| CVE-2026-53561 | 7.4 | high | apache / hive | An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through | 11d ago |
| CVE-2026-50631 | 7.4 | high | apache / cxf | A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass si | 85d ago |
| CVE-2026-67260 | 7.3 | high | apache / airflow | Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept b | 24d ago |
| CVE-2026-65948 | 7.3 | high | apache / ranger | UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0. | 26d ago |
| CVE-2026-23904 | 7.3 | high | apache / kyuubi | Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination | 38d ago |
| CVE-2026-60080 | 7.3 | high | apache / fory | Use After Free vulnerability in the Rust deserialization logic of Apache Fory. | 46d ago |
| CVE-2026-56624 | 7.3 | high | apache / mina sshd | Improper certificate validation in Apache MINA SSHD (server-side). | 47d ago |
| CVE-2026-43825 | 7.3 | high | apache / opennlp | Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected: before 3.0.0-M4 (libsvm documen | 61d ago |
| CVE-2026-49042 | 7.3 | high | apache / camel | Improper Input Validation vulnerability in Apache Camel. | 61d ago |
| CVE-2026-46588 | 7.3 | high | apache / camel | Improper Input Validation vulnerability in Apache Camel. | 61d ago |
| CVE-2026-46587 | 7.3 | high | apache / camel | Improper Input Validation vulnerability in Apache Camel. | 61d ago |
| CVE-2026-43866 | 7.3 | high | apache / camel | Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. | 61d ago |
| CVE-2026-55957 | 7.3 | high | apache / tomcat | Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authen | 68d ago |
| CVE-2026-53404 | 7.3 | high | apache / tomcat | Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the firs | 68d ago |
| CVE-2026-48913 | 7.3 | high | apache / http server | Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. | 89d ago |
| CVE-2026-44186 | 7.3 | high | apache / http server | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Se | 89d ago |
| CVE-2026-44185 | 7.3 | high | apache / http server | Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP ser | 89d ago |
| CVE-2026-45360 | 7.3 | high | apache / airflow | Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imp | 96d ago |
| CVE-2026-29226 | 7.3 | high | apache / ofbiz | Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations. | 109d ago |
| CVE-2026-42498 | 7.3 | high | apache / tomcat | Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache | 116d ago |
| CVE-2026-66722 | 7.2 | high | apache / cloudstack | Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in Clou | 15d ago |
| CVE-2026-24033 | 7.2 | high | apache / traffic server | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic S | 38d ago |
| CVE-2026-44914 | 7.2 | high | apache / nifi | Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension co | 75d ago |
| CVE-2026-44913 | 7.2 | high | apache / nifi | Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 thro | 75d ago |
| CVE-2026-48895 | 7.2 | high | apache / apisix | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. | 78d ago |
| CVE-2026-25700 | 7.2 | high | apache / answer | Improper Restriction of Security Token Assignment vulnerability in Apache Answer. | 87d ago |
| CVE-2026-40961 | 7.2 | high | apache / airflow | A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `i | 96d ago |
| CVE-2026-42782 | 7.2 | high | apache / syncope | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. | 103d ago |
| CVE-2026-56623 | 7.1 | high | apache / mina sshd | Path traversal on Windows in Apache MINA SSHD component sshd-git. | 47d ago |
| CVE-2026-48827 | 7.1 | high | apache / mina sshd | Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. | 96d ago |