CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-60080 - Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Ap
CVE-2026-64606 - Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypas
CVE-2026-64609 - Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is
CVE-2026-64608 - Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deseria
CVE-2026-58624 - Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for cl
CVE-2026-56624 - Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java librar
CVE-2026-56623 - Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library
CVE-2026-56452 - Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for
CVE-2026-53593 - FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version
CVE-2026-63071 - Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with a
CVE-2026-62418 - Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via
CVE-2026-62183 - Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow
CVE-2026-57308 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-53421 - Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with
CVE-2026-53405 - Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with a
CVE-2026-59173 - Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache
CVE-2026-62764 - Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but
CVE-2026-44182 - Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like
CVE-2026-44181 - Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like
CVE-2026-44180 - Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like
CVE-2026-33692 - WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenti
CVE-2026-26032 - The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a
CVE-2026-57821 - A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in
CVE-2026-56287 - A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/
CVE-2026-35152 - A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint)
CVE-2026-62393 - Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper
CVE-2026-62392 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi
CVE-2026-62390 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-49488 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac
CVE-2026-58319 - Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication.
CVE-2026-59084 - Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to secure
CVE-2026-59083 - Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allo
CVE-2026-49972 - Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attac
CVE-2026-59245 - In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-
CVE-2026-58065 - The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by
CVE-2026-49876 - Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and
CVE-2026-41041 - URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This
CVE-2026-52761 - ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS
CVE-2026-52747 - ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS
CVE-2026-49844 - Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache
CVE-2026-40454 - Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bound
CVE-2026-40452 - Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass
CVE-2026-40009 - Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated
CVE-2026-40008 - Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in
CVE-2026-40007 - Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB. When pipe_a
CVE-2026-40006 - Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, M
CVE-2026-40005 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac
CVE-2026-28564 - Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoT
CVE-2026-57111 - Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.s
CVE-2026-41042 - Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which exe
CVE-2026-23698 - Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin
CVE-2026-23697 - Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileg
CVE-2026-49487 - In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a defe
CVE-2026-49296 - Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Da
CVE-2026-48892 - The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables l
CVE-2026-48891 - A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable
CVE-2026-48828 - The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so
CVE-2026-33264 - A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-contro
CVE-2026-43825 - Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected: before 3.0.0-M
CVE-2026-49042 - Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: from 4.8.
CVE-2026-46588 - Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4
CVE-2026-46587 - Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4
CVE-2026-56139 - Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Undertow
CVE-2026-55994 - Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side R
CVE-2026-55993 - Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side R
CVE-2026-53913 - Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failin
CVE-2026-49365 - Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Netty HTT
CVE-2026-49099 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'),
CVE-2026-49098 - Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstrea
CVE-2026-49097 - Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstrea
CVE-2026-49086 - Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apa
CVE-2026-48206 - Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache
CVE-2026-48205 - Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS comp
CVE-2026-48204 - Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gr
CVE-2026-48203 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'),
CVE-2026-46726 - Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side R
CVE-2026-46592 - Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apa
CVE-2026-46591 - Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J
CVE-2026-46585 - Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache
CVE-2026-46584 - Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2026-46457 - Improper Input Validation vulnerability in Apache Camel NATS component. The camel-nats component ma
CVE-2026-46455 - Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloa
CVE-2026-46454 - Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd componen
CVE-2026-43866 - Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. JmsBin
CVE-2026-43865 - Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-haze
CVE-2026-42527 - Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter patt
CVE-2026-40859 - Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component des
CVE-2026-40047 - Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in
CVE-2026-24014 - Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trig
CVE-2026-24013 - Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers l
CVE-2026-24012 - Uncontrolled Resource Consumption vulnerability in Apache IoTDB. Some interface fails to impose re
CVE-2026-47896 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac
CVE-2026-47898 - Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net
CVE-2026-47897 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac
CVE-2026-54428 - Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpCompo
CVE-2026-54399 - Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpCompone
CVE-2026-55223 - c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with ot
CVE-2026-54475 - Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.
CVE-2026-53917 - Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, A
CVE-2026-53916 - Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, A
CVE-2026-52760 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-50750 - Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache
CVE-2026-50734 - Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ
CVE-2026-49877 - Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console
CVE-2026-49434 - Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ
CVE-2026-49432 - Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Sto
CVE-2026-55957 - Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was config
CVE-2026-55956 - Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for th
CVE-2026-55955 - Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the Encryptio
CVE-2026-55276 - Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles
CVE-2026-53434 - Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for
CVE-2026-53404 - Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant th
CVE-2026-50229 - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the n
CVE-2026-57915 - It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA
CVE-2025-64152 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac
CVE-2025-55017 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac
CVE-2026-57914 - By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trig
CVE-2026-49486 - The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but n
CVE-2026-48946 - The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's
CVE-2026-56130 - "Remember me" cookie age is not verified on the server. This potentially allows an attacker to inter
CVE-2026-56091 - When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted HT
CVE-2026-54226 - A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.6.0 through 2.15.0. U
CVE-2026-46752 - Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache
CVE-2026-46751 - A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.2.0 through 2.15.0. U
CVE-2026-45188 - Relative Path Traversal vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.
CVE-2026-41566 - Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. This i
CVE-2026-54665 - Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request hea
CVE-2026-44914 - Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that includ
CVE-2026-44913 - Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache N
CVE-2026-44911 - Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 throu
CVE-2025-66336 - Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-cont
CVE-2025-62198 - An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier.
CVE-2026-49872 - Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route
CVE-2026-49871 - Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations.
CVE-2026-49231 - Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed iden
CVE-2026-49230 - Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin
CVE-2026-48895 - URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker co
CVE-2026-47341 - Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from c
CVE-2026-47339 - Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor
CVE-2026-44915 - URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default con
CVE-2026-44087 - Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect p
CVE-2026-44046 - Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac
CVE-2026-39999 - Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypas
CVE-2026-39998 - Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certai
CVE-2026-49257 - mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. I
CVE-2026-49268 - A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction i
CVE-2026-50203 - A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`
CVE-2026-47340 - Allow authenticated users to access alert instances associated with alert groups they do not have pe
CVE-2026-42357 - Incorrect Authorization vulnerability allows users to access workflow instance information belonging
CVE-2026-41280 - Incorrect Authorization vulnerability allows users with system login privileges to delete task defin
CVE-2026-32967 - Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. T
CVE-2026-32966 - DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apa
CVE-2026-50645 - There is no restriction on the amount of attachment headers that a message can contain when being de
CVE-2026-50634 - A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to proce
CVE-2026-50633 - A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can
CVE-2026-50632 - A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lea
CVE-2026-50627 - The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of inc
CVE-2026-50623 - An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF.
CVE-2026-49875 - Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory w
CVE-2026-41000 - Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestDa
CVE-2026-40996 - Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J'
CVE-2026-50223 - Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low
CVE-2026-47342 - A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to o
CVE-2026-45569 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45567 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45566 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45565 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-25700 - Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affect
CVE-2026-45564 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45563 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45561 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45560 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45559 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45558 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45556 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45552 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45550 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45549 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-41732 - JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning t
CVE-2026-41731 - JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trust
CVE-2026-41727 - Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header value
CVE-2026-41726 - When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap withou
CVE-2026-49818 - The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destinat
CVE-2026-34905 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This iss
CVE-2026-34033 - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apach
CVE-2026-34031 - Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects
CVE-2026-33582 - Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects
CVE-2026-25699 - Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. T
CVE-2026-25688 - Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects
CVE-2026-49975 - Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to
CVE-2026-48913 - Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already ex
CVE-2026-44631 - Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configur
CVE-2026-44186 - Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in
CVE-2026-44185 - Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker contr
CVE-2026-44119 - Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .h
CVE-2026-43951 - Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple re
CVE-2026-42536 - Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and
CVE-2026-42535 - A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to d
CVE-2026-34356 - Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and Pr
CVE-2026-34355 - A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an
CVE-2026-29170 - A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apa
CVE-2026-29167 - Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration Thi
CVE-2026-50076 - Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK
CVE-2026-45080 - Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4
CVE-2026-44367 - Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4
CVE-2026-46718 - Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in
CVE-2026-41115 - An improper authorization vulnerability has been identified in Apache Kafka. The implementation of
CVE-2026-49328 - Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) f
CVE-2026-49361 - Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.M
CVE-2026-49298 - A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate a
CVE-2026-49270 - Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache A
CVE-2026-49267 - Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STA
CVE-2026-49157 - Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ:
CVE-2026-48827 - Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upl
CVE-2026-48726 - A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after
CVE-2026-46764 - The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched audit
CVE-2026-46605 - Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authent
CVE-2026-45505 - Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i
CVE-2026-45426 - Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log
CVE-2026-45360 - Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_r
CVE-2026-44825 - Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr v
CVE-2026-42588 - Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i
CVE-2026-42360 - A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g.
CVE-2026-42359 - A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authentic
CVE-2026-42358 - A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-
CVE-2026-42253 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-42252 - Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when tr
CVE-2026-41084 - A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_
CVE-2026-41017 - Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deploy
CVE-2026-41014 - The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not p
CVE-2026-40963 - The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Da
CVE-2026-40961 - A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that b
CVE-2026-40861 - A Dag author could either (a) create a symlink under their task's log directory pointing to an arbit
CVE-2026-45192 - A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed a
CVE-2026-48557 - Spatie Laravel Media Library before version 11.23.0 contains a file upload restriction bypass in Fil
CVE-2026-40914 - A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with securi
CVE-2025-48977 - Relative Path Traversal vulnerability in Apache Ignite REST API. Authenticated REST API users can r
CVE-2026-44966 - Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earl
CVE-2026-40564 - Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerabilit
CVE-2026-48589 - Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect aft
CVE-2026-44598 - With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Reque
CVE-2026-43828 - Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attr
CVE-2026-43827 - Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Ap
CVE-2026-42797 - Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administ
CVE-2026-42782 - Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with a
CVE-2026-46745 - Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows
CVE-2026-45249 - A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rend
CVE-2026-44930 - An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF
CVE-2026-44618 - Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform
CVE-2026-44417 - The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.