CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-44966 - Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earl
CVE-2026-40564 - Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerabilit
CVE-2026-48589 - Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect aft
CVE-2026-44598 - With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Reque
CVE-2026-43828 - Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attr
CVE-2026-43827 - Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Ap
CVE-2026-42797 - Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administ
CVE-2026-42782 - Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with a
CVE-2026-46745 - Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows
CVE-2026-45361 - Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by defau
CVE-2026-45249 - A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rend
CVE-2026-44930 - An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF
CVE-2026-44618 - Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform
CVE-2026-44417 - The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete
CVE-2026-48207 - Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass docu
CVE-2026-45760 - (Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through Use
CVE-2026-42526 - In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-ama
CVE-2026-47323 - Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knat
CVE-2026-46586 - Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in
CVE-2026-45434 - Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remo
CVE-2026-45187 - Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: bef
CVE-2026-41919 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability i
CVE-2026-35086 - Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache
CVE-2026-31986 - Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz:
CVE-2026-31910 - Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz:
CVE-2026-31909 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issu
CVE-2026-31906 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-31388 - Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affec
CVE-2026-31387 - Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.0
CVE-2026-31380 - Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression La
CVE-2026-31379 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limit
CVE-2026-31378 - Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24
CVE-2026-29226 - Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations.
CVE-2026-29220 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac
CVE-2026-29207 - Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz.
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.