Apache Software Foundation
181 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-60080
N/A
Apache Fory — Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory …
2026-07-21
CVE-2026-64606
CRITICAL 9.8
Apache Fory — Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during…
2026-07-21
CVE-2026-64608
CRITICAL 9.8
Apache Fory — Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing dat…
2026-07-21
CVE-2026-64609
CRITICAL 9.1
Apache Fory — Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, rea…
2026-07-21
CVE-2026-53405
CRITICAL 9.8
Apache Syncope — Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate en…
2026-07-20
CVE-2026-53421
CRITICAL 9.8
Apache Syncope — Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate …
2026-07-20
CVE-2026-56452
HIGH 7.5
Apache Mina Sshd — Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-si…
2026-07-20
CVE-2026-56623
HIGH 7.1
Apache Mina Sshd — Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for clien…
2026-07-20
CVE-2026-56624
HIGH 7.3
Apache Mina Sshd — Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for clie…
2026-07-20
CVE-2026-57308
CRITICAL 9.8
Apache Syncope — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache S…
2026-07-20
CVE-2026-58624
MEDIUM 5.4
Apache Mina Sshd — Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side …
2026-07-20
CVE-2026-62183
CRITICAL 9.8
Apache Syncope — Improper Privilege Management vulnerability in Apache Syncope.
When:
* the all-Java user workflow adapter is…
2026-07-20
CVE-2026-62418
HIGH 8.1
Apache Syncope — Low-privileged authenticated Server-Side Request Forgery (SSRF)
vulnerability in Apache Syncope via Connector…
2026-07-20
CVE-2026-63071
CRITICAL 9.8
Apache Syncope — Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate en…
2026-07-20
CVE-2026-59173
HIGH 7.5
Apache Traffic Server — Uncontrolled Resource Consumption vulnerability in Apache Traffic Server.
This issue affects Apache Traffic S…
2026-07-18
CVE-2026-62764
MEDIUM 5.7
Apache Accumulo — Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo.
An authenticated, but low-privi…
2026-07-17
CVE-2026-26032
MEDIUM 5.4
Apache Ivy — The PackagerResolver of Apache Ivy is able to download online
artifacts and to (re)package them in a format de…
2026-07-15
CVE-2026-35152
HIGH 8.8
Apache Fineract — A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versio…
2026-07-15
CVE-2026-56287
HIGH 8.1
Apache Fineract — A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients…
2026-07-15
CVE-2026-57821
HIGH 8.1
Apache Fineract — A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions …
2026-07-15
CVE-2026-49488
MEDIUM 6.5
Apache Openmeetings — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMee…
2026-07-14
CVE-2026-58319
CRITICAL 9.1
Apache Doris — Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauth…
2026-07-14
CVE-2026-59083
CRITICAL 9.1
Apache Tomcat — Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed securi…
2026-07-14
CVE-2026-59084
CRITICAL 9.1
Apache Tomcat — Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configu…
2026-07-14
CVE-2026-62390
CRITICAL 9.8
Apache Kylin — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache K…
2026-07-14
CVE-2026-62392
HIGH 8.8
Apache Kylin — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Ap…
2026-07-14
CVE-2026-62393
MEDIUM 4.3
Apache Kylin — Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorizat…
2026-07-14
CVE-2026-41041
CRITICAL 9.1
Apache Gravitino — URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino.
This issue affe…
2026-07-13
CVE-2026-49876
MEDIUM 6.5
Apache Gravitino — Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud meta…
2026-07-13
CVE-2026-58065
HIGH 8.1
Apache Airflow Git Provider — The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, d…
2026-07-13
CVE-2026-59245
HIGH 8.1
Apache Airflow Fab Provider — In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permi…
2026-07-13
CVE-2026-28564
CRITICAL 9.8
Apache Iotdb — Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB.
REST B…
2026-07-10
CVE-2026-40005
CRITICAL 9.1
Apache Iotdb — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB.
…
2026-07-10
CVE-2026-40006
HIGH 7.5
Apache Iotdb — Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Aut…
2026-07-10
CVE-2026-40007
HIGH 7.5
Apache Iotdb — Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB.
When pipe_air_gap_rec…
2026-07-10
CVE-2026-40008
CRITICAL 9.8
Apache Iotdb — Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoT…
2026-07-10
CVE-2026-40009
MEDIUM 6.5
Apache Iotdb — Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB.
Authenticated users can …
2026-07-10
CVE-2026-40452
HIGH 7.5
Apache Iotdb — Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB.
Authorization bypass in /rest/…
2026-07-10
CVE-2026-40454
HIGH 7.5
Apache Iotdb C++ Client — Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client.
Out-of-bounds reads in…
2026-07-10
CVE-2026-49844
MEDIUM 6.3
Apache Log4j Api — Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API…
2026-07-10
CVE-2026-57111
HIGH 7.5
Apache Helix Rest — Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filt…
2026-07-09
CVE-2026-41042
CRITICAL 9.1
Apache Gravitino — Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbi…
2026-07-08
CVE-2026-33264
CRITICAL 9.8
Apache Airflow — A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class…
2026-07-07
CVE-2026-48828
MEDIUM 6.5
Apache Airflow — The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-ba…
2026-07-07
CVE-2026-48891
MEDIUM 4.3
Apache Airflow — A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filte…
2026-07-07
CVE-2026-48892
MEDIUM 6.5
Apache Airflow — The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFL…
2026-07-07
CVE-2026-49296
MEDIUM 6.5
Apache Airflow — Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-loca…
2026-07-07
CVE-2026-49487
MEDIUM 6.5
Apache Airflow — In Apache Airflow before 3.3.0, the REST API task-instance detail and list
endpoints returned a deferred task'…
2026-07-07
CVE-2026-24012
HIGH 7.5
Apache Iotdb — Uncontrolled Resource Consumption vulnerability in Apache IoTDB.
Some interface fails to impose reasonable
l…
2026-07-06
CVE-2026-24013
CRITICAL 9.1
Apache Iotdb — Authentication Bypass by Spoofing vulnerability in Apache IoTDB.
Certain Thrift RPC query handlers lack strict…
2026-07-06
CVE-2026-24014
CRITICAL 9.8
Apache Iotdb — Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR na…
2026-07-06
CVE-2026-40047
CRITICAL 9.1
Apache Camel — Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Cam…
2026-07-06
CVE-2026-40859
HIGH 8.1
Apache Camel — Deserialization of Untrusted Data vulnerability in Apache Camel.
The camel-vertx-http component deserializes …
2026-07-06
CVE-2026-42527
HIGH 8.1
Apache Camel — Deserialization of Untrusted Data vulnerability in Apache Camel.
The default ObjectInputFilter pattern shippe…
2026-07-06
CVE-2026-43825
HIGH 7.3
Apache Opennlp :: Core :: Ml :: Libsvm — Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel
Versions Affected:
before 3.0.0-M4 (libsvm …
2026-07-06
CVE-2026-43865
HIGH 8.1
Apache Camel — Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component.
The camel-hazelcast comp…
2026-07-06
CVE-2026-43866
HIGH 7.3
Apache Camel — Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component.
JmsBinding.extra…
2026-07-06
CVE-2026-43867
CRITICAL 9.8
Apache Camel — Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component.
The camel-pqc component persis…
2026-07-06
CVE-2026-46453
MEDIUM 5.3
Apache Camel — Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Elas…
2026-07-06
CVE-2026-46454
CRITICAL 9.8
Apache Camel — Improper Input Validation vulnerability in Apache Camel Cometd Component.
The camel-cometd component maps inb…
2026-07-06
CVE-2026-46455
CRITICAL 9.8
Apache Camel — Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component.
The camel-keycloak security…
2026-07-06
CVE-2026-46456
CRITICAL 9.8
Apache Camel — Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component.
The camel-aws2-sqs component map…
2026-07-06
CVE-2026-46457
HIGH 7.5
Apache Camel — Improper Input Validation vulnerability in Apache Camel NATS component.
The camel-nats component maps inbound…
2026-07-06
CVE-2026-46584
LOW 3.7
Apache Camel Mail — Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache …
2026-07-06
CVE-2026-46585
HIGH 7.5
Apache Camel Lucene — Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Luce…
2026-07-06
CVE-2026-46587
HIGH 7.3
Apache Camel — Improper Input Validation vulnerability in Apache Camel.
This issue affects Apache Camel: through 4.14.7, fro…
2026-07-06
CVE-2026-46588
HIGH 7.3
Apache Camel — Improper Input Validation vulnerability in Apache Camel.
This issue affects Apache Camel: through 4.14.7, fro…
2026-07-06
CVE-2026-46590
HIGH 8.8
Apache Camel — Deserialization of Untrusted Data vulnerability in Apache Camel PQC component.
The camel-pqc component persis…
2026-07-06
CVE-2026-46591
HIGH 8.2
Apache Camel — Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component.…
2026-07-06
CVE-2026-46592
HIGH 7.5
Apache Camel — Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel …
2026-07-06
CVE-2026-46726
HIGH 7.5
Apache Camel Vertx Websocket — Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request For…
2026-07-06
CVE-2026-48203
CRITICAL 9.1
Apache Camel — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper I…
2026-07-06
CVE-2026-48204
CRITICAL 9.8
Apache Camel — Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs compo…
2026-07-06
CVE-2026-48205
CRITICAL 9.1
Apache Camel Dns — Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component.
Th…
2026-07-06
CVE-2026-48206
MEDIUM 5.3
Apache Camel Jira — Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel JIRA…
2026-07-06
CVE-2026-49042
HIGH 7.3
Apache Camel — Improper Input Validation vulnerability in Apache Camel.
This issue affects Apache Camel: from 4.8.0 through …
2026-07-06
CVE-2026-49086
MEDIUM 6.5
Apache Camel Dapr — Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel …
2026-07-06
CVE-2026-49097
MEDIUM 6.5
Apache Camel — Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Componen…
2026-07-06
CVE-2026-49098
MEDIUM 5.3
Apache Camel — Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Componen…
2026-07-06
CVE-2026-49099
MEDIUM 5.3
Apache Camel Salesforce — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorizat…
2026-07-06
CVE-2026-49297
HIGH 8.1
Apache Airflow Google Provider — Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined G…
2026-07-06
CVE-2026-49365
MEDIUM 5.3
Apache Camel — Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Netty HTTP componen…
2026-07-06
CVE-2026-53913
CRITICAL 9.8
Apache Camel Keycloak — Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') v…
2026-07-06
CVE-2026-55993
HIGH 7.5
Apache Camel Atmosphere Websocket — Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request For…
2026-07-06
CVE-2026-55994
HIGH 7.5
Apache Camel Iggy — Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request For…
2026-07-06
CVE-2026-56139
MEDIUM 5.3
Apache Camel Undertow — Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Undertow Component.…
2026-07-06
CVE-2026-56140
CRITICAL 9.8
Apache Camel Aws2 Sns — Improper Input Validation vulnerability in Apache Camel AWS SNS component.
The camel-aws2-sns component filt…
2026-07-06
CVE-2026-47896
HIGH 8.9
Apache Lucene.Net — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.…
2026-07-03
CVE-2026-47897
HIGH 8.9
Apache Lucene.Net — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.…
2026-07-03
CVE-2026-47898
MEDIUM 4
Apache Lucene.Net — Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.…
2026-07-03
CVE-2026-54399
HIGH 7.5
Apache Httpcomponents Core — Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (…
2026-07-01
CVE-2026-54428
HIGH 7.5
Apache Httpcomponents Core — Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core…
2026-07-01
CVE-2026-49432
HIGH 7.5
Apache Activemq — Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp.
A rem…
2026-06-30
CVE-2026-49434
HIGH 7.5
Apache Activemq Broker — Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
An a…
2026-06-30
CVE-2026-49877
HIGH 8.1
Apache Activemq — Improper Authorization vulnerability in Apache ActiveMQ.
An authenticated low-privilege Web Console user by d…
2026-06-30
CVE-2026-50734
HIGH 7.5
Apache Activemq Client — Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache A…
2026-06-30
CVE-2026-50750
HIGH 7.5
Apache Activemq Broker — Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ …
2026-06-30
CVE-2026-52760
MEDIUM 6.1
Apache Activemq — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache A…
2026-06-30
CVE-2026-53916
HIGH 7.5
Apache Activemq — Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache Acti…
2026-06-30
CVE-2026-53917
HIGH 7.5
Apache Activemq — Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache Acti…
2026-06-30
CVE-2026-54475
HIGH 7.5
Apache Activemq Broker — Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.
Apache A…
2026-06-30
CVE-2025-53648
MEDIUM 5.4
Apache Gravitino — SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or t…
2026-06-30
CVE-2026-50229
MEDIUM 6.1
Apache Tomcat — Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number gues…● PoC
2026-06-29
CVE-2026-53404
HIGH 7.3
Apache Tomcat — Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the …
2026-06-29
CVE-2026-53434
CRITICAL 9.1
Apache Tomcat — Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM bas…
2026-06-29
CVE-2026-55276
CRITICAL 9.1
Apache Tomcat — Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty…
2026-06-29
CVE-2026-55955
MEDIUM 6.5
Apache Tomcat — Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionIntercept…
2026-06-29
CVE-2026-55956
MEDIUM 6.5
Apache Tomcat — Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default …
2026-06-29
CVE-2026-55957
HIGH 7.3
Apache Tomcat — Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to au…
2026-06-29
CVE-2026-49486
HIGH 7.5
Apache Airflow Ftp Provider — The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never calle…
2026-06-26
CVE-2026-57914
MEDIUM 6.5
Apache Kerby — By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a Stac…
2026-06-26
CVE-2026-57915
HIGH 7.3
Apache Kerby — It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an un…
2026-06-26
CVE-2025-55017
CRITICAL 9.1
Apache Iotdb — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB.
…
2026-06-26
CVE-2025-64152
CRITICAL 9.1
Apache Iotdb — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB.
…
2026-06-26
CVE-2026-41566
CRITICAL 9.4
Apache Kvrocks — Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks.
This issue affec…
2026-06-25
CVE-2026-45188
LOW 2.4
Apache Kvrocks — Relative Path Traversal vulnerability in Apache Kvrocks.
This issue affects Apache Kvrocks: from 1.0.0 throug…
2026-06-25
CVE-2026-46751
MEDIUM 5.5
Apache Kvrocks — A vulnerability in Apache Kvrocks.
This issue affects Apache Kvrocks: from 2.2.0 through 2.15.0.
Users are r…
2026-06-25
CVE-2026-46752
CRITICAL 10
Apache Kvrocks — Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks.
This issue affects Apache Kvrocks: …
2026-06-25
CVE-2026-54226
MEDIUM 6.4
Apache Kvrocks — A vulnerability in Apache Kvrocks.
This issue affects Apache Kvrocks: from 2.6.0 through 2.15.0.
Users are r…
2026-06-25
CVE-2026-56091
HIGH 8.2
Apache Shiro — When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted HTTP request…
2026-06-25
CVE-2026-56130
LOW 2
Apache Shiro — "Remember me" cookie age is not verified on the server. This potentially allows an attacker to intercept a val…
2026-06-25
CVE-2026-44911
LOW 2.3
Apache Nifi — Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 a…
2026-06-22
CVE-2026-44913
MEDIUM 5.2
Apache Nifi — Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 …
2026-06-22
CVE-2026-44914
HIGH 7.5
Apache Nifi — Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extensio…
2026-06-22
CVE-2026-54665
MEDIUM 6.3
Apache Nifi — Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that …
2026-06-22
CVE-2025-62198
MEDIUM 5.4
Apache Atlas — An authenticated user can perform XSS.
This issue affects Apache Atlas versions 2.4.0 and earlier.
Users are…
2026-06-22
CVE-2025-66336
HIGH 8.1
Apache Doris Mcp Server — Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled dat…
2026-06-22
CVE-2026-39998
MEDIUM 5.8
Apache Apisix — Improper Input Validation vulnerability in Apache APISIX.
The attacker can take advantage of certain configur…
2026-06-19
CVE-2026-39999
HIGH 7
Apache Apisix — Authentication Bypass by Spoofing vulnerability in Apache APISIX.
The attacker can completely bypass authenti…
2026-06-19
CVE-2026-44046
LOW 2.3
Apache Apisix — Use of Less Trusted Source vulnerability in Apache APISIX.
Attacker can take advantage of wolf-rbac plugin un…
2026-06-19
CVE-2026-44087
MEDIUM 5.3
Apache Apisix — Insufficient Verification of Data Authenticity vulnerability in Apache APISIX.
The openid-connect plugin unde…
2026-06-19
CVE-2026-44915
LOW 2.1
Apache Apisix — URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX.
The default configuration…
2026-06-19
CVE-2026-47339
MEDIUM 5.3
Apache Apisix — Incorrect Authorization vulnerability in Apache APISIX.
An attacker can capitalise on authz-casdoor plugin un…
2026-06-19
CVE-2026-47341
MEDIUM 6.3
Apache Apisix — Authentication Bypass by Capture-replay vulnerability in Apache APISIX.
Attacker can benefit from certain con…
2026-06-19
CVE-2026-48895
LOW 2.1
Apache Apisix — URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX.
The attacker could manipu…
2026-06-19
CVE-2026-49230
MEDIUM 6.3
Apache Apisix — Improper Validation of Integrity Check Value vulnerability in Apache APISIX.
The jwe-decrypt plugin under def…
2026-06-19
CVE-2026-49231
LOW 2.3
Apache Apisix — Authentication Bypass by Spoofing vulnerability in opa plugin.
An attacker could relay spoofed identity heade…
2026-06-19
CVE-2026-49871
LOW 2.1
Apache Apisix — Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations.
This def…
2026-06-19
CVE-2026-49872
MEDIUM 5.3
Apache Apisix — Improper Authentication vulnerability in Apache APISIX.
When the cas-auth plugin is used in a route, an attac…
2026-06-19
CVE-2026-32966
HIGH 7.5
Apache Dolphinscheduler — DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache Dolphi…
2026-06-17
CVE-2026-32967
MEDIUM 6.5
Apache Dolphinscheduler — Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler.
This issue …
2026-06-17
CVE-2026-41280
MEDIUM 4.9
Apache Dolphinscheduler — Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in …
2026-06-17
CVE-2026-42357
MEDIUM 6.5
Apache Dolphinscheduler — Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projec…
2026-06-17
CVE-2026-47340
MEDIUM 6.5
Apache Dolphinscheduler — Allow authenticated users to access alert instances associated with alert groups they do not have permission t…
2026-06-17
CVE-2026-49268
HIGH 8.8
Apache Shiro — A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultL…
2026-06-17
CVE-2026-50203
CRITICAL 9.1
Apache Airflow Sftp Provider — A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a ma…
2026-06-17
CVE-2026-49875
MEDIUM 6.5
Apache Cxf — Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the…
2026-06-12
CVE-2026-50623
MEDIUM 4.8
Apache Cxf — An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a …
2026-06-12
CVE-2026-50627
CRITICAL 9.1
Apache Cxf — The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT …
2026-06-12
CVE-2026-50628
CRITICAL 9.8
Apache Cxf — A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while b…
2026-06-12
CVE-2026-50629
MEDIUM 5.3
Apache Cxf — The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning m…
2026-06-12
CVE-2026-50630
MEDIUM 6.5
Apache Cxf — A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authen…
2026-06-12
CVE-2026-50631
HIGH 7.4
Apache Cxf — A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypas…
2026-06-12
CVE-2026-50632
HIGH 8.1
Apache Cxf — A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) …
2026-06-12
CVE-2026-50633
HIGH 8.1
Apache Cxf — A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for…
2026-06-12
CVE-2026-50634
MEDIUM 6.5
Apache Cxf — A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadat…
2026-06-12
CVE-2026-50645
HIGH 7.5
Apache Cxf — There is no restriction on the amount of attachment headers that a message can contain when being deserialized…
2026-06-12
CVE-2026-25700
HIGH 7.2
Apache Answer — Improper Restriction of Security Token Assignment vulnerability in Apache Answer.
This issue affects Apache A…
2026-06-10
CVE-2026-47342
HIGH 8.8
Apache Ofbiz — A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain high…
2026-06-10
CVE-2026-50223
HIGH 8.8
Apache Ofbiz — Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privilege…
2026-06-10
CVE-2026-25688
MEDIUM 6.1
Apache Answer — Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer.
This issue affects Apache Ans…
2026-06-09
CVE-2026-25699
MEDIUM 6.1
Apache Answer — Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue …
2026-06-09
CVE-2026-33582
MEDIUM 6.5
Apache Answer — Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
This issue affects Apache Ans…
2026-06-09
CVE-2026-34031
MEDIUM 6.5
Apache Answer — Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
This issue affects Apache Ans…
2026-06-09
CVE-2026-34033
MEDIUM 5.4
Apache Answer — Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer.
…
2026-06-09
CVE-2026-34905
MEDIUM 6.5
Apache Answer — Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects…
2026-06-09
CVE-2026-49818
MEDIUM 6.5
Apache Airflow Samba Provider — The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path w…
2026-06-09
CVE-2026-29167
CRITICAL 9.8
Apache Http Server — Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration
This issue af…
2026-06-08
CVE-2026-29170
MEDIUM 6.1
Apache Http Server — A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP S…
2026-06-08
CVE-2026-34355
HIGH 7.5
Apache Http Server — A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted …
2026-06-08
CVE-2026-34356
HIGH 7.5
Apache Http Server — Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassRev…
2026-06-08
CVE-2026-42535
CRITICAL 9.1
Apache Http Server — A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly ma…
2026-06-08
CVE-2026-42536
HIGH 7.5
Apache Http Server — Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted…
2026-06-08
CVE-2026-43951
MEDIUM 6.5
Apache Http Server — Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response lan…
2026-06-08
CVE-2026-44119
MEDIUM 5.5
Apache Http Server — Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess au…
2026-06-08
CVE-2026-44185
HIGH 7.3
Apache Http Server — Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP…
2026-06-08
CVE-2026-44186
HIGH 7.3
Apache Http Server — Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTT…
2026-06-08
CVE-2026-44631
CRITICAL 9.8
Apache Http Server — Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.
Th…
2026-06-08
CVE-2026-47430
CRITICAL 9.5
Cordova Plugin Inappbrowser — ## Summary
The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMess…
2026-06-08
CVE-2026-48913
HIGH 7.3
Apache Http Server — Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.
…
2026-06-08
CVE-2026-49975
HIGH 7.5
Apache Http Server — Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of …● PoC
2026-06-08