| CVE-2026-66908 | 7.5 | high | apache / camel | Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. | 12d ago |
| CVE-2026-66907 | 7.5 | high | apache / camel | Relative path traversal vulnerability in Apache Camel Google Storage component. | 12d ago |
| CVE-2026-59654 | 7.5 | high | apache / cloudstack | Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configurat | 15d ago |
| CVE-2026-61397 | 7.5 | high | apache / cloudstack | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authenticat | 15d ago |
| CVE-2026-59780 | 7.5 | high | apache / cloudstack | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authenticatio | 15d ago |
| CVE-2026-59657 | 7.5 | high | apache / cloudstack | Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the databas | 15d ago |
| CVE-2026-59655 | 7.5 | high | apache / cloudstack | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authenticati | 15d ago |
| CVE-2026-50222 | 7.5 | high | apache / cloudstack | Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudSta | 15d ago |
| CVE-2026-63043 | 7.5 | high | apache / inlong | Relative Path Traversal vulnerability in Apache InLong. | 16d ago |
| CVE-2026-73635 | 7.5 | high | apache / struts | Allocation of resources without limits or throttling vulnerability in Apache Struts. | 21d ago |
| CVE-2026-73634 | 7.5 | high | apache / struts | Uncontrolled resource consumption vulnerability in Apache Struts. | 21d ago |
| CVE-2026-73633 | 7.5 | high | apache / struts | Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. | 22d ago |
| CVE-2026-68968 | 7.5 | high | apache / airflow | Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_ | 24d ago |
| CVE-2026-65942 | 7.5 | high | apache / ranger | TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. | 26d ago |
| CVE-2026-61899 | 7.5 | high | apache / tapestry | Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath as | 26d ago |
| CVE-2026-55814 | 7.5 | high | apache / ranger | Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. | 26d ago |
| CVE-2026-71559 | 7.5 | high | apache / fory | Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to caus | 29d ago |
| CVE-2026-34502 | 7.5 | high | apache / apr-util | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Ap | 30d ago |
| CVE-2026-34501 | 7.5 | high | apache / apr-util | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. | 30d ago |
| CVE-2025-49506 | 7.5 | high | apache / apr-util | APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashe | 30d ago |
| CVE-2026-68481 | 7.5 | high | apache / cxf | In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenInt | 30d ago |
| CVE-2026-65432 | 7.5 | high | apache / cxf | Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entiti | 30d ago |
| CVE-2026-64958 | 7.5 | high | apache / cxf | An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apac | 30d ago |
| CVE-2026-57819 | 7.5 | high | apache / cxf | Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCou | 30d ago |
| CVE-2026-54225 | 7.5 | high | apache / cxf | Apache CXF allows to control the maximum attachment size via the "attachment-max-size". | 30d ago |
| CVE-2026-60023 | 7.5 | high | apache / answer | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. | 31d ago |
| CVE-2026-48911 | 7.5 | high | apache / answer | Insufficient Verification of Data Authenticity vulnerability in Apache Answer. | 31d ago |
| CVE-2026-48834 | 7.5 | high | apache / answer | Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. | 31d ago |
| CVE-2026-61483 | 7.5 | high | apache / lucy | ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. | 31d ago |
| CVE-2026-68073 | 7.5 | high | apache / qpid broker-j | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to den | 31d ago |
| CVE-2026-67592 | 7.5 | high | apache / qpid protonj2 | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticat | 31d ago |
| CVE-2026-67590 | 7.5 | high | apache / qpid protonj2 | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to den | 31d ago |
| CVE-2026-67552 | 7.5 | high | apache / qpid proton-dotnet | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to den | 31d ago |
| CVE-2026-66274 | 7.5 | high | apache / qpid proton-j | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to den | 31d ago |
| CVE-2026-68074 | 7.5 | high | apache / qpid broker-j | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading t | 31d ago |
| CVE-2026-68060 | 7.5 | high | apache / qpid broker-j | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to pot | 31d ago |
| CVE-2026-67589 | 7.5 | high | apache / qpid protonj2 | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to pot | 31d ago |
| CVE-2026-67588 | 7.5 | high | apache / qpid protonj2 | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading t | 31d ago |
| CVE-2026-67551 | 7.5 | high | apache / qpid proton-dotnet | pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to poten | 31d ago |
| CVE-2026-67465 | 7.5 | high | apache / qpid proton-dotnet | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading t | 31d ago |
| CVE-2026-66273 | 7.5 | high | apache / qpid proton-j | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to pot | 31d ago |
| CVE-2026-66257 | 7.5 | high | apache / qpid proton-j | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading t | 31d ago |
| CVE-2026-68981 | 7.5 | high | apache / nifi | Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey en | 33d ago |
| CVE-2026-61372 | 7.5 | high | apache / jena fuseki | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki | 33d ago |
| CVE-2026-66755 | 7.5 | high | apache / tika | Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, an | 37d ago |
| CVE-2026-28814 | 7.5 | high | apache / jspwiki | Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to ob | 37d ago |
| CVE-2026-28811 | 7.5 | high | apache / jspwiki | Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. | 37d ago |
| CVE-2026-58189 | 7.5 | high | apache / traffic server | Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplificati | 38d ago |
| CVE-2026-58186 | 7.5 | high | apache / traffic server | The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. | 38d ago |
| CVE-2026-58181 | 7.5 | high | apache / traffic server | The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. | 38d ago |
| CVE-2026-58180 | 7.5 | high | apache / traffic server | The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. | 38d ago |
| CVE-2026-58178 | 7.5 | high | apache / traffic server | The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. | 38d ago |
| CVE-2026-58175 | 7.5 | high | apache / traffic server | Apache Traffic Server leaks memory when handling HostDB SRV records. | 38d ago |
| CVE-2026-58164 | 7.5 | high | apache / traffic server | Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. | 38d ago |
| CVE-2026-58163 | 7.5 | high | apache / traffic server | Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. | 38d ago |
| CVE-2026-58161 | 7.5 | high | apache / traffic server | Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. | 38d ago |
| CVE-2026-65324 | 7.5 | high | apache / traffic server | Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow c | 38d ago |
| CVE-2026-58151 | 7.5 | high | apache / traffic server | Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. | 38d ago |
| CVE-2026-59878 | 7.5 | high | apache / activemq | Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. | 39d ago |
| CVE-2026-58389 | 7.5 | high | apache / thrift | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. | 40d ago |