CVE Datenbank

Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.

Zurücksetzen
281 CVEs gefunden (Seite 1/2)

CVE-2026-60363 - Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Apache Plugi

🏢 Oracle 📅 21.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-60080 - Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Ap

🏢 Apache 📅 21.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-64606 - Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypas

🏢 Apache 📅 21.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-64609 - Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is

🏢 Apache 📅 21.7.2026 📊 CVSS: 9.1
9.1

CVE-2026-64608 - Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deseria

🏢 Apache 📅 21.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-58624 - Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for cl

🏢 Apache 📅 20.7.2026 📊 CVSS: 5.4
5.4

CVE-2026-56624 - Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java librar

🏢 Apache 📅 20.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-56623 - Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library

🏢 Apache 📅 20.7.2026 📊 CVSS: 7.1
7.1

CVE-2026-56452 - Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for

🏢 Apache 📅 20.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-53593 - FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version

🏢 Apache 📅 20.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-63071 - Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with a

🏢 Apache 📅 20.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-62418 - Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via

🏢 Apache 📅 20.7.2026 📊 CVSS: 8.1
8.1

CVE-2026-62183 - Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow

🏢 Apache 📅 20.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-57308 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i

🏢 Apache 📅 20.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-53421 - Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with

🏢 Apache 📅 20.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-53405 - Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with a

🏢 Apache 📅 20.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-59173 - Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache

🏢 Apache 📅 18.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-62764 - Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but

🏢 Apache 📅 17.7.2026 📊 CVSS: 6.5
6.5

CVE-2026-44182 - Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like

🏢 Apache 📅 16.7.2026 📊 CVSS: 10.0
10.0

CVE-2026-44181 - Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like

🏢 Apache 📅 16.7.2026 📊 CVSS: 10.0
10.0

CVE-2026-44180 - Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like

🏢 Apache 📅 16.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-33692 - WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenti

🏢 Apache 📅 16.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-26032 - The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a

🏢 Apache 📅 15.7.2026 📊 CVSS: 5.4
5.4

CVE-2026-57821 - A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in

🏢 Apache 📅 15.7.2026 📊 CVSS: 8.1
8.1

CVE-2026-56287 - A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/

🏢 Apache 📅 15.7.2026 📊 CVSS: 8.1
8.1

CVE-2026-35152 - A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint)

🏢 Apache 📅 15.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-62393 - Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper

🏢 Apache 📅 14.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-62392 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi

🏢 Apache 📅 14.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-62390 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i

🏢 Apache 📅 14.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-49488 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac

🏢 Apache 📅 14.7.2026 📊 CVSS: 6.5
6.5

CVE-2026-58319 - Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication.

🏢 Apache 📅 14.7.2026 📊 CVSS: 9.1
9.1

CVE-2026-59084 - Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to secure

🏢 Apache 📅 14.7.2026 📊 CVSS: 9.1
9.1

CVE-2026-59083 - Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allo

🏢 Apache 📅 14.7.2026 📊 CVSS: 9.1
9.1

CVE-2026-49972 - Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attac

🏢 Apache 📅 13.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-59245 - In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-

🏢 Apache 📅 13.7.2026 📊 CVSS: 8.1
8.1

CVE-2026-58065 - The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by

🏢 Apache 📅 13.7.2026 📊 CVSS: 8.1
8.1

CVE-2026-49876 - Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and

🏢 Apache 📅 13.7.2026 📊 CVSS: 6.5
6.5

CVE-2026-41041 - URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This

🏢 Apache 📅 13.7.2026 📊 CVSS: 9.1
9.1

CVE-2026-52761 - ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS

🏢 Apache 📅 10.7.2026 📊 CVSS: 5.8
5.8

CVE-2026-52747 - ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS

🏢 Apache 📅 10.7.2026 📊 CVSS: 8.6
8.6

CVE-2026-49844 - Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache

🏢 Apache 📅 10.7.2026 📊 CVSS: 5.9
5.9

CVE-2026-40454 - Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bound

🏢 Apache 📅 10.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-40452 - Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass

🏢 Apache 📅 10.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-40009 - Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated

🏢 Apache 📅 10.7.2026 📊 CVSS: 6.5
6.5

CVE-2026-40008 - Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in

🏢 Apache 📅 10.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-40007 - Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB. When pipe_a

🏢 Apache 📅 10.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-40006 - Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, M

🏢 Apache 📅 10.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-40005 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac

🏢 Apache 📅 10.7.2026 📊 CVSS: 9.1
9.1

CVE-2026-28564 - Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoT

🏢 Apache 📅 10.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-57111 - Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.s

🏢 Apache 📅 9.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-41042 - Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which exe

🏢 Apache 📅 8.7.2026 📊 CVSS: 9.1
9.1

CVE-2026-23698 - Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin

🏢 Apache 📅 7.7.2026 📊 CVSS: 7.2
7.2

CVE-2026-23697 - Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileg

🏢 Apache 📅 7.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-49487 - In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a defe

🏢 Apache 📅 7.7.2026 📊 CVSS: 6.5
6.5

CVE-2026-49296 - Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Da

🏢 Apache 📅 7.7.2026 📊 CVSS: 6.5
6.5

CVE-2026-48892 - The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables l

🏢 Apache 📅 7.7.2026 📊 CVSS: 6.5
6.5

CVE-2026-48891 - A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable

🏢 Apache 📅 7.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-48828 - The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so

🏢 Apache 📅 7.7.2026 📊 CVSS: 6.5
6.5

CVE-2026-33264 - A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-contro

🏢 Apache 📅 7.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-53646 - FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0

🏢 Cloudflare 📅 6.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-43825 - Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected:   before 3.0.0-M

🏢 Apache 📅 6.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-49297 - Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator

🏢 Google 📅 6.7.2026 📊 CVSS: 8.1
8.1

CVE-2026-49042 - Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: from 4.8.

🏢 Apache 📅 6.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-46588 - Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4

🏢 Apache 📅 6.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-46587 - Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4

🏢 Apache 📅 6.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-56140 - Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns comp

🏢 Aws 📅 6.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-56139 - Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Undertow

🏢 Apache 📅 6.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-55994 - Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side R

🏢 Apache 📅 6.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-55993 - Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side R

🏢 Apache 📅 6.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-53913 - Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failin

🏢 Apache 📅 6.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-49365 - Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Netty HTT

🏢 Apache 📅 6.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-49099 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'),

🏢 Apache 📅 6.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-49098 - Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstrea

🏢 Apache 📅 6.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-49097 - Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstrea

🏢 Apache 📅 6.7.2026 📊 CVSS: 6.5
6.5

CVE-2026-49086 - Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apa

🏢 Apache 📅 6.7.2026 📊 CVSS: 6.5
6.5

CVE-2026-48206 - Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache

🏢 Apache 📅 6.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-48205 - Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS comp

🏢 Apache 📅 6.7.2026 📊 CVSS: 9.1
9.1

CVE-2026-48204 - Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gr

🏢 Apache 📅 6.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-48203 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'),

🏢 Apache 📅 6.7.2026 📊 CVSS: 9.1
9.1

CVE-2026-46726 - Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side R

🏢 Apache 📅 6.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-46592 - Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apa

🏢 Apache 📅 6.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-46591 - Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J

🏢 Apache 📅 6.7.2026 📊 CVSS: 8.2
8.2

CVE-2026-46590 - Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc compon

🏢 Aws 📅 6.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-46585 - Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache

🏢 Apache 📅 6.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-46584 - Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor vulnerability

🏢 Apache 📅 6.7.2026 📊 CVSS: 3.7
3.7

CVE-2026-46457 - Improper Input Validation vulnerability in Apache Camel NATS component. The camel-nats component ma

🏢 Apache 📅 6.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-46456 - Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs com

🏢 Aws 📅 6.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-46455 - Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloa

🏢 Apache 📅 6.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-46454 - Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd componen

🏢 Apache 📅 6.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-46453 - Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache

🏢 Elastic 📅 6.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-43867 - Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc compon

🏢 Aws 📅 6.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-43866 - Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. JmsBin

🏢 Apache 📅 6.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-43865 - Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-haze

🏢 Apache 📅 6.7.2026 📊 CVSS: 8.1
8.1

CVE-2026-42527 - Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter patt

🏢 Apache 📅 6.7.2026 📊 CVSS: 8.1
8.1

CVE-2026-40859 - Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component des

🏢 Apache 📅 6.7.2026 📊 CVSS: 8.1
8.1

CVE-2026-40047 - Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in

🏢 Apache 📅 6.7.2026 📊 CVSS: 9.1
9.1

CVE-2026-24014 - Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trig

🏢 Apache 📅 6.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-24013 - Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers l

🏢 Apache 📅 6.7.2026 📊 CVSS: 9.1
9.1

CVE-2026-24012 - Uncontrolled Resource Consumption vulnerability in Apache IoTDB.  Some interface fails to impose re

🏢 Apache 📅 6.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-47896 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac

🏢 Apache 📅 3.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-47898 - Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net

🏢 Apache 📅 3.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-47897 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac

🏢 Apache 📅 3.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-54428 - Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpCompo

🏢 Apache 📅 1.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-54399 - Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpCompone

🏢 Apache 📅 1.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-55223 - c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with ot

🏢 Apache 📅 30.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-54475 - Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.

🏢 Apache 📅 30.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-53917 - Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, A

🏢 Apache 📅 30.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-53916 - Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, A

🏢 Apache 📅 30.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-52760 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i

🏢 Apache 📅 30.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-50750 - Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache

🏢 Apache 📅 30.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-50734 - Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ

🏢 Apache 📅 30.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-49877 - Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console

🏢 Apache 📅 30.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-49434 - Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ

🏢 Apache 📅 30.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-49432 - Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Sto

🏢 Apache 📅 30.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-55957 - Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was config

🏢 Apache 📅 29.6.2026 📊 CVSS: 7.3
7.3

CVE-2026-55956 - Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for th

🏢 Apache 📅 29.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-55955 - Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the Encryptio

🏢 Apache 📅 29.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-55276 - Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles

🏢 Apache 📅 29.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-53434 - Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for

🏢 Apache 📅 29.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-53404 - Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant th

🏢 Apache 📅 29.6.2026 📊 CVSS: 7.3
7.3

CVE-2026-50229 - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the n

🏢 Apache 📅 29.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-57915 - It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA

🏢 Apache 📅 26.6.2026 📊 CVSS: 7.3
7.3

CVE-2025-64152 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac

🏢 Apache 📅 26.6.2026 📊 CVSS: 9.1
9.1

CVE-2025-55017 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac

🏢 Apache 📅 26.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-57914 - By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trig

🏢 Apache 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-49486 - The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but n

🏢 Apache 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-48946 - The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's

🏢 Apache 📅 25.6.2026 📊 CVSS: 6.3
6.3

CVE-2026-56130 - "Remember me" cookie age is not verified on the server. This potentially allows an attacker to inter

🏢 Apache 📅 25.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-56091 - When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted HT

🏢 Apache 📅 25.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-54226 - A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.6.0 through 2.15.0. U

🏢 Apache 📅 25.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-46752 - Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache

🏢 Apache 📅 25.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-46751 - A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.2.0 through 2.15.0. U

🏢 Apache 📅 25.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-45188 - Relative Path Traversal vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.

🏢 Apache 📅 25.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-41566 - Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. This i

🏢 Apache 📅 25.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-54665 - Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request hea

🏢 Apache 📅 22.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-44914 - Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that includ

🏢 Apache 📅 22.6.2026 📊 CVSS: 7.2
7.2

CVE-2026-44913 - Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache N

🏢 Apache 📅 22.6.2026 📊 CVSS: 7.2
7.2

CVE-2026-44911 - Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 throu

🏢 Apache 📅 22.6.2026 📊 CVSS: 6.3
6.3

CVE-2025-66336 - Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-cont

🏢 Apache 📅 22.6.2026 📊 CVSS: 8.1
8.1

CVE-2025-62198 - An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier.

🏢 Apache 📅 22.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-49872 - Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route

🏢 Apache 📅 19.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-49871 - Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations.

🏢 Apache 📅 19.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-49231 - Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed iden

🏢 Apache 📅 19.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-49230 - Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin

🏢 Apache 📅 19.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-48895 - URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker co

🏢 Apache 📅 19.6.2026 📊 CVSS: 7.2
7.2

CVE-2026-47341 - Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from c

🏢 Apache 📅 19.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-47339 - Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor

🏢 Apache 📅 19.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-44915 - URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default con

🏢 Apache 📅 19.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-44087 - Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect p

🏢 Apache 📅 19.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-44046 - Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac

🏢 Apache 📅 19.6.2026 📊 CVSS: 5.8
5.8

CVE-2026-39999 - Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypas

🏢 Apache 📅 19.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-39998 - Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certai

🏢 Apache 📅 19.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-49257 - mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. I

🏢 Apache 📅 18.6.2026 📊 CVSS: 10.0
10.0

CVE-2026-49268 - A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction i

🏢 Apache 📅 17.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-50203 - A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`

🏢 Apache 📅 17.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-47340 - Allow authenticated users to access alert instances associated with alert groups they do not have pe

🏢 Apache 📅 17.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-42357 - Incorrect Authorization vulnerability allows users to access workflow instance information belonging

🏢 Apache 📅 17.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-41280 - Incorrect Authorization vulnerability allows users with system login privileges to delete task defin

🏢 Apache 📅 17.6.2026 📊 CVSS: 4.9
4.9

CVE-2026-32967 - Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. T

🏢 Apache 📅 17.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-32966 - DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apa

🏢 Apache 📅 17.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-50645 - There is no restriction on the amount of attachment headers that a message can contain when being de

🏢 Apache 📅 12.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-50634 - A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to proce

🏢 Apache 📅 12.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-50633 - A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can

🏢 Apache 📅 12.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-50632 - A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lea

🏢 Apache 📅 12.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-50627 - The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of inc

🏢 Apache 📅 12.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-50623 - An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF.

🏢 Apache 📅 12.6.2026 📊 CVSS: 4.8
4.8

CVE-2026-49875 - Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory w

🏢 Apache 📅 12.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-41000 - Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestDa

🏢 Apache 📅 11.6.2026 📊 CVSS: 3.7
3.7

CVE-2026-40996 - Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J'

🏢 Apache 📅 11.6.2026 📊 CVSS: 4.8
4.8

CVE-2026-50223 - Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low

🏢 Apache 📅 10.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-47342 - A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to o

🏢 Apache 📅 10.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-45569 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8

🏢 Apache 📅 10.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-45567 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8

🏢 Apache 📅 10.6.2026 📊 CVSS: 8.3
8.3

CVE-2026-45566 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8

🏢 Apache 📅 10.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-45565 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8

🏢 Apache 📅 10.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-25700 - Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affect

🏢 Apache 📅 10.6.2026 📊 CVSS: 7.2
7.2

CVE-2026-45564 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8

🏢 Apache 📅 10.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-45563 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8

🏢 Apache 📅 10.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-45561 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8

🏢 Apache 📅 10.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-45560 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8

🏢 Apache 📅 10.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-45559 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8

🏢 Apache 📅 10.6.2026 📊 CVSS: 4.9
4.9

CVE-2026-45558 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8

🏢 Apache 📅 10.6.2026 📊 CVSS: 9.9
9.9

CVE-2026-45556 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8

🏢 Apache 📅 10.6.2026 📊 CVSS: 9.9
9.9

CVE-2026-45552 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8

🏢 Apache 📅 10.6.2026 📊 CVSS: 9.9
9.9

CVE-2026-45550 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8

🏢 Apache 📅 10.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-45549 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8

🏢 Apache 📅 10.6.2026 📊 CVSS: 8.5
8.5

CVE-2026-41732 - JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning t

🏢 Apache 📅 10.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-41731 - JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trust

🏢 Apache 📅 10.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-41727 - Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header value

🏢 Apache 📅 10.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-41726 - When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap withou

🏢 Apache 📅 10.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-49818 - The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destinat

🏢 Apache 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-34905 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This iss

🏢 Apache 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-34033 - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apach

🏢 Apache 📅 9.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-34031 - Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects

🏢 Apache 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-33582 - Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects

🏢 Apache 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-25699 - Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. T

🏢 Apache 📅 9.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-25688 - Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects

🏢 Apache 📅 9.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-49975 - Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to

🏢 Apache 📅 8.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-48913 - Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already ex

🏢 Apache 📅 8.6.2026 📊 CVSS: 7.3
7.3

CVE-2026-44631 - Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configur

🏢 Apache 📅 8.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-44186 - Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in

🏢 Apache 📅 8.6.2026 📊 CVSS: 7.3
7.3

CVE-2026-44185 - Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker contr

🏢 Apache 📅 8.6.2026 📊 CVSS: 7.3
7.3

CVE-2026-44119 - Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .h

🏢 Apache 📅 8.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-43951 - Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple re

🏢 Apache 📅 8.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-42536 - Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and

🏢 Apache 📅 8.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-42535 - A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to d

🏢 Apache 📅 8.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-34356 - Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and Pr

🏢 Apache 📅 8.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-34355 - A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an

🏢 Apache 📅 8.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-29170 - A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apa

🏢 Apache 📅 8.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-29167 - Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration Thi

🏢 Apache 📅 8.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-50076 - Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK

🏢 Apache 📅 4.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-43926 - FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the

🏢 Cloudflare 📅 4.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-45080 - Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4

🏢 Apache 📅 2.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-44367 - Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4

🏢 Apache 📅 2.6.2026 📊 CVSS: 2.7
2.7

CVE-2026-46718 - Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in

🏢 Apache 📅 2.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-41115 - An improper authorization vulnerability has been identified in Apache Kafka. The implementation of

🏢 Apache 📅 2.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-49328 - Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) f

🏢 Apache 📅 1.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-49361 - Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.M

🏢 Apache 📅 1.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-49298 - A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate a

🏢 Apache 📅 1.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-49270 - Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache A

🏢 Apache 📅 1.6.2026 📊 CVSS: 5.9
5.9

CVE-2026-49267 - Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STA

🏢 Apache 📅 1.6.2026 📊 CVSS: 5.9
5.9

CVE-2026-49157 - Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ:

🏢 Apache 📅 1.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-48827 - Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upl

🏢 Apache 📅 1.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-48726 - A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after

🏢 Apache 📅 1.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-46764 - The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched audit

🏢 Apache 📅 1.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-46605 - Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authent

🏢 Apache 📅 1.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-45505 - Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i

🏢 Apache 📅 1.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-45426 - Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log

🏢 Apache 📅 1.6.2026 📊 CVSS: 3.1
3.1

CVE-2026-45360 - Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_r

🏢 Apache 📅 1.6.2026 📊 CVSS: 7.3
7.3

CVE-2026-44825 - Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr v

🏢 Apache 📅 1.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-42588 - Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i

🏢 Apache 📅 1.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-42360 - A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g.

🏢 Apache 📅 1.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-42359 - A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authentic

🏢 Apache 📅 1.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-42358 - A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-

🏢 Apache 📅 1.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-42253 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i

🏢 Apache 📅 1.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-42252 - Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when tr

🏢 Apache 📅 1.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-41084 - A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_

🏢 Apache 📅 1.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-41017 - Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deploy

🏢 Apache 📅 1.6.2026 📊 CVSS: 5.9
5.9

CVE-2026-41014 - The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not p

🏢 Apache 📅 1.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-40963 - The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Da

🏢 Apache 📅 1.6.2026 📊 CVSS: 3.1
3.1

CVE-2026-40961 - A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that b

🏢 Apache 📅 1.6.2026 📊 CVSS: 7.2
7.2

CVE-2026-40861 - A Dag author could either (a) create a symlink under their task's log directory pointing to an arbit

🏢 Apache 📅 1.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-45192 - A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed a

🏢 Apache 📅 1.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-48557 - Spatie Laravel Media Library before version 11.23.0 contains a file upload restriction bypass in Fil

🏢 Apache 📅 29.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-40914 - A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with securi

🏢 Apache 📅 28.5.2026 📊 CVSS: 4.3
4.3

CVE-2025-48977 - Relative Path Traversal vulnerability in Apache Ignite REST API. Authenticated REST API users can r

🏢 Apache 📅 28.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-44966 - Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earl

🏢 Apache 📅 26.5.2026 📊 CVSS: 8.3
8.3

CVE-2026-40564 - Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerabilit

🏢 Apache 📅 26.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-48589 - Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect aft

🏢 Apache 📅 25.5.2026 📊 CVSS: 5.4
5.4

CVE-2026-44598 - With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Reque

🏢 Apache 📅 25.5.2026 📊 CVSS: 5.4
5.4
Seite 1 von 2 Weiter » »»

🏢 CVE nach Hersteller

Empfohlene Sicherheitstools

Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.