-08-05 HIGH 7.5 CVE-2026-61485 ** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue affects Apache Lucy: all versio… Lucy No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-61483 ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project … Lucy No fix yet Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-68078 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso… Qpid Broker J 10.1.0+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-68080 It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resou… Qpid Broker J 10.1.0+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-68075 An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache … Qpid Broker J 10.1.0+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-68077 An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading… Qpid Broker J 10.1.0+ Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-67592 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso… Qpid Protonj2 1.2.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-67552 A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects… Qpid Proton Dotnet 1.1.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-67590 A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects… Qpid Protonj2 1.2.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-68073 A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects… Qpid Broker J 10.1.0+ Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-67554 An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading… Qpid Proton Dotnet 1.1.0+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-67555 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso… Qpid Proton Dotnet 1.1.0+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-67553 An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache … Qpid Proton Dotnet 1.1.0+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-67591 An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache … Qpid Protonj2 1.2.0+ Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-66274 A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects… Qpid Proton J 0.35.0+ Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-66277 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso… Qpid Proton J 0.35.0+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-66275 An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache … Qpid Proton J 0.35.0+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-66276 An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading… Qpid Proton J 0.35.0+ Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-67465 A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af… Qpid Proton Dotnet 1.1.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-67551 pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue… Qpid Proton Dotnet 1.1.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-67588 A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af… Qpid Protonj2 1.2.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-67589 A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This iss… Qpid Protonj2 1.2.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-68060 A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This iss… Qpid Broker J 10.1.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-68074 A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af… Qpid Broker J 10.1.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-66257 A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af… Qpid Proton J 0.35.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-66273 A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This iss… Qpid Proton J 0.35.0+ Fix from $1,9502026-08-05 CRITICAL 9.1 CVE-2026-68980 Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framewor… Nifi 2.11.0+ Fix from $2,3002026-08-03