| CVE-2026-58162 | 10 | critical | apache / traffic server | The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. | 38d ago |
| CVE-2026-58150 | 10 | critical | apache / traffic server | Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. | 38d ago |
| CVE-2026-57834 | 10 | critical | apache / traffic server | Apache Traffic Server allows request smuggling if chunked messages are malformed. | 38d ago |
| CVE-2026-33267 | 10 | critical | apache / traffic server | Improper Input Validation vulnerability in Apache Traffic Server. | 38d ago |
| CVE-2026-65905 | 9.8 | critical | apache / tomcat | Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. | 11d ago |
| CVE-2026-65637 | 9.8 | critical | apache / tomcat | Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. | 11d ago |
| CVE-2026-49845 | 9.8 | critical | apache / hive | SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms | 11d ago |
| CVE-2026-78329 | 9.8 | critical | apache / camel | Improper input validation vulnerability in Apache Camel Undertow component. | 12d ago |
| CVE-2026-71300 | 9.8 | critical | apache / camel | Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. | 12d ago |
| CVE-2026-63039 | 9.8 | critical | apache / inlong | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLon | 16d ago |
| CVE-2026-63038 | 9.8 | critical | apache / inlong | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLon | 16d ago |
| CVE-2026-63037 | 9.8 | critical | apache / inlong | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLon | 16d ago |
| CVE-2026-34884 | 9.8 | critical | apache / skywalking mcp | SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. | 18d ago |
| CVE-2026-73240 | 9.8 | critical | apache / allura | Specifically crafted inputs may lead to git argument injection in Apache Allura. | 24d ago |
| CVE-2026-55799 | 9.8 | critical | apache / ranger | Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to | 26d ago |
| CVE-2026-44416 | 9.8 | critical | apache / ranger | Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2. | 26d ago |
| CVE-2026-42537 | 9.8 | critical | apache / ranger | Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version | 26d ago |
| CVE-2026-40920 | 9.8 | critical | apache / ranger | Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. | 26d ago |
| CVE-2026-32227 | 9.8 | critical | apache / ranger | SQL Injection vulnerability vulnerability in Apache Ranger. | 26d ago |
| CVE-2026-28672 | 9.8 | critical | apache / ranger | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger | 26d ago |
| CVE-2026-71558 | 9.8 | critical | apache / fory | Heap type confusion vulnerability in Apache Fory C++ deserialization. | 29d ago |
| CVE-2026-68079 | 9.8 | critical | apache / cxf | In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited numb | 30d ago |
| CVE-2026-66909 | 9.8 | critical | apache / cxf | Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserializatio | 30d ago |
| CVE-2026-61486 | 9.8 | critical | apache / lucy | ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. | 31d ago |
| CVE-2026-61484 | 9.8 | critical | apache / lucy | ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. | 31d ago |
| CVE-2026-68979 | 9.8 | critical | apache / nifi | Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authori | 33d ago |
| CVE-2026-66756 | 9.8 | critical | apache / tika | Improper Protection of Alternate Path vulnerability in Apache Tika. | 37d ago |
| CVE-2026-52680 | 9.8 | critical | apache / kyuubi | Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a tem | 37d ago |
| CVE-2026-28812 | 9.8 | critical | apache / jspwiki | UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escala | 37d ago |
| CVE-2026-59243 | 9.8 | critical | apache / apache-airflow-providers-fab | The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an a | 38d ago |
| CVE-2026-66713 | 9.8 | critical | apache / axis2\/java | Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation | 39d ago |
| CVE-2026-55971 | 9.8 | critical | apache / thrift | Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. | 40d ago |
| CVE-2026-64606 | 9.8 | critical | apache / fory | Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Jav | 46d ago |
| CVE-2026-64608 | 9.8 | critical | apache / fory | Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. | 46d ago |
| CVE-2026-63071 | 9.8 | critical | apache / syncope | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. | 47d ago |
| CVE-2026-62183 | 9.8 | critical | apache / syncope | Improper Privilege Management vulnerability in Apache Syncope. | 47d ago |
| CVE-2026-57308 | 9.8 | critical | apache / syncope | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Synco | 47d ago |
| CVE-2026-53421 | 9.8 | critical | apache / syncope | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. | 47d ago |
| CVE-2026-53405 | 9.8 | critical | apache / syncope | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. | 47d ago |
| CVE-2026-62392 | 9.8 | critical | apache / kylin | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache | 53d ago |
| CVE-2026-62390 | 9.8 | critical | apache / kylin | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin | 53d ago |
| CVE-2026-33264 | 9.8 | critical | apache / airflow | A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class pat | 60d ago |
| CVE-2026-56140 | 9.8 | critical | apache / camel | Improper Input Validation vulnerability in Apache Camel AWS SNS component. | 61d ago |
| CVE-2026-53913 | 9.8 | critical | apache / camel | Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulne | 61d ago |
| CVE-2026-48204 | 9.8 | critical | apache / camel | Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component | 61d ago |
| CVE-2026-46456 | 9.8 | critical | apache / camel | Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. | 61d ago |
| CVE-2026-46455 | 9.8 | critical | apache / camel | Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. | 61d ago |
| CVE-2026-46454 | 9.8 | critical | apache / camel | Improper Input Validation vulnerability in Apache Camel Cometd Component. | 61d ago |
| CVE-2026-43867 | 9.8 | critical | apache / camel | Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. | 61d ago |
| CVE-2026-24014 | 9.8 | critical | apache / iotdb | Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name t | 61d ago |
| CVE-2026-47898 | 9.8 | critical | apache / lucene.net | Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Comm | 64d ago |
| CVE-2026-32966 | 9.8 | critical | apache / dolphinscheduler | DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinSch | 80d ago |
| CVE-2026-50628 | 9.8 | critical | apache / cxf | A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blind | 85d ago |
| CVE-2026-49875 | 9.8 | critical | apache / cxf | Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the nec | 85d ago |
| CVE-2026-44631 | 9.8 | critical | apache / http server | Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. | 89d ago |
| CVE-2026-29167 | 9.8 | critical | apache / http server | Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects | 89d ago |
| CVE-2026-47065 | 9.8 | critical | apache / mina | ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: | 94d ago |
| CVE-2026-44930 | 9.8 | critical | apache / cxf | An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an a | 106d ago |
| CVE-2026-48207 | 9.8 | critical | apache / fory | Deserialization of untrusted data in Apache Fory PyFory. | 107d ago |
| CVE-2026-47323 | 9.8 | critical | apache / camel | Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilte | 109d ago |