Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-64609 Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the b… Fory 1.4.0+ Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2026-64608 Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip pa… Fory 1.4.0+ Fix from $2,3002026-07-21 HIGH 7.3 CVE-2026-56624 Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH. Server… Mina Sshd 2.19.0+ Fix from $1,9502026-07-20 MEDIUM 5.4 CVE-2026-58624 Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.… Mina Sshd 2.19.0+ Fix from $1,6002026-07-20 HIGH 7.5 CVE-2026-56452 Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The impleme… Mina Sshd 2.19.0+ Fix from $1,9502026-07-20 HIGH 7.1 CVE-2026-56623 Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH. A git s… Mina Sshd 2.19.0+ Fix from $1,9502026-07-20 CRITICAL 9.8 CVE-2026-63071 Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can crea… Syncope 4.0.7 / 4.1.2+ Fix from $2,3002026-07-20 CRITICAL 9.8 CVE-2026-57308 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate… Syncope 4.0.7 / 4.1.2+ Fix from $2,3002026-07-20 CRITICAL 9.8 CVE-2026-62183 Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user wor… Syncope 4.0.7 / 4.1.2+ Fix from $2,3002026-07-20 HIGH 8.1 CVE-2026-62418 Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue af… Syncope 4.0.7 / 4.1.2+ Fix from $1,9502026-07-20 CRITICAL 9.8 CVE-2026-53421 Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code ex… Syncope 4.0.7 / 4.1.2+ Fix from $2,3002026-07-20 CRITICAL 9.8 CVE-2026-53405 Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN pr… Syncope 4.0.7 / 4.1.2+ Fix from $2,3002026-07-20 HIGH 7.5 CVE-2026-59173 Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from … Traffic Server 9.2.14 / 10.1.3+ Fix from $1,9502026-07-18 MEDIUM 6.5 CVE-2026-62764 Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user without system permissions m… Accumulo 2.1.6+ Fix from $1,6002026-07-17 MEDIUM 5.4 CVE-2026-26032 The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repa… Ivy 2.6.0+ Fix from $1,6002026-07-15 HIGH 8.1 CVE-2026-56287 A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.… Fineract 1.15.0+ Fix from $1,9502026-07-15 HIGH 8.1 CVE-2026-57821 A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy… Fineract 1.15.0+ Fix from $1,9502026-07-15 HIGH 8.8 CVE-2026-35152 A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report p… Fineract 1.15.0+ Fix from $1,9502026-07-15 CRITICAL 9.8 CVE-2026-62390 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table ca… Kylin 5.0.4+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-62392 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job… Kylin 5.0.4+ Fix from $2,3002026-07-14 MEDIUM 6.5 CVE-2026-49488 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenM… Openmeetings 9.1.0+ Fix from $1,6002026-07-14 CRITICAL 9.1 CVE-2026-58319 Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access … Doris 3.1.0+ Fix from $2,3002026-07-14 CRITICAL 9.1 CVE-2026-59083 Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configura… Tomcat after 11.0.23 Fix from $2,3002026-07-14 CRITICAL 9.1 CVE-2026-59084 Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clea… Tomcat after 11.0.23 Fix from $2,3002026-07-14 HIGH 8.1 CVE-2026-58065 The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An … Apache Airflow Providers Git 0.4.1+ Fix from $1,9502026-07-13 HIGH 8.1 CVE-2026-59245 In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resour… Apache Airflow Providers Fab 3.7.2+ Fix from $1,9502026-07-13 MEDIUM 6.5 CVE-2026-49876 Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job temp… Gravitino 1.3.0+ Fix from $1,6002026-07-13 CRITICAL 9.1 CVE-2026-41041 URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before… Gravitino 1.2.1+ Fix from $2,3002026-07-13 MEDIUM 5.9 CVE-2026-49844 Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON… Log4j 2.25.5+ Fix from $1,6002026-07-10 HIGH 7.5 CVE-2026-57111 Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through… Helix 2.0.1+ Fix from $1,9502026-07-09