| CVE-2026-50622 | 8.8 | high | apache / atlas | Description: Missing Authorization in Apache Atlas. | 38d ago |
| CVE-2026-45813 | 8.8 | high | apache / nimble | Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. | 43d ago |
| CVE-2026-35152 | 8.8 | high | apache / fineract | A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions u | 52d ago |
| CVE-2026-46590 | 8.8 | high | apache / camel | Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. | 61d ago |
| CVE-2026-39998 | 8.8 | high | apache / apisix | Improper Input Validation vulnerability in Apache APISIX. | 78d ago |
| CVE-2026-50223 | 8.8 | high | apache / ofbiz | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged au | 87d ago |
| CVE-2026-47342 | 8.8 | high | apache / ofbiz | A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher p | 87d ago |
| CVE-2026-49298 | 8.8 | high | apache / airflow | A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Exe | 96d ago |
| CVE-2026-49157 | 8.8 | high | apache / activemq | Incorrect Default Permissions vulnerability in Apache ActiveMQ. | 96d ago |
| CVE-2026-45505 | 8.8 | high | apache / activemq | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Activ | 96d ago |
| CVE-2026-42359 | 8.8 | high | apache / airflow | A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API us | 96d ago |
| CVE-2026-46586 | 8.8 | high | apache / ofbiz | Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Ev | 109d ago |
| CVE-2025-54920 | 8.8 | high | apache / spark | This issue affects Apache Spark: before 3.5.7 and 4.0.1. | 173d ago |
| CVE-2026-58157 | 8.7 | high | apache / traffic server | Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections. | 38d ago |
| CVE-2026-27173 | 8.7 | high | apache / apache-airflow-providers-cncf-kubernetes | JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access t | 109d ago |
| CVE-2026-58182 | 8.6 | high | apache / traffic server | The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. | 38d ago |
| CVE-2026-35563 | 8.5 | high | apache / directory ldap api | It was identified that the LDAP client implementation in version 2.1.7 does not verify if the server certificate m | 96d ago |
| CVE-2026-58153 | 8.3 | high | apache / traffic server | Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when conver | 38d ago |
| CVE-2026-58188 | 8.2 | high | apache / traffic server | Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. | 38d ago |
| CVE-2026-58184 | 8.2 | high | apache / traffic server | The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR cond | 38d ago |
| CVE-2026-58159 | 8.2 | high | apache / traffic server | Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. | 38d ago |
| CVE-2026-22068 | 8.2 | high | apache / traffic server | Regular Expression without Anchors vulnerability in Apache Traffic Server. | 38d ago |
| CVE-2026-46591 | 8.2 | high | apache / camel | Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component. | 61d ago |
| CVE-2026-75020 | 8.1 | high | apache / apisix | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISI | 9d ago |
| CVE-2026-68569 | 8.1 | high | apache / tomcat | Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. | 11d ago |
| CVE-2026-66422 | 8.1 | high | apache / tomcat | Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly use | 11d ago |
| CVE-2026-65183 | 8.1 | high | apache / tomcat | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets | 11d ago |
| CVE-2026-68745 | 8.1 | high | apache / cloudstack | Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms | 15d ago |
| CVE-2026-63042 | 8.1 | high | apache / inlong | Files or Directories Accessible to External Parties vulnerability in Apache InLong. | 16d ago |
| CVE-2026-63040 | 8.1 | high | apache / inlong | Files or Directories Accessible to External Parties vulnerability in Apache InLong. | 16d ago |
| CVE-2026-57818 | 8.1 | high | apache / cxf | A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times | 30d ago |
| CVE-2026-57817 | 8.1 | high | apache / cxf | The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating | 30d ago |
| CVE-2026-62391 | 8.1 | high | apache / kyuubi | The security fix for CVE-2025-66518 is incomplete. | 36d ago |
| CVE-2026-58179 | 8.1 | high | apache / traffic server | The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. | 38d ago |
| CVE-2026-58177 | 8.1 | high | apache / traffic server | The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. | 38d ago |
| CVE-2026-62418 | 8.1 | high | apache / syncope | Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and | 47d ago |
| CVE-2026-57821 | 8.1 | high | apache / fineract | A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up t | 52d ago |
| CVE-2026-56287 | 8.1 | high | apache / fineract | A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in | 52d ago |
| CVE-2026-59245 | 8.1 | high | apache / apache-airflow-providers-fab | In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permissio | 54d ago |
| CVE-2026-58065 | 8.1 | high | apache / apache-airflow-providers-git | The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disab | 54d ago |
| CVE-2026-49297 | 8.1 | high | apache / apache-airflow-providers-google | Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS o | 61d ago |
| CVE-2026-43865 | 8.1 | high | apache / camel | Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. | 61d ago |
| CVE-2026-42527 | 8.1 | high | apache / camel | Deserialization of Untrusted Data vulnerability in Apache Camel. | 61d ago |
| CVE-2026-40859 | 8.1 | high | apache / camel | Deserialization of Untrusted Data vulnerability in Apache Camel. | 61d ago |
| CVE-2026-49877 | 8.1 | high | apache / activemq | Improper Authorization vulnerability in Apache ActiveMQ. | 67d ago |
| CVE-2025-66336 | 8.1 | high | apache / doris mcp server | Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. | 75d ago |
| CVE-2026-49872 | 8.1 | high | apache / apisix | Improper Authentication vulnerability in Apache APISIX. | 78d ago |
| CVE-2026-47339 | 8.1 | high | apache / apisix | Incorrect Authorization vulnerability in Apache APISIX. | 78d ago |
| CVE-2026-50633 | 8.1 | high | apache / cxf | A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for cod | 85d ago |
| CVE-2026-50632 | 8.1 | high | apache / cxf | A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for | 85d ago |
| CVE-2026-44825 | 8.1 | high | apache / solr | Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 | 96d ago |
| CVE-2026-42588 | 8.1 | high | apache / activemq | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Activ | 96d ago |
| CVE-2026-45361 | 8.1 | high | apache / apache-airflow-providers-google | Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing S | 103d ago |
| CVE-2026-35194 | 8.1 | high | apache / flink | Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authentic | 113d ago |
| CVE-2026-30911 | 8.1 | high | apache / airflow | Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-th | 172d ago |
| CVE-2026-71257 | 7.5 | high | apache / wicket | Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multipart request wi | 5d ago |
| CVE-2026-75005 | 7.5 | high | apache / apisix | Inefficient Algorithmic Complexity vulnerability in Apache APISIX. | 9d ago |
| CVE-2026-74848 | 7.5 | high | apache / apisix | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. | 9d ago |
| CVE-2026-68763 | 7.5 | high | apache / tomcat | Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog trac | 11d ago |
| CVE-2026-65927 | 7.5 | high | apache / tomcat | Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite proces | 11d ago |