Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-68981 Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforc… Nifi 2.11.0+ Fix from $1,9502026-08-03 CRITICAL 9.8 CVE-2026-68979 Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components refer… Nifi 2.11.0+ Fix from $2,3002026-08-03 HIGH 7.5 CVE-2026-61372 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena F… Jena Fuseki 6.2.0+ Fix from $1,9502026-08-03 HIGH 8.1 CVE-2026-62391 The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-… Kyuubi 1.12.0+ Fix from $1,9502026-07-31 MEDIUM 5.3 CVE-2026-64607 HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an inv… Httpclient 5.6.3+ Fix from $1,6002026-07-31 MEDIUM 6.5 CVE-2026-44615 Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a not… Zeppelin 0.12.1+ Fix from $1,6002026-07-31 CRITICAL 9.8 CVE-2026-66756 Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users a… Tika No fix yet Fix from $2,3002026-07-30 HIGH 7.5 CVE-2026-66755 Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker… Tika 3.3.2+ Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-52680 Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote … Kyuubi 1.12.0+ Fix from $2,3002026-07-30 MEDIUM 6.5 CVE-2026-48910 A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the markdown renderer, which could … Jspwiki 2.12.4+ Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-44616 LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, al… Zeppelin 0.12.1+ Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-44617 LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing LDAP search filters ins… Zeppelin 0.12.1+ Fix from $1,6002026-07-30 MEDIUM 6.1 CVE-2026-44613 Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and a… Zeppelin 0.12.1+ Fix from $1,6002026-07-30 HIGH 8.8 CVE-2026-28813 Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.… Jspwiki 2.12.4+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-28814 Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWi… Jspwiki 2.12.4+ Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-28812 UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommende… Jspwiki 2.12.4+ Fix from $2,3002026-07-30 HIGH 7.5 CVE-2026-28811 Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes this… Jspwiki 2.12.4+ Fix from $1,9502026-07-30 MEDIUM 6.5 CVE-2026-23985 A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The vulnerability is located in … Superset 6.0.0+ Fix from $1,6002026-07-30 CRITICAL 9.8 CVE-2026-59243 The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or… Apache Airflow Providers Fab 3.7.3+ Fix from $2,3002026-07-29 HIGH 8.2 CVE-2026-58188 Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 … Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-58189 Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traf… Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 CRITICAL 9.8 CVE-2026-58185 The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 thro… Traffic Server 9.2.15 / 10.1.4+ Fix from $2,3002026-07-29 HIGH 8.6 CVE-2026-58182 The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Serv… Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-58181 The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue affects Apache Traffic Server… Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-58183 The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apache Traffic Server: from 8.0.0 … Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-58184 The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects… Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-58186 The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Ser… Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-58187 The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apac… Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 CRITICAL 9.8 CVE-2026-58177 The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Se… Traffic Server 10.1.4+ Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-58179 The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: fro… Traffic Server 9.2.15 / 10.1.4+ Fix from $2,3002026-07-29