55 Total CVEs
45 AI Analyzed
0 CISA KEV
18 Critical
All Vendors
Showing 1-55 of 55 CVEs
CVE-2026-22265
Analyzed
7.5
Apache Multiple Products

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers

2026-01-16
CVE-2026-22022
Analyzed
8.2
Apache Multiple Products

Deployments of Apache Solr 5

2026-01-22
CVE-2025-70841
Analyzed
10
Apache Multi-Tenancy Based eCommerce Platform SaaS

Dokans SaaS platform allows unauthenticated attackers to download the `.env` file, exposing encryption keys, database credentials, and API keys, leadi...

2026-02-04
CVE-2025-68675
Analyzed
7.5
Apache Multiple Products

In Apache Airflow versions before 3

2026-01-18
CVE-2025-68493
Analyzed
8.1
Apache Multiple Products

Missing XML Validation vulnerability in Apache Struts, Apache Struts

2026-01-13
CVE-2025-68438
Analyzed
7.5
Apache Multiple Products

In Apache Airflow versions before 3

2026-01-18
CVE-2025-67895
Analyzed
9.8
Apache Multiple Products

Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on A...

2025-12-18
CVE-2025-66675
8.2
Apache Multiple Products

Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion

2025-12-11
CVE-2025-66430
Analyzed
9.1
Apache Multiple Products

Plesk 18.0 has Incorrect Access Control.

2025-12-13
CVE-2025-66384
Analyzed
8.2
Apache Multiple Products

app/Controller/EventsController

2025-11-29
CVE-2025-66296
Analyzed
8.8
Apache Multiple Products

Grav is a file-based Web platform

2025-12-02
CVE-2025-65998
Analyzed
7.5
Apache Multiple Products

Apache Syncope can be configured to store the user password values in the internal database with AES encryption, though this is not the default option

2025-11-25
CVE-2025-64775
Analyzed
7.5
Apache Multiple Products

Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion

2025-12-02
CVE-2025-61735
Analyzed
7.3
Apache Multiple Products

Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin

2025-10-02
CVE-2025-61734
Analyzed
7.5
Apache Multiple Products

Files or Directories Accessible to External Parties vulnerability in Apache Kylin

2025-10-02
CVE-2025-61733
Analyzed
7.5
Apache Multiple Products

Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin

2025-10-02
CVE-2025-61581
Analyzed
7.5
Apache Multiple Products

** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control

2025-10-17
CVE-2025-60425
Analyzed
8.6
Apache Multiple Products

Nagios Fusion v2024R1

2025-10-27
CVE-2025-59932
Analyzed
8.6
Apache Multiple Products

Flag Forge is a Capture The Flag (CTF) platform

2025-09-28
CVE-2025-59789
Analyzed
7.5
Apache Multiple Products

Uncontrolled recursion in the json2pb component in Apache bRPC (version < 1

2025-12-02
CVE-2025-59390
Analyzed
9.8
Apache Multiple Products

Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is...

2025-11-27
CVE-2025-59118
7.3
Apache Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz

2025-11-14
CVE-2025-58137
Analyzed
8.1
Apache Multiple Products

Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract

2025-12-13
CVE-2025-58130
Analyzed
9.1
Apache Multiple Products

Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in vers...

2025-12-13
CVE-2025-58098
8.3
Apache Multiple Products

Apache HTTP Server 2

2025-12-06
CVE-2025-57738
Analyzed
7.2
Apache Multiple Products

Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few J...

2025-10-20
CVE-2025-56266
Analyzed
9.8
Apache Multiple Products

A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplying a crafted URL.

2025-09-08
CVE-2025-55754
Analyzed
9.6
Apache Multiple Products

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log mess...

2025-10-28
CVE-2025-55752
Analyzed
7.5
Apache Multiple Products

Relative Path Traversal vulnerability in Apache Tomcat

2025-10-27
CVE-2025-54988
Analyzed
9.8
Apache Multiple Products

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out...

2025-08-21
CVE-2025-54981
Analyzed
7.5
Apache Multiple Products

Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, includ...

2025-12-13
CVE-2025-54831
Analyzed
7.5
Apache Multiple Products

Apache Airflow 3 introduced a change to the handling of sensitive information in Connections

2025-09-26
CVE-2025-54539
Analyzed
9.8
Apache Multiple Products

A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ N...

2025-10-16
CVE-2025-54472
7.5
Apache Multiple Products

Unlimited memory allocation in redis protocol parser in Apache bRPC (all versions < 1

2025-08-14
CVE-2025-53833
Analyzed
10
Apache Multiple Products

LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior to 2.8.1 are vulnerable to Ser...

2025-07-14
CVE-2025-53689
Analyzed
8.8
Apache Multiple Products

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2

2025-07-14
CVE-2025-53606
Analyzed
9.8
Apache Multiple Products

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recomme...

2025-08-08
CVE-2025-53192
Analyzed
8.8
Apache Multiple Products

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons OGNL

2025-08-19
CVE-2025-52122
Analyzed
9.8
Apache Multiple Products

Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code...

2025-08-27
CVE-2025-48989
7.5
Apache Multiple Products

Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack

2025-08-14
CVE-2025-48913
Analyzed
9.8
Apache Multiple Products

If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capa...

2025-08-08
CVE-2025-48392
7.5
Apache Multiple Products

A vulnerability in Apache IoTDB

2025-09-24
CVE-2025-48208
8.8
Apache Multiple Products

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat

2025-09-10
CVE-2025-46295
Analyzed
9.8
Apache Multiple Products

Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the te...

2025-12-17
CVE-2025-40933
7.5
Apache Multiple Products

Apache::AuthAny::Cookie v0

2025-09-17
CVE-2025-30001
Analyzed
7.3
Apache Multiple Products

Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark

2025-10-10
CVE-2025-27821
Analyzed
7.3
Apache Multiple Products

Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client

2026-01-27
CVE-2025-26467
Analyzed
8.8
Apache Multiple Products

Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra

2025-08-25
CVE-2025-24404
8.8
Apache Multiple Products

XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat

2025-09-10
CVE-2025-15026
Analyzed
9.8
Apache Multiple Products

Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functional...

2026-01-06
CVE-2025-12543
Analyzed
9.6
Apache Multiple Products

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to pro...

2026-01-08
CVE-2024-48988
Analyzed
7.6
Apache Multiple Products

SQL Injection vulnerability in Apache StreamPark

2025-08-23
CVE-2024-43166
Analyzed
9.8
Apache Multiple Products

Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommen...

2025-09-03
CVE-2024-43115
8.8
Apache Multiple Products

Improper Input Validation vulnerability in Apache DolphinScheduler

2025-09-03
CVE-2016-15057
Analyzed
9.9
Apache Multiple Products

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum....

2026-01-27