Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-46454 Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeux (CometD) message headers in… Camel 4.14.8 / 4.18.3+ Fix from $2,3002026-07-06 CRITICAL 9.8 CVE-2026-46455 Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper KeycloakSecurityHelper.parseAnd… Camel 4.18.3 / 4.21.0+ Fix from $2,3002026-07-06 CRITICAL 9.8 CVE-2026-46456 Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs component map inbound message attributes into the Ca… Camel 4.14.8 / 4.18.3+ Fix from $2,3002026-07-06 HIGH 7.5 CVE-2026-46457 Improper Input Validation vulnerability in Apache Camel NATS component. The camel-nats component maps inbound NATS message headers into the Camel Ex… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 MEDIUM 5.3 CVE-2026-46453 Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel ElasticSearch Rest Client. The camel-elast… Camel 4.14.8 / 4.18.3+ Fix from $1,6002026-07-06 CRITICAL 9.8 CVE-2026-24014 Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without suffici… Iotdb 2.0.8+ Fix from $2,3002026-07-06 CRITICAL 9.1 CVE-2026-24013 Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter.… Iotdb 2.0.8+ Fix from $2,3002026-07-06 CRITICAL 9.1 CVE-2026-40047 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. The camel-doclin… Camel 4.18.3+ Fix from $2,3002026-07-06 HIGH 8.1 CVE-2026-42527 Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several Apache Camel components … Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 HIGH 8.1 CVE-2026-43865 Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component creates and manages Hazelcast ins… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 HIGH 8.1 CVE-2026-40859 Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP response bodies carrying the Conte… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 HIGH 7.5 CVE-2026-24012 Uncontrolled Resource Consumption vulnerability in Apache IoTDB.  Some interface fails to impose reasonable limits on the time span and aggregation … Iotdb 2.0.8+ Fix from $1,9502026-07-06 HIGH 7.3 CVE-2026-43866 Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. JmsBinding.extractBodyFromJms() in camel-jms - and the … Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 HIGH 7.5 CVE-2026-47896 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). T… Lucene.net Mitigation only Fix from $1,9502026-07-03 CRITICAL 9.8 CVE-2026-47898 Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Ap… Lucene.net Mitigation only Fix from $2,3002026-07-03 HIGH 7.5 CVE-2026-47897 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). T… Lucene.net Mitigation only Fix from $1,9502026-07-03 HIGH 7.5 CVE-2026-54428 Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earl… Httpcomponents Core after 5.4.2 Fix from $1,9502026-07-01 HIGH 7.5 CVE-2026-54399 Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlie… Httpcomponents Core after 5.4.2 Fix from $1,9502026-07-01 MEDIUM 5.4 CVE-2025-53648 SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files. Users are recommended to… Gravitino 1.0.0+ Fix from $1,6002026-06-30 HIGH 7.5 CVE-2026-53916 Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. An unauthenticated client… Activemq 5.19.8 / 6.2.7+ Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-53917 Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker. A… Activemq 5.19.8 / 6.2.7+ Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-54475 Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic temporary destinations … Activemq 5.19.8 / 6.2.7+ Fix from $1,9502026-06-30 MEDIUM 6.1 CVE-2026-52760 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console. … Activemq 5.19.8 / 6.2.7+ Fix from $1,6002026-06-30 HIGH 8.1 CVE-2026-49877 Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can access /admin/* paths in the… Activemq 5.19.8 / 6.2.7+ Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-49432 Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. A remote unauthenticated peer that can reach… Activemq 5.19.8 / 6.2.7+ Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-49434 Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to publish or m… Activemq 5.19.8 / 6.2.7+ Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-50734 Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All. An unauthenticated networ… Activemq 5.19.8 / 6.2.7+ Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-50750 Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Following the fix for CVE-2026-4… Activemq Mitigation only Fix from $1,9502026-06-30 CRITICAL 9.1 CVE-2026-55276 Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not inc… Tomcat 9.0.119 / 10.1.56+ Fix from $2,3002026-06-29 HIGH 7.3 CVE-2026-55957 Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed a… Tomcat 9.0.101 / 10.1.37+ Fix from $1,9502026-06-29