Apache
145 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-26032
MEDIUM 5.4
Apache Ivy — The PackagerResolver of Apache Ivy is able to download online
artifacts and to (re)package them in a format de…
2026-07-15
CVE-2026-35152
HIGH 8.8
Apache Fineract — A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versio…
2026-07-15
CVE-2026-56287
HIGH 8.1
Apache Fineract — A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients…
2026-07-15
CVE-2026-57821
HIGH 8.1
Apache Fineract — A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions …
2026-07-15
CVE-2026-49488
MEDIUM 6.5
Apache Openmeetings — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMee…
2026-07-14
CVE-2026-58319
CRITICAL 9.1
Apache Doris — Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauth…
2026-07-14
CVE-2026-59083
CRITICAL 9.1
Apache Tomcat — Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed securi…
2026-07-14
CVE-2026-59084
CRITICAL 9.1
Apache Tomcat — Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configu…
2026-07-14
CVE-2026-62390
CRITICAL 9.8
Apache Kylin — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache K…
2026-07-14
CVE-2026-62392
HIGH 8.8
Apache Kylin — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Ap…
2026-07-14
CVE-2026-62393
MEDIUM 4.3
Apache Kylin — Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorizat…
2026-07-14
CVE-2026-41041
CRITICAL 9.1
Apache Gravitino — URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino.
This issue affe…
2026-07-13
CVE-2026-49876
MEDIUM 6.5
Apache Gravitino — Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud meta…
2026-07-13
CVE-2026-58065
HIGH 8.1
Apache Airflow Git Provider — The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, d…
2026-07-13
CVE-2026-59245
HIGH 8.1
Apache Airflow Fab Provider — In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permi…
2026-07-13
CVE-2026-49844
MEDIUM 6.3
Apache Log4j Api — Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API…
2026-07-10
CVE-2026-57111
HIGH 7.5
Apache Helix Rest — Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filt…
2026-07-09
CVE-2026-33264
CRITICAL 9.8
Apache Airflow — A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class…
2026-07-07
CVE-2026-48828
MEDIUM 6.5
Apache Airflow — The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-ba…
2026-07-07
CVE-2026-48891
MEDIUM 4.3
Apache Airflow — A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filte…
2026-07-07
CVE-2026-48892
MEDIUM 6.5
Apache Airflow — The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFL…
2026-07-07
CVE-2026-49296
MEDIUM 6.5
Apache Airflow — Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-loca…
2026-07-07
CVE-2026-49487
MEDIUM 6.5
Apache Airflow — In Apache Airflow before 3.3.0, the REST API task-instance detail and list
endpoints returned a deferred task'…
2026-07-07
CVE-2026-24012
HIGH 7.5
Apache Iotdb — Uncontrolled Resource Consumption vulnerability in Apache IoTDB.
Some interface fails to impose reasonable
l…
2026-07-06
CVE-2026-24013
CRITICAL 9.1
Apache Iotdb — Authentication Bypass by Spoofing vulnerability in Apache IoTDB.
Certain Thrift RPC query handlers lack strict…
2026-07-06
CVE-2026-24014
CRITICAL 9.8
Apache Iotdb — Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR na…
2026-07-06
CVE-2026-40047
CRITICAL 9.1
Apache Camel — Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Cam…
2026-07-06
CVE-2026-40859
HIGH 8.1
Apache Camel — Deserialization of Untrusted Data vulnerability in Apache Camel.
The camel-vertx-http component deserializes …
2026-07-06
CVE-2026-42527
HIGH 8.1
Apache Camel — Deserialization of Untrusted Data vulnerability in Apache Camel.
The default ObjectInputFilter pattern shippe…
2026-07-06
CVE-2026-43825
HIGH 7.3
Apache Opennlp :: Core :: Ml :: Libsvm — Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel
Versions Affected:
before 3.0.0-M4 (libsvm …
2026-07-06
CVE-2026-43865
HIGH 8.1
Apache Camel — Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component.
The camel-hazelcast comp…
2026-07-06
CVE-2026-43866
HIGH 7.3
Apache Camel — Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component.
JmsBinding.extra…
2026-07-06
CVE-2026-43867
CRITICAL 9.8
Apache Camel — Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component.
The camel-pqc component persis…
2026-07-06
CVE-2026-46453
MEDIUM 5.3
Apache Camel — Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Elas…
2026-07-06
CVE-2026-46454
CRITICAL 9.8
Apache Camel — Improper Input Validation vulnerability in Apache Camel Cometd Component.
The camel-cometd component maps inb…
2026-07-06
CVE-2026-46455
CRITICAL 9.8
Apache Camel — Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component.
The camel-keycloak security…
2026-07-06
CVE-2026-46456
CRITICAL 9.8
Apache Camel — Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component.
The camel-aws2-sqs component map…
2026-07-06
CVE-2026-46457
HIGH 7.5
Apache Camel — Improper Input Validation vulnerability in Apache Camel NATS component.
The camel-nats component maps inbound…
2026-07-06
CVE-2026-46584
LOW 3.7
Apache Camel Mail — Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache …
2026-07-06
CVE-2026-46585
HIGH 7.5
Apache Camel Lucene — Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Luce…
2026-07-06
CVE-2026-46587
HIGH 7.3
Apache Camel — Improper Input Validation vulnerability in Apache Camel.
This issue affects Apache Camel: through 4.14.7, fro…
2026-07-06
CVE-2026-46588
HIGH 7.3
Apache Camel — Improper Input Validation vulnerability in Apache Camel.
This issue affects Apache Camel: through 4.14.7, fro…
2026-07-06
CVE-2026-46590
HIGH 8.8
Apache Camel — Deserialization of Untrusted Data vulnerability in Apache Camel PQC component.
The camel-pqc component persis…
2026-07-06
CVE-2026-46591
HIGH 8.2
Apache Camel — Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component.…
2026-07-06
CVE-2026-46592
HIGH 7.5
Apache Camel — Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel …
2026-07-06
CVE-2026-46726
HIGH 7.5
Apache Camel Vertx Websocket — Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request For…
2026-07-06
CVE-2026-48203
CRITICAL 9.1
Apache Camel — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper I…
2026-07-06
CVE-2026-48204
CRITICAL 9.8
Apache Camel — Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs compo…
2026-07-06
CVE-2026-48205
CRITICAL 9.1
Apache Camel Dns — Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component.
Th…
2026-07-06
CVE-2026-48206
MEDIUM 5.3
Apache Camel Jira — Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel JIRA…
2026-07-06
CVE-2026-49042
HIGH 7.3
Apache Camel — Improper Input Validation vulnerability in Apache Camel.
This issue affects Apache Camel: from 4.8.0 through …
2026-07-06
CVE-2026-49086
MEDIUM 6.5
Apache Camel Dapr — Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel …
2026-07-06
CVE-2026-49097
MEDIUM 6.5
Apache Camel — Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Componen…
2026-07-06
CVE-2026-49098
MEDIUM 5.3
Apache Camel — Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Componen…
2026-07-06
CVE-2026-49099
MEDIUM 5.3
Apache Camel Salesforce — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorizat…
2026-07-06
CVE-2026-49297
HIGH 8.1
Apache Airflow Google Provider — Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined G…
2026-07-06
CVE-2026-49365
MEDIUM 5.3
Apache Camel — Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Netty HTTP componen…
2026-07-06
CVE-2026-53913
CRITICAL 9.8
Apache Camel Keycloak — Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') v…
2026-07-06
CVE-2026-55993
HIGH 7.5
Apache Camel Atmosphere Websocket — Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request For…
2026-07-06
CVE-2026-55994
HIGH 7.5
Apache Camel Iggy — Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request For…
2026-07-06
CVE-2026-56139
MEDIUM 5.3
Apache Camel Undertow — Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Undertow Component.…
2026-07-06
CVE-2026-56140
CRITICAL 9.8
Apache Camel Aws2 Sns — Improper Input Validation vulnerability in Apache Camel AWS SNS component.
The camel-aws2-sns component filt…
2026-07-06
CVE-2026-47896
HIGH 8.9
Apache Lucene.Net — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.…
2026-07-03
CVE-2026-47897
HIGH 8.9
Apache Lucene.Net — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.…
2026-07-03
CVE-2026-47898
MEDIUM 4
Apache Lucene.Net — Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.…
2026-07-03
CVE-2026-54399
HIGH 7.5
Apache Httpcomponents Core — Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (…
2026-07-01
CVE-2026-54428
HIGH 7.5
Apache Httpcomponents Core — Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core…
2026-07-01
CVE-2026-49432
HIGH 7.5
Apache Activemq — Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp.
A rem…
2026-06-30
CVE-2026-49434
HIGH 7.5
Apache Activemq Broker — Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
An a…
2026-06-30
CVE-2026-49877
HIGH 8.1
Apache Activemq — Improper Authorization vulnerability in Apache ActiveMQ.
An authenticated low-privilege Web Console user by d…
2026-06-30
CVE-2026-50734
HIGH 7.5
Apache Activemq Client — Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache A…
2026-06-30
CVE-2026-50750
HIGH 7.5
Apache Activemq Broker — Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ …
2026-06-30
CVE-2026-52760
MEDIUM 6.1
Apache Activemq — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache A…
2026-06-30
CVE-2026-53916
HIGH 7.5
Apache Activemq — Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache Acti…
2026-06-30
CVE-2026-53917
HIGH 7.5
Apache Activemq — Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache Acti…
2026-06-30
CVE-2026-54475
HIGH 7.5
Apache Activemq Broker — Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.
Apache A…
2026-06-30
CVE-2025-53648
MEDIUM 5.4
Apache Gravitino — SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or t…
2026-06-30
CVE-2026-50229
MEDIUM 6.1
Apache Tomcat — Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number gues…● PoC
2026-06-29
CVE-2026-53404
HIGH 7.3
Apache Tomcat — Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the …
2026-06-29
CVE-2026-53434
CRITICAL 9.1
Apache Tomcat — Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM bas…
2026-06-29
CVE-2026-55276
CRITICAL 9.1
Apache Tomcat — Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty…
2026-06-29
CVE-2026-55955
MEDIUM 6.5
Apache Tomcat — Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionIntercept…
2026-06-29
CVE-2026-55956
MEDIUM 6.5
Apache Tomcat — Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default …
2026-06-29
CVE-2026-55957
HIGH 7.3
Apache Tomcat — Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to au…
2026-06-29
CVE-2026-49486
HIGH 7.5
Apache Airflow Ftp Provider — The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never calle…
2026-06-26
CVE-2026-44911
LOW 2.3
Apache Nifi — Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 a…
2026-06-22
CVE-2026-44913
MEDIUM 5.2
Apache Nifi — Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 …
2026-06-22
CVE-2026-44914
HIGH 7.5
Apache Nifi — Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extensio…
2026-06-22
CVE-2026-54665
MEDIUM 6.3
Apache Nifi — Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that …
2026-06-22
CVE-2025-62198
MEDIUM 5.4
Apache Atlas — An authenticated user can perform XSS.
This issue affects Apache Atlas versions 2.4.0 and earlier.
Users are…
2026-06-22
CVE-2025-66336
HIGH 8.1
Apache Doris Mcp Server — Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled dat…
2026-06-22
CVE-2026-39998
MEDIUM 5.8
Apache Apisix — Improper Input Validation vulnerability in Apache APISIX.
The attacker can take advantage of certain configur…
2026-06-19
CVE-2026-39999
HIGH 7
Apache Apisix — Authentication Bypass by Spoofing vulnerability in Apache APISIX.
The attacker can completely bypass authenti…
2026-06-19
CVE-2026-44046
LOW 2.3
Apache Apisix — Use of Less Trusted Source vulnerability in Apache APISIX.
Attacker can take advantage of wolf-rbac plugin un…
2026-06-19
CVE-2026-44087
MEDIUM 5.3
Apache Apisix — Insufficient Verification of Data Authenticity vulnerability in Apache APISIX.
The openid-connect plugin unde…
2026-06-19
CVE-2026-44915
LOW 2.1
Apache Apisix — URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX.
The default configuration…
2026-06-19
CVE-2026-47339
MEDIUM 5.3
Apache Apisix — Incorrect Authorization vulnerability in Apache APISIX.
An attacker can capitalise on authz-casdoor plugin un…
2026-06-19
CVE-2026-47341
MEDIUM 6.3
Apache Apisix — Authentication Bypass by Capture-replay vulnerability in Apache APISIX.
Attacker can benefit from certain con…
2026-06-19
CVE-2026-48895
LOW 2.1
Apache Apisix — URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX.
The attacker could manipu…
2026-06-19
CVE-2026-49230
MEDIUM 6.3
Apache Apisix — Improper Validation of Integrity Check Value vulnerability in Apache APISIX.
The jwe-decrypt plugin under def…
2026-06-19
CVE-2026-49231
LOW 2.3
Apache Apisix — Authentication Bypass by Spoofing vulnerability in opa plugin.
An attacker could relay spoofed identity heade…
2026-06-19
CVE-2026-49871
LOW 2.1
Apache Apisix — Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations.
This def…
2026-06-19
CVE-2026-49872
MEDIUM 5.3
Apache Apisix — Improper Authentication vulnerability in Apache APISIX.
When the cas-auth plugin is used in a route, an attac…
2026-06-19
CVE-2026-32966
HIGH 7.5
Apache Dolphinscheduler — DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache Dolphi…
2026-06-17
CVE-2026-32967
MEDIUM 6.5
Apache Dolphinscheduler — Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler.
This issue …
2026-06-17
CVE-2026-41280
MEDIUM 4.9
Apache Dolphinscheduler — Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in …
2026-06-17
CVE-2026-42357
MEDIUM 6.5
Apache Dolphinscheduler — Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projec…
2026-06-17
CVE-2026-47340
MEDIUM 6.5
Apache Dolphinscheduler — Allow authenticated users to access alert instances associated with alert groups they do not have permission t…
2026-06-17
CVE-2026-49268
HIGH 8.8
Apache Shiro — A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultL…
2026-06-17
CVE-2026-50203
CRITICAL 9.1
Apache Airflow Sftp Provider — A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a ma…
2026-06-17
CVE-2026-49875
MEDIUM 6.5
Apache Cxf — Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the…
2026-06-12
CVE-2026-50623
MEDIUM 4.8
Apache Cxf — An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a …
2026-06-12
CVE-2026-50627
CRITICAL 9.1
Apache Cxf — The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT …
2026-06-12
CVE-2026-50628
CRITICAL 9.8
Apache Cxf — A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while b…
2026-06-12
CVE-2026-50629
MEDIUM 5.3
Apache Cxf — The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning m…
2026-06-12
CVE-2026-50630
MEDIUM 6.5
Apache Cxf — A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authen…
2026-06-12
CVE-2026-50631
HIGH 7.4
Apache Cxf — A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypas…
2026-06-12
CVE-2026-50632
HIGH 8.1
Apache Cxf — A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) …
2026-06-12
CVE-2026-50633
HIGH 8.1
Apache Cxf — A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for…
2026-06-12
CVE-2026-50634
MEDIUM 6.5
Apache Cxf — A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadat…
2026-06-12
CVE-2026-50645
HIGH 7.5
Apache Cxf — There is no restriction on the amount of attachment headers that a message can contain when being deserialized…
2026-06-12
CVE-2026-25700
HIGH 7.2
Apache Answer — Improper Restriction of Security Token Assignment vulnerability in Apache Answer.
This issue affects Apache A…
2026-06-10
CVE-2026-47342
HIGH 8.8
Apache Ofbiz — A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain high…
2026-06-10
CVE-2026-50223
HIGH 8.8
Apache Ofbiz — Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privilege…
2026-06-10
CVE-2026-25688
MEDIUM 6.1
Apache Answer — Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer.
This issue affects Apache Ans…
2026-06-09
CVE-2026-25699
MEDIUM 6.1
Apache Answer — Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue …
2026-06-09
CVE-2026-33582
MEDIUM 6.5
Apache Answer — Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
This issue affects Apache Ans…
2026-06-09
CVE-2026-34031
MEDIUM 6.5
Apache Answer — Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
This issue affects Apache Ans…
2026-06-09
CVE-2026-34033
MEDIUM 5.4
Apache Answer — Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer.
…
2026-06-09
CVE-2026-34905
MEDIUM 6.5
Apache Answer — Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects…
2026-06-09
CVE-2026-49818
MEDIUM 6.5
Apache Airflow Samba Provider — The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path w…
2026-06-09
CVE-2026-29167
CRITICAL 9.8
Apache Http Server — Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration
This issue af…
2026-06-08
CVE-2026-29170
MEDIUM 6.1
Apache Http Server — A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP S…
2026-06-08
CVE-2026-34355
HIGH 7.5
Apache Http Server — A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted …
2026-06-08
CVE-2026-34356
HIGH 7.5
Apache Http Server — Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassRev…
2026-06-08
CVE-2026-42535
CRITICAL 9.1
Apache Http Server — A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly ma…
2026-06-08
CVE-2026-42536
HIGH 7.5
Apache Http Server — Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted…
2026-06-08
CVE-2026-43951
MEDIUM 6.5
Apache Http Server — Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response lan…
2026-06-08
CVE-2026-44119
MEDIUM 5.5
Apache Http Server — Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess au…
2026-06-08
CVE-2026-44185
HIGH 7.3
Apache Http Server — Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP…
2026-06-08
CVE-2026-44186
HIGH 7.3
Apache Http Server — Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTT…
2026-06-08
CVE-2026-44631
CRITICAL 9.8
Apache Http Server — Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.
Th…
2026-06-08
CVE-2026-47430
CRITICAL 9.5
Cordova Plugin Inappbrowser — ## Summary
The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMess…
2026-06-08
CVE-2026-48913
HIGH 7.3
Apache Http Server — Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.
…
2026-06-08
CVE-2026-49975
HIGH 7.5
Apache Http Server — Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of …● PoC
2026-06-08