| CVE-2026-45434 | 9.8 | critical | apache / ofbiz | Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execut | 109d ago |
| CVE-2026-43512 | 9.8 | critical | apache / tomcat | DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. | 116d ago |
| CVE-2026-41293 | 9.8 | critical | apache / tomcat | Improper Input Validation vulnerability in Apache Tomcat. | 116d ago |
| CVE-2026-58155 | 9.3 | critical | apache / traffic server | Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy by | 38d ago |
| CVE-2026-41920 | 9.3 | critical | apache / traffic server | Improper Access Control vulnerability in Apache Traffic Server. | 38d ago |
| CVE-2026-49871 | 9.3 | critical | apache / apisix | Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. | 78d ago |
| CVE-2026-68525 | 9.1 | critical | apache / tomcat | Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a sec | 11d ago |
| CVE-2026-65182 | 9.1 | critical | apache / tomcat | Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypas | 11d ago |
| CVE-2026-55976 | 9.1 | critical | apache / hive | Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authentic | 11d ago |
| CVE-2026-66906 | 9.1 | critical | apache / camel | Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. | 12d ago |
| CVE-2026-62440 | 9.1 | critical | apache / cloudstack | Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenan | 15d ago |
| CVE-2026-61398 | 9.1 | critical | apache / cloudstack | Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Passwor | 15d ago |
| CVE-2026-59085 | 9.1 | critical | apache / cloudstack | Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook de | 15d ago |
| CVE-2026-71290 | 9.1 | critical | apache / httpclient | Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. | 25d ago |
| CVE-2026-69223 | 9.1 | critical | apache / allura | Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). | 25d ago |
| CVE-2026-71560 | 9.1 | critical | apache / fory | Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. | 29d ago |
| CVE-2026-34191 | 9.1 | critical | apache / apr-util | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Porta | 30d ago |
| CVE-2026-32327 | 9.1 | critical | apache / apr-util | A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which p | 30d ago |
| CVE-2026-65583 | 9.1 | critical | apache / cxf | Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required cla | 30d ago |
| CVE-2026-63687 | 9.1 | critical | apache / cxf | Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map | 30d ago |
| CVE-2026-61466 | 9.1 | critical | apache / cxf | In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scop | 30d ago |
| CVE-2026-60053 | 9.1 | critical | apache / answer | Insufficient Session Expiration vulnerability in Apache Answer. | 31d ago |
| CVE-2026-68980 | 9.1 | critical | apache / nifi | Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts | 33d ago |
| CVE-2026-58662 | 9.1 | critical | apache / thrift | Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings | 40d ago |
| CVE-2026-58023 | 9.1 | critical | apache / thrift | Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. | 40d ago |
| CVE-2026-48144 | 9.1 | critical | apache / thrift | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. | 40d ago |
| CVE-2026-64609 | 9.1 | critical | apache / fory | Out-of-bounds read via sun.misc.Unsafe in Apache Fory. | 46d ago |
| CVE-2026-58319 | 9.1 | critical | apache / doris | Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. | 53d ago |
| CVE-2026-59084 | 9.1 | critical | apache / tomcat | Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure t | 53d ago |
| CVE-2026-59083 | 9.1 | critical | apache / tomcat | Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security c | 53d ago |
| CVE-2026-41041 | 9.1 | critical | apache / gravitino | URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. | 54d ago |
| CVE-2026-48205 | 9.1 | critical | apache / camel | Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. | 61d ago |
| CVE-2026-48203 | 9.1 | critical | apache / camel | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input | 61d ago |
| CVE-2026-40047 | 9.1 | critical | apache / camel | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel D | 61d ago |
| CVE-2026-24013 | 9.1 | critical | apache / iotdb | Authentication Bypass by Spoofing vulnerability in Apache IoTDB. | 61d ago |
| CVE-2026-55276 | 9.1 | critical | apache / tomcat | Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty aut | 68d ago |
| CVE-2026-53434 | 9.1 | critical | apache / tomcat | Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based c | 68d ago |
| CVE-2026-49230 | 9.1 | critical | apache / apisix | Improper Validation of Integrity Check Value vulnerability in Apache APISIX. | 78d ago |
| CVE-2026-44087 | 9.1 | critical | apache / apisix | Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. | 78d ago |
| CVE-2026-39999 | 9.1 | critical | apache / apisix | Authentication Bypass by Spoofing vulnerability in Apache APISIX. | 78d ago |
| CVE-2026-49268 | 9.1 | critical | apache / shiro | A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapR | 80d ago |
| CVE-2026-50203 | 9.1 | critical | apache / apache-airflow-providers-sftp | A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malici | 80d ago |
| CVE-2026-32967 | 9.1 | critical | apache / dolphinscheduler | Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. | 80d ago |
| CVE-2026-50627 | 9.1 | critical | apache / cxf | The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT acce | 85d ago |
| CVE-2026-42535 | 9.1 | critical | apache / http server | A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipu | 89d ago |
| CVE-2026-50076 | 9.1 | critical | apache / fory | Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 | 93d ago |
| CVE-2026-42252 | 9.1 | critical | apache / airflow | Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags" | 96d ago |
| CVE-2026-41919 | 9.1 | critical | apache / ofbiz | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz | 109d ago |
| CVE-2026-31986 | 9.1 | critical | apache / ofbiz | Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. | 109d ago |
| CVE-2026-43515 | 9.1 | critical | apache / tomcat | Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension | 116d ago |
| CVE-2026-58154 | 8.9 | high | apache / traffic server | Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. | 38d ago |
| CVE-2026-63041 | 8.8 | high | apache / apisix | Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. | 10d ago |
| CVE-2026-63046 | 8.8 | high | apache / inlong | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. | 15d ago |
| CVE-2026-61400 | 8.8 | high | apache / cloudstack | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudS | 15d ago |
| CVE-2026-59799 | 8.8 | high | apache / cloudstack | Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypas | 15d ago |
| CVE-2026-50112 | 8.8 | high | apache / cloudstack | SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-c | 15d ago |
| CVE-2026-47359 | 8.8 | high | apache / cloudstack | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache | 15d ago |
| CVE-2026-67587 | 8.8 | high | apache / airflow | Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which im | 24d ago |
| CVE-2026-58076 | 8.8 | high | apache / airflow | Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name ta | 24d ago |
| CVE-2026-28813 | 8.8 | high | apache / jspwiki | Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. | 37d ago |