CVE Datenbank

Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.

Zurücksetzen
196 CVEs gefunden (Seite 1/1)

CVE-2026-45205 - Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration

🏢 Apache 📅 14.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-42268 - ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS

🏢 Apache 📅 12.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-43515 - Improper Authorization vulnerability when multiple method constraints define an HTTP method for the

🏢 Apache 📅 12.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-43514 - Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue

🏢 Apache 📅 12.5.2026 📊 CVSS: 3.7
3.7

CVE-2026-43513 - Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue af

🏢 Apache 📅 12.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-43512 - DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. T

🏢 Apache 📅 12.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-42498 - Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerabi

🏢 Apache 📅 12.5.2026 📊 CVSS: 7.3
7.3

CVE-2026-41293 - Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11

🏢 Apache 📅 12.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-41284 - Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue aff

🏢 Apache 📅 12.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-43826 - The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for exam

🏢 Apache 📅 11.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-41018 - The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for e

🏢 Elastic 📅 11.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-6722 - In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.

🏢 Apache 📅 10.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-39816 - The optional extension component TinkerpopClientService is missing the Restricted annotation with th

🏢 Apache 📅 8.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-25199 - Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to oth

🏢 Apache 📅 8.5.2026 📊 CVSS: 9.1
9.1

CVE-2026-25077 - Account users are allowed by default to register templates to be downloaded directly to the primary

🏢 Apache 📅 8.5.2026 📊 CVSS: 8.8
8.8

CVE-2025-69233 - Due to multiple time-of-check time-of-use race conditions in the resource count check and increment

🏢 Apache 📅 8.5.2026 📊 CVSS: 6.5
6.5

CVE-2025-66467 - Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access

🏢 Apache 📅 8.5.2026 📊 CVSS: 8.0
8.0

CVE-2013-10075 - Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apac

🏢 Apache 📅 8.5.2026 📊 CVSS: 9.1
9.1

CVE-2026-33844 - Improper input validation in Azure Managed Instance for Apache Cassandra allows an authorized attack

🏢 Azure 📅 7.5.2026 📊 CVSS: 9.0
9.0

CVE-2026-33109 - Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker

🏢 Azure 📅 7.5.2026 📊 CVSS: 9.9
9.9

CVE-2026-42241 - ParquetSharp is a .NET library for reading and writing Apache Parquet files. From version 18.1.0 to

🏢 Apache 📅 7.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-41930 - Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-a

🏢 Apache 📅 6.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-5081 - Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are inse

🏢 Apache 📅 6.5.2026 📊 CVSS: 9.1
9.1

CVE-2026-43975 - FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter

🏢 Apache 📅 6.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-43646 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket. This iss

🏢 Apache 📅 6.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-42509 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i

🏢 Apache 📅 6.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-40010 - Missing invocation of Servlet http web request method changeSessionId after session binding can be e

🏢 Apache 📅 6.5.2026 📊 CVSS: 9.1
9.1

CVE-2026-40075 - OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earl

🏢 Apache 📅 5.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-28780 - Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp co

🏢 Apache 📅 5.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-30923 - ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS

🏢 Apache 📅 5.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-29168 - Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md v

🏢 Apache 📅 5.5.2026 📊 CVSS: 7.3
7.3

CVE-2026-43870 - Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversa

🏢 Apache 📅 5.5.2026 📊 CVSS: 7.3
7.3

CVE-2026-43868 - Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apac

🏢 Apache 📅 5.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-43869 - Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue af

🏢 Apache 📅 5.5.2026 📊 CVSS: 7.3
7.3

CVE-2026-42812 - In Apache Iceberg, the table's metadata files are control files: they tell readers which data files

🏢 Apache 📅 4.5.2026 📊 CVSS: 9.9
9.9

CVE-2026-42811 - In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for o

🏢 Google cloud 📅 4.5.2026 📊 CVSS: 9.9
9.9

CVE-2026-42810 - Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds tem

🏢 Aws 📅 4.5.2026 📊 CVSS: 9.9
9.9

CVE-2026-42809 - Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation

🏢 Apache 📅 4.5.2026 📊 CVSS: 9.9
9.9

CVE-2026-42440 - OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader  Version

🏢 Apache 📅 4.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-42027 - Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Aff

🏢 Apache 📅 4.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-40682 - XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersis

🏢 Apache 📅 4.5.2026 📊 CVSS: 9.1
9.1

CVE-2026-40563 - Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas

🏢 Apache 📅 4.5.2026 📊 CVSS: 8.1
8.1

CVE-2026-33523 - HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compr

🏢 Apache 📅 4.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-33007 - A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows

🏢 Apache 📅 4.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-33006 - A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authe

🏢 Apache 📅 4.5.2026 📊 CVSS: 4.8
4.8

CVE-2026-29169 - A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an att

🏢 Apache 📅 4.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-23918 - Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This iss

🏢 Apache 📅 4.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-34032 - Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affec

🏢 Apache 📅 4.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-33857 - Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apach

🏢 Apache 📅 4.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-34059 - Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: throug

🏢 Apache 📅 4.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-24072 - An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .ht

🏢 Apache 📅 4.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-42779 - The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original is

🏢 Apache 📅 1.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-42778 - The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original is

🏢 Apache 📅 1.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-42404 - Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy referenc

🏢 Apache 📅 1.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-42403 - Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy d

🏢 Apache 📅 1.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-42402 - Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy n

🏢 Apache 📅 1.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-41016 - Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL c

🏢 Apache 📅 30.4.2026 📊 CVSS: 5.9
5.9

CVE-2026-41636 - Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Th

🏢 Apache 📅 28.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-41607 - Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0.

🏢 Apache 📅 28.4.2026 📊 CVSS: 6.5
6.5

CVE-2026-41606 - Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.2

🏢 Apache 📅 28.4.2026 📊 CVSS: 5.3
5.3

CVE-2026-41605 - Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: be

🏢 Apache 📅 28.4.2026 📊 CVSS: 7.3
7.3

CVE-2026-41604 - Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0.

🏢 Apache 📅 28.4.2026 📊 CVSS: 8.2
8.2

CVE-2026-41603 - Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue af

🏢 Apache 📅 28.4.2026 📊 CVSS: 7.4
7.4

CVE-2026-41602 - Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implement

🏢 Apache 📅 28.4.2026 📊 CVSS: 7.5
7.5

CVE-2025-48431 - Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This

🏢 Apache 📅 28.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-41081 - Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in

🏢 Apache 📅 27.4.2026 📊 CVSS: 6.5
6.5

CVE-2026-40557 - Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter

🏢 Apache 📅 27.4.2026 📊 CVSS: 4.8
4.8

CVE-2026-33453 - Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apac

🏢 Apache 📅 27.4.2026 📊 CVSS: 10.0
10.0

CVE-2026-27172 - The ConsulRegistry in the camel-consul component (class org.apache.camel.component.consul.ConsulRegi

🏢 Apache 📅 27.4.2026 📊 CVSS: 8.8
8.8

CVE-2026-41409 - The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname

🏢 Apache 📅 27.4.2026 📊 CVSS: 9.8
9.8

CVE-2026-40858 - The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data r

🏢 Apache 📅 27.4.2026 📊 CVSS: 8.8
8.8

CVE-2026-40022 - When authentication is enabled on the Apache Camel embedded HTTP server or embedded management serve

🏢 Apache 📅 27.4.2026 📊 CVSS: 8.2
8.2

CVE-2026-33454 - The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter s

🏢 Apache 📅 27.4.2026 📊 CVSS: 9.4
9.4

CVE-2026-41635 - Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes

🏢 Apache 📅 27.4.2026 📊 CVSS: 9.8
9.8

CVE-2026-40860 - JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, des

🏢 Apache 📅 27.4.2026 📊 CVSS: 9.8
9.8

CVE-2026-40473 - The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in

🏢 Apache 📅 27.4.2026 📊 CVSS: 8.8
8.8

CVE-2026-40453 - The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant

🏢 Google 📅 27.4.2026 📊 CVSS: 9.9
9.9

CVE-2026-40048 - The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in

🏢 Apache 📅 27.4.2026 📊 CVSS: 7.8
7.8

CVE-2026-39920 - BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administ

🏢 Apache 📅 24.4.2026 📊 CVSS: 9.8
9.8

CVE-2026-23902 - Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with sys

🏢 Apache 📅 24.4.2026 📊 CVSS: 8.1
8.1

CVE-2026-41044 - Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i

🏢 Apache 📅 24.4.2026 📊 CVSS: 8.8
8.8

CVE-2026-41043 - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apach

🏢 Apache 📅 24.4.2026 📊 CVSS: 6.5
6.5

CVE-2026-40466 - Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i

🏢 Apache 📅 24.4.2026 📊 CVSS: 8.8
8.8

CVE-2025-62233 - Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue a

🏢 Apache 📅 24.4.2026 📊 CVSS: 6.3
6.3

CVE-2026-33208 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to vers

🏢 Apache 📅 24.4.2026 📊 CVSS: 8.8
8.8

CVE-2026-33078 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prio

🏢 Apache 📅 24.4.2026 📊 CVSS: 9.8
9.8

CVE-2026-33077 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to vers

🏢 Apache 📅 24.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-33076 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to vers

🏢 Apache 📅 24.4.2026 📊 CVSS: 9.8
9.8

CVE-2026-4132 - The HTTP Headers plugin for WordPress is vulnerable to External Control of File Name or Path leading

🏢 Apache 📅 22.4.2026 📊 CVSS: 7.2
7.2

CVE-2026-2717 - The HTTP Headers plugin for WordPress is vulnerable to CRLF Injection in all versions up to, and inc

🏢 Apache 📅 22.4.2026 📊 CVSS: 5.5
5.5

CVE-2026-40542 - Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the cli

🏢 Apache 📅 22.4.2026 📊 CVSS: 7.3
7.3

CVE-2026-33432 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions u

🏢 Apache 📅 20.4.2026 📊 CVSS: 9.1
9.1

CVE-2026-33431 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to vers

🏢 Apache 📅 20.4.2026 📊 CVSS: 6.5
6.5

CVE-2026-6257 - Vvveb CMS prior to v1.0.8.2 contains a remote code execution vulnerability in its media management f

🏢 Apache 📅 20.4.2026 📊 CVSS: 9.1
9.1

CVE-2026-33558 - Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component

🏢 Apache 📅 20.4.2026 📊 CVSS: 5.3
5.3

CVE-2026-33557 - A possible security vulnerability has been identified in Apache Kafka. By default, the broker prope

🏢 Apache 📅 20.4.2026 📊 CVSS: 9.1
9.1

CVE-2025-66335 - Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw

🏢 Apache 📅 20.4.2026 📊 CVSS: 5.3
5.3

CVE-2026-40948 - The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or valid

🏢 Apache 📅 18.4.2026 📊 CVSS: 5.4
5.4

CVE-2026-32690 - Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables

🏢 Apache 📅 18.4.2026 📊 CVSS: 3.7
3.7

CVE-2026-30912 - In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_

🏢 Apache 📅 18.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-25917 - Dag Authors, who normally should not be able to execute code in the webserver context could craft XC

🏢 Apache 📅 18.4.2026 📊 CVSS: 7.2
7.2

CVE-2026-30778 - The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of M

🏢 Apache 📅 15.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-5088 - Apache::API::Password versions through 0.5.2 for Perl can generate insecure random values for salts.

🏢 Apache 📅 15.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-33929 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac

🏢 Apache 📅 14.4.2026 📊 CVSS: 4.3
4.3

CVE-2026-31924 - Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls l

🏢 Apache 📅 14.4.2026 📊 CVSS: 5.3
5.3

CVE-2026-31923 - Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due

🏢 Apache 📅 14.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-31908 - Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configu

🏢 Apache 📅 14.4.2026 📊 CVSS: 9.1
9.1

CVE-2026-33858 - Dag Authors, who normally should not be able to execute code in the webserver context could craft XC

🏢 Apache 📅 13.4.2026 📊 CVSS: 8.8
8.8

CVE-2025-66236 - Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager

🏢 Apache 📅 13.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-34476 - Server-Side Request Forgery via SW-URL Header vulnerability in Apache SkyWalking MCP. This issue af

🏢 Apache 📅 13.4.2026 📊 CVSS: 7.1
7.1

CVE-2026-35565 - Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Af

🏢 Apache 📅 13.4.2026 📊 CVSS: 5.4
5.4

CVE-2026-35337 - Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6.

🏢 Apache 📅 13.4.2026 📊 CVSS: 8.8
8.8

CVE-2026-33704 - Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including stu

🏢 Apache 📅 10.4.2026 📊 CVSS: 7.1
7.1

CVE-2026-40023 - Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayou

🏢 Apache 📅 10.4.2026 📊 CVSS: 5.3
5.3

CVE-2026-40021 - Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#lay

🏢 Apache 📅 10.4.2026 📊 CVSS: 5.3
5.3

CVE-2026-34481 - Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.

🏢 Apache 📅 10.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-34480 - Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout ,

🏢 Apache 📅 10.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-34479 - The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden b

🏢 Apache 📅 10.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-34478 - Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424L

🏢 Apache 📅 10.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-34477 - The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete:

🏢 Apache 📅 10.4.2026 📊 CVSS: 5.9
5.9

CVE-2026-39304 - Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker,

🏢 Apache 📅 10.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-34500 - CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled a

🏢 Apache 📅 9.4.2026 📊 CVSS: 6.5
6.5

CVE-2026-34487 - Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clusterin

🏢 Apache 📅 9.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-34486 - Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-2914

🏢 Apache 📅 9.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-34483 - Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache

🏢 Apache 📅 9.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-32990 - Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614.

🏢 Apache 📅 9.4.2026 📊 CVSS: 5.3
5.3

CVE-2026-29146 - Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This

🏢 Oracle 📅 9.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-29145 - CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled v

🏢 Apache 📅 9.4.2026 📊 CVSS: 9.1
9.1

CVE-2026-29129 - Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects

🏢 Apache 📅 9.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-25854 - Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via th

🏢 Apache 📅 9.4.2026 📊 CVSS: 6.1
6.1

CVE-2026-24880 - Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Ap

🏢 Apache 📅 9.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-40046 - Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveM

🏢 Apache 📅 9.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-39962 - MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutraliz

🏢 Apache 📅 9.4.2026 📊 CVSS: 9.6
9.6

CVE-2026-34020 - Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The RE

🏢 Apache 📅 9.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-33266 - Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie en

🏢 Apache 📅 9.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-33005 - Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered u

🏢 Apache 📅 9.4.2026 📊 CVSS: 4.3
4.3

CVE-2026-34538 - Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint returns XCom result values even to

🏢 Apache 📅 9.4.2026 📊 CVSS: 6.5
6.5

CVE-2025-62188 - An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache Dolphin

🏢 Apache 📅 9.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-35573 - ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability

🏢 Apache 📅 7.4.2026 📊 CVSS: 9.1
9.1

CVE-2026-32588 - Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise quer

🏢 Apache 📅 7.4.2026 📊 CVSS: 6.5
6.5

CVE-2026-27315 - Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information,

🏢 Apache 📅 7.4.2026 📊 CVSS: 5.5
5.5

CVE-2026-27314 - Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator all

🏢 Apache 📅 7.4.2026 📊 CVSS: 8.8
8.8

CVE-2026-35554 - A race condition in the Apache Kafka Java producer client’s buffer pool management can cause message

🏢 Apache 📅 7.4.2026 📊 CVSS: 8.7
8.7

CVE-2026-34197 - Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i

🏢 Apache 📅 7.4.2026 📊 CVSS: 8.8
8.8

CVE-2026-33227 - Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Cli

🏢 Apache 📅 7.4.2026 📊 CVSS: 4.3
4.3

CVE-2019-25671 - VA MAX 8.3.4 contains a remote code execution vulnerability that allows authenticated attackers to e

🏢 Apache 📅 5.4.2026 📊 CVSS: 8.8
8.8

CVE-2025-65114 - Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affec

🏢 Apache 📅 2.4.2026 📊 CVSS: 7.5
7.5

CVE-2025-58136 - A bug in POST request handling causes a crash under a certain condition. This issue affects Apache

🏢 Apache 📅 2.4.2026 📊 CVSS: 7.5
7.5

CVE-2026-34381 - Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, Admi

🏢 Apache 📅 31.3.2026 📊 CVSS: 7.5
7.5

CVE-2026-32794 - Improper Certificate Validation vulnerability in Apache Airflow Provider for Databricks. Provider co

🏢 Apache 📅 30.3.2026 📊 CVSS: 4.8
4.8

CVE-2026-28367 - A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` a

🏢 Google cloud 📅 27.3.2026 📊 CVSS: 8.7
8.7

CVE-2026-4649 - Apache Artemis before version 2.52.0 is affected by an authentication bypass flaw which allows readi

🏢 Apache 📅 24.3.2026 📊 CVSS: 0.0
0.0

CVE-2026-32642 - Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists wh

🏢 Apache 📅 24.3.2026 📊 CVSS: 4.3
4.3

CVE-2026-33308 - Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Prior to version 0.13.0, code for clien

🏢 Apache 📅 24.3.2026 📊 CVSS: 6.8
6.8

CVE-2026-33307 - Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. In versions prior to 0.12.3 and 0.13.0,

🏢 Apache 📅 24.3.2026 📊 CVSS: 7.5
7.5

CVE-2026-3533 - The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authori

🏢 Apache 📅 24.3.2026 📊 CVSS: 8.8
8.8

CVE-2026-33071 - FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, the WebDAV u

🏢 Apache 📅 20.3.2026 📊 CVSS: 4.3
4.3

CVE-2026-3547 - Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 and earlier contained

🏢 Apache 📅 19.3.2026 📊 CVSS: 7.5
7.5

CVE-2026-27811 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to vers

🏢 Apache 📅 18.3.2026 📊 CVSS: 8.8
8.8

CVE-2026-30911 - Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API

🏢 Apache 📅 17.3.2026 📊 CVSS: 8.1
8.1

CVE-2026-28779 - Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regar

🏢 Apache 📅 17.3.2026 📊 CVSS: 7.5
7.5

CVE-2026-28563 - Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependenc

🏢 Apache 📅 17.3.2026 📊 CVSS: 4.3
4.3

CVE-2026-26929 - Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG au

🏢 Apache 📅 17.3.2026 📊 CVSS: 6.5
6.5

CVE-2025-54920 - This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version

🏢 Apache 📅 16.3.2026 📊 CVSS: 8.8
8.8

CVE-2016-20026 - ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that all

🏢 Apache 📅 16.3.2026 📊 CVSS: 9.8
9.8

CVE-2026-23941 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP

🏢 Apache 📅 13.3.2026 📊 CVSS: 0.0
0.0

CVE-2025-66249 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac

🏢 Apache 📅 13.3.2026 📊 CVSS: 6.3
6.3

CVE-2025-60012 - Malicious configuration can lead to unauthorized file access in Apache Livy. This issue affects Apa

🏢 Apache 📅 13.3.2026 📊 CVSS: 6.3
6.3

CVE-2026-3963 - A security flaw has been discovered in perfree go-fastdfs-web up to 1.3.7. This affects the function

🏢 Apache 📅 11.3.2026 📊 CVSS: 3.7
3.7

CVE-2026-23907 - This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, f

🏢 Apache 📅 10.3.2026 📊 CVSS: 5.3
5.3

CVE-2026-24713 - Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.

🏢 Apache 📅 9.3.2026 📊 CVSS: 9.8
9.8

CVE-2026-24015 - A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0

🏢 Apache 📅 9.3.2026 📊 CVSS: 9.8
9.8

CVE-2026-24308 - Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all pla

🏢 Apache 📅 7.3.2026 📊 CVSS: 7.5
7.5

CVE-2026-24281 - Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN

🏢 Apache 📅 7.3.2026 📊 CVSS: 7.4
7.4

CVE-2025-40931 - Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id. Apache::S

🏢 Linux 📅 5.3.2026 📊 CVSS: 9.1
9.1

CVE-2026-27446 - Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache Activ

🏢 Apache 📅 4.3.2026 📊 CVSS: 9.8
9.8

CVE-2025-66168 - WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releas

🏢 Apache 📅 4.3.2026 📊 CVSS: 5.4
5.4

CVE-2025-59060 - Hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient is reported in Apa

🏢 Apache 📅 3.3.2026 📊 CVSS: 5.3
5.3

CVE-2025-59059 - Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versi

🏢 Apache 📅 3.3.2026 📊 CVSS: 9.8
9.8

CVE-2025-40932 - Apache::SessionX versions through 2.01 for Perl create insecure session id. Apache::SessionX genera

🏢 Apache 📅 27.2.2026 📊 CVSS: 8.2
8.2

CVE-2026-27636 - FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version

🏢 Apache 📅 25.2.2026 📊 CVSS: 8.8
8.8

CVE-2026-23984 - An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated us

🏢 Apache 📅 24.2.2026 📊 CVSS: 6.5
6.5

CVE-2026-23983 - A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to re

🏢 Apache 📅 24.2.2026 📊 CVSS: 6.5
6.5

CVE-2026-23982 - An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user

🏢 Apache 📅 24.2.2026 📊 CVSS: 6.5
6.5

CVE-2026-23980 - Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in

🏢 Apache 📅 24.2.2026 📊 CVSS: 6.5
6.5

CVE-2026-23969 - Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execut

🏢 Apache 📅 24.2.2026 📊 CVSS: 6.5
6.5

CVE-2026-25747 - Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelD

🏢 Apache 📅 23.2.2026 📊 CVSS: 8.8
8.8

CVE-2026-23552 - Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.  The

🏢 Apache 📅 23.2.2026 📊 CVSS: 9.1
9.1

CVE-2026-27161 - GetSimple CMS is a content management system. All versions of GetSimple CMS rely on .htaccess files

🏢 Apache 📅 21.2.2026 📊 CVSS: 7.5
7.5

CVE-2026-27134 - Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployme

🏢 Apache 📅 21.2.2026 📊 CVSS: 8.1
8.1

CVE-2026-27133 - Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployme

🏢 Apache 📅 20.2.2026 📊 CVSS: 5.9
5.9

CVE-2026-24734 - Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP

🏢 Apache 📅 17.2.2026 📊 CVSS: 7.5
7.5

CVE-2026-24733 - Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests t

🏢 Apache 📅 17.2.2026 📊 CVSS: 3.7
3.7

CVE-2025-66614 - Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 1

🏢 Apache 📅 17.2.2026 📊 CVSS: 9.1
9.1

CVE-2026-25087 - Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 t

🏢 Apache 📅 17.2.2026 📊 CVSS: 7.0
7.0

CVE-2026-25903 - Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on

🏢 Apache 📅 17.2.2026 📊 CVSS: 6.6
6.6

🏢 CVE nach Hersteller

Empfohlene Sicherheitstools

Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.