| CVE-2026-58180 | 7.5 | high | apache / traffic server | The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. | 38d ago |
| CVE-2026-58178 | 7.5 | high | apache / traffic server | The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. | 38d ago |
| CVE-2026-58175 | 7.5 | high | apache / traffic server | Apache Traffic Server leaks memory when handling HostDB SRV records. | 38d ago |
| CVE-2026-58164 | 7.5 | high | apache / traffic server | Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. | 38d ago |
| CVE-2026-58163 | 7.5 | high | apache / traffic server | Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. | 38d ago |
| CVE-2026-58161 | 7.5 | high | apache / traffic server | Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. | 38d ago |
| CVE-2026-65324 | 7.5 | high | apache / traffic server | Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow c | 38d ago |
| CVE-2026-58151 | 7.5 | high | apache / traffic server | Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. | 38d ago |
| CVE-2026-59878 | 7.5 | high | apache / activemq | Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. | 39d ago |
| CVE-2026-58389 | 7.5 | high | apache / thrift | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. | 40d ago |
| CVE-2026-55969 | 7.5 | high | apache / thrift | Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. | 40d ago |
| CVE-2026-55968 | 7.5 | high | apache / thrift | Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache T | 40d ago |
| CVE-2026-49158 | 7.5 | high | apache / thrift | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. | 40d ago |
| CVE-2026-48586 | 7.5 | high | apache / thrift | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, | 40d ago |
| CVE-2026-48145 | 7.5 | high | apache / thrift | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. | 40d ago |
| CVE-2026-45112 | 7.5 | high | apache / thrift | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. | 40d ago |
| CVE-2026-43871 | 7.5 | high | apache / thrift | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bin | 40d ago |
| CVE-2026-41608 | 7.5 | high | apache / thrift | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. | 40d ago |
| CVE-2026-66144 | 7.5 | high | apache / neethi | Although remote policy references are not retrieved during policy normalization, if they are manually retrieved vi | 43d ago |
| CVE-2026-66143 | 7.5 | high | apache / neethi | It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi | 43d ago |
| CVE-2026-66142 | 7.5 | high | apache / neethi | Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply ne | 43d ago |
| CVE-2026-45816 | 7.5 | high | apache / nimble | NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. | 43d ago |
| CVE-2026-45815 | 7.5 | high | apache / nimble | Reachable Assertion vulnerability in Apache NimBLE. | 43d ago |
| CVE-2026-45811 | 7.5 | high | apache / nimble | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. | 43d ago |
| CVE-2026-56452 | 7.5 | high | apache / mina sshd | Path traversal in the sshd-scp component of Apache MINA SSHD. | 47d ago |
| CVE-2026-59173 | 7.5 | high | apache / traffic server | Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. | 49d ago |
| CVE-2026-57111 | 7.5 | high | apache / helix | Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters. | 58d ago |
| CVE-2026-55994 | 7.5 | high | apache / camel | Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery | 61d ago |
| CVE-2026-55993 | 7.5 | high | apache / camel | Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery | 61d ago |
| CVE-2026-46726 | 7.5 | high | apache / camel | Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery | 61d ago |
| CVE-2026-46592 | 7.5 | high | apache / camel | Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF | 61d ago |
| CVE-2026-46585 | 7.5 | high | apache / camel | Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene C | 61d ago |
| CVE-2026-46457 | 7.5 | high | apache / camel | Improper Input Validation vulnerability in Apache Camel NATS component. | 61d ago |
| CVE-2026-24012 | 7.5 | high | apache / iotdb | Uncontrolled Resource Consumption vulnerability in Apache IoTDB. | 61d ago |
| CVE-2026-47896 | 7.5 | high | apache / lucene.net | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net | 64d ago |
| CVE-2026-47897 | 7.5 | high | apache / lucene.net | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net | 64d ago |
| CVE-2026-54428 | 7.5 | high | apache / httpcomponents core | Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5. | 66d ago |
| CVE-2026-54399 | 7.5 | high | apache / httpcomponents core | Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4. | 66d ago |
| CVE-2026-54475 | 7.5 | high | apache / activemq | Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. | 67d ago |
| CVE-2026-53917 | 7.5 | high | apache / activemq | Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ | 67d ago |
| CVE-2026-53916 | 7.5 | high | apache / activemq | Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ | 67d ago |
| CVE-2026-50750 | 7.5 | high | apache / activemq | Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. | 67d ago |
| CVE-2026-50734 | 7.5 | high | apache / activemq | Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache Activ | 67d ago |
| CVE-2026-49434 | 7.5 | high | apache / activemq | Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. | 67d ago |
| CVE-2026-49432 | 7.5 | high | apache / activemq | Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. | 67d ago |
| CVE-2026-49486 | 7.5 | high | apache / apache-airflow-providers-ftp | The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `p | 71d ago |
| CVE-2026-50645 | 7.5 | high | apache / cxf | There is no restriction on the amount of attachment headers that a message can contain when being deserialized by | 85d ago |
| CVE-2026-49975 | 7.5 | high | apache / http server | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of serv | 89d ago |
| CVE-2026-42536 | 7.5 | high | apache / http server | Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted con | 89d ago |
| CVE-2026-34356 | 7.5 | high | apache / http server | Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverse | 89d ago |
| CVE-2026-34355 | 7.5 | high | apache / http server | A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted back | 89d ago |
| CVE-2026-47430 | 7.5 | high | apache / cordova inappbrowser | ## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` | 89d ago |
| CVE-2026-49361 | 7.5 | high | apache / fluss | Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as th | 96d ago |
| CVE-2026-41084 | 7.5 | high | apache / airflow | A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskIn | 96d ago |
| CVE-2026-44417 | 7.5 | high | apache / cxf | The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that | 106d ago |
| CVE-2026-31910 | 7.5 | high | apache / ofbiz | Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. | 109d ago |
| CVE-2026-31909 | 7.5 | high | apache / ofbiz | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. | 109d ago |
| CVE-2026-43513 | 7.5 | high | apache / tomcat | Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. | 116d ago |
| CVE-2026-41284 | 7.5 | high | apache / tomcat | Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. | 116d ago |
| CVE-2026-28779 | 7.5 | high | apache / airflow | Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the c | 172d ago |