CVE Datenbank

Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.

Zurücksetzen
33 CVEs gefunden (Seite 1/1)

CVE-2026-44966 - Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earl

🏢 Apache 📅 26.5.2026 📊 CVSS: 8.3
8.3

CVE-2026-40564 - Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerabilit

🏢 Apache 📅 26.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-48589 - Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect aft

🏢 Apache 📅 25.5.2026 📊 CVSS: 5.4
5.4

CVE-2026-44598 - With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Reque

🏢 Apache 📅 25.5.2026 📊 CVSS: 5.4
5.4

CVE-2026-43828 - Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attr

🏢 Apache 📅 25.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-43827 - Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Ap

🏢 Apache 📅 25.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-42797 - Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administ

🏢 Apache 📅 25.5.2026 📊 CVSS: 4.9
4.9

CVE-2026-42782 - Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with a

🏢 Apache 📅 25.5.2026 📊 CVSS: 7.2
7.2

CVE-2026-46745 - Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows

🏢 Apache 📅 25.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-45249 - A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rend

🏢 Apache 📅 25.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-44930 - An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF

🏢 Apache 📅 22.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-44618 - Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform

🏢 Apache 📅 22.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-44417 - The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete

🏢 Apache 📅 22.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-48207 - Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass docu

🏢 Apache 📅 21.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-45760 - (Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through Use

🏢 Apache 📅 21.5.2026 📊 CVSS: 8.1
8.1

CVE-2026-47323 - Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knat

🏢 Apache 📅 19.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-46586 - Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in

🏢 Apache 📅 19.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-45434 - Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remo

🏢 Apache 📅 19.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-45187 - Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: bef

🏢 Apache 📅 19.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-41919 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability i

🏢 Apache 📅 19.5.2026 📊 CVSS: 9.1
9.1

CVE-2026-35086 - Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache

🏢 Apache 📅 19.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-31986 - Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz:

🏢 Apache 📅 19.5.2026 📊 CVSS: 9.1
9.1

CVE-2026-31910 - Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz:

🏢 Apache 📅 19.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-31909 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issu

🏢 Apache 📅 19.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-31906 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i

🏢 Apache 📅 19.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-31388 - Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affec

🏢 Apache 📅 19.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-31387 - Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.0

🏢 Apache 📅 19.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-31380 - Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression La

🏢 Apache 📅 19.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-31379 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limit

🏢 Apache 📅 19.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-31378 - Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24

🏢 Apache 📅 19.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-29226 - Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations.

🏢 Apache 📅 19.5.2026 📊 CVSS: 7.3
7.3

CVE-2026-29220 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac

🏢 Apache 📅 19.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-29207 - Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz.

🏢 Apache 📅 19.5.2026 📊 CVSS: 6.5
6.5

🏢 CVE nach Hersteller

Empfohlene Sicherheitstools

Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.