[{"_id":"5f916f2a8ab7b2085d871cd9","ID":"CVE-2020-17515","title":"","state":"PUBLIC","updated":"2020-12-11T13:35:28.574Z","owner":"airflow"},{"_id":"5f91743d4f16541eef216883","ID":"CVE-2020-17511","title":"","state":"PUBLIC","updated":"2020-12-14T09:35:45.373Z","owner":"airflow"},{"_id":"5f9174624f16541eef216887","ID":"CVE-2020-17513","title":"","state":"PUBLIC","updated":"2020-12-14T09:36:02.746Z","owner":"airflow"},{"_id":"5f91e7eddb3965e63465d057","ID":"CVE-2020-17514","title":"disabled hostname verificiation","state":"PUBLIC","updated":"2021-05-27T12:07:40.403Z","owner":"fineract"},{"_id":"5f9424d0f8c222f0d4279ecc","ID":"CVE-2020-13959","title":"Velocity Tools XSS Vulnerability","state":"PUBLIC","updated":"2021-03-10T07:52:04.870Z","owner":"velocity"},{"_id":"5f942537f8c222f0d4279ed1","ID":"CVE-2020-13954","title":"Apache CXF Reflected XSS in the services listing page via the styleSheetPath","state":"PUBLIC","updated":"2020-11-12T12:45:31.751Z","owner":"cxf"},{"_id":"5f942587f8c222f0d4279ed4","ID":"CVE-2020-13950","title":"mod_proxy_http NULL pointer dereference","state":"PUBLIC","updated":"2021-06-10T07:00:03.831Z","owner":"httpd"},{"_id":"5fa93ec7a676dc9bb0b0aa0f","ID":"CVE-2020-13942","title":"Remote Code Execution in Apache Unomi","state":"PUBLIC","updated":"2020-11-24T17:55:44.282Z","owner":"unomi"},{"_id":"5fad2a3c6ae40c1ce527ae02","ID":"CVE-2020-17518","title":"Apache Flink directory traversal attack: remote file writing through the REST API","state":"PUBLIC","updated":"2021-01-05T11:32:09.849Z","owner":"flink"},{"_id":"5fad2a4e6ae40c1ce527ae04","ID":"CVE-2020-17519","title":"Apache Flink directory traversal attack: reading remote files through the REST API","state":"PUBLIC","updated":"2021-01-05T11:32:48.294Z","owner":"flink"},{"_id":"5fc651614433c10cd0d51f9f","ID":"CVE-2020-17525","title":"Remote unauthenticated denial-of-service in Subversion mod_authz_svn","state":"PUBLIC","updated":"2021-03-17T09:12:33.507Z","owner":"subversion"},{"_id":"5fc668d04433c10cd0d51fa1","ID":"CVE-2020-17526","title":"","state":"PUBLIC","updated":"2020-12-21T16:43:50.352Z","owner":"airflow"},{"_id":"5fc9230c4433c10cd0d51fa3","ID":"CVE-2020-17527","title":"Apache Tomcat: Request header mix-up between HTTP/2 streams","state":"PUBLIC","updated":"2020-12-03T18:25:33.380Z","owner":"tomcat"},{"_id":"5fc92e604433c10cd0d51fa7","ID":"CVE-2020-17529","title":"Apache NuttX (incubating) Out of Bound Write from invalid fragmentation offset value specified in the IP header","state":"PUBLIC","updated":"2020-12-09T16:35:02.859Z","owner":"nuttx"},{"_id":"5fc92e854433c10cd0d51faa","ID":"CVE-2020-17528","title":"Apache NuttX (incubating) Out of Bound Write from invalid TCP Urgent length","state":"PUBLIC","updated":"2020-12-09T16:34:56.566Z","owner":"nuttx"},{"_id":"5fce13294433c10cd0d51faf","ID":"CVE-2020-17531","title":"Deserialization flaw in EOL Tapestry 4.","state":"PUBLIC","updated":"2020-12-08T12:41:08.137Z","owner":"tapestry"},{"_id":"5fcf474d4433c10cd0d51fb7","ID":"CVE-2020-17532","title":"Apache ServiceComb Yaml remote deserialization vulnerability","state":"PUBLIC","updated":"2021-01-25T09:21:23.271Z","owner":"servicecomb"},{"_id":"5fd08f0a4433c10cd0d51fc3","ID":"CVE-2020-17533","title":"Apache Accumulo Improper Handling of Insufficient Permissions","state":"PUBLIC","updated":"2024-01-31T09:33:16.054Z","owner":"accumulo"},{"_id":"5fd720d89404c7ea0f4c44b8","ID":"CVE-2020-35451","title":"Oozie local privilege escalation","state":"PUBLIC","updated":"2021-03-09T15:14:53.244Z","owner":"oozie"},{"_id":"5fd76934348cf18d00b701bb","ID":"CVE-2020-35452","title":"mod_auth_digest possible stack overflow by one nul byte","state":"PUBLIC","updated":"2021-06-10T07:01:23.279Z","owner":"httpd"},{"_id":"5ff2d7ccdb734996b27a68a0","ID":"CVE-2021-21501","title":"ServiceComb ServiceCenter Directory Traversal","state":"PUBLIC","updated":"2021-08-10T09:15:53.939Z","owner":"servicecomb"},{"_id":"5ff3725ddb734996b27a68a1","ID":"CVE-2019-10095","title":"bash command injection in spark interpreter","state":"PUBLIC","updated":"2022-12-08T11:51:05.587Z","owner":"zeppelin"},{"_id":"5ff37273db734996b27a68a3","ID":"CVE-2019-17567","title":"mod_proxy_wstunnel tunneling of non Upgraded connections","state":"PUBLIC","updated":"2021-06-16T13:33:49.334Z","owner":"httpd"},{"_id":"5ff3728bdb734996b27a68a5","ID":"CVE-2020-1926","title":"Timing attack in Cookie signature verification","state":"PUBLIC","updated":"2021-03-16T12:44:51.635Z","owner":"hive"},{"_id":"5ff372bddb734996b27a68a7","ID":"CVE-2020-1936","title":"Stored XSS in Apache Ambari","state":"PUBLIC","updated":"2021-03-02T08:54:00.947Z","owner":"ambari"},{"_id":"5ff372d2db734996b27a68a9","ID":"CVE-2020-1946","title":"Apache SpamAssassin has an OS Command Injection vulnerability","state":"PUBLIC","updated":"2021-03-25T09:15:51.926Z","owner":"spamassassin"},{"_id":"5ff372e5db734996b27a68ab","ID":"CVE-2020-9493","title":"Java deserialization in Chainsaw","state":"PUBLIC","updated":"2021-06-16T07:28:39.802Z","owner":"logging"},{"_id":"5ff37361db734996b27a68b5","ID":"CVE-2020-13929","title":"Notebook permissions bypass","state":"PUBLIC","updated":"2021-09-02T16:10:15.351Z","owner":"zeppelin"},{"_id":"5ff37389db734996b27a68b9","ID":"CVE-2020-13936","title":"Velocity Sandbox Bypass","state":"PUBLIC","updated":"2021-03-10T07:51:18.089Z","owner":"velocity"},{"_id":"5ff3739cdb734996b27a68bb","ID":"CVE-2020-13938","title":"Improper Handling of Insufficient Privileges","state":"PUBLIC","updated":"2021-06-10T06:59:41.634Z","owner":"httpd"},{"_id":"5ff373b4db734996b27a68bd","ID":"CVE-2020-13947","title":"","state":"PUBLIC","updated":"2021-02-10T09:16:00.641Z","owner":"activemq"},{"_id":"5ff373e2db734996b27a68c1","ID":"CVE-2020-17517","title":"Ozone S3 Gateway allows bucket and key access to non authenticated users ","state":"PUBLIC","updated":"2021-04-27T16:36:35.505Z","owner":"ozone"},{"_id":"5ff43c4ddb734996b27a68c7","ID":"CVE-2021-22160","title":"Authentication with JWT allows use of “none”-algorithm","state":"PUBLIC","updated":"2021-05-25T13:39:14.223Z","owner":"pulsar"},{"_id":"5ff59365db734996b27a68ce","ID":"CVE-2021-22696","title":"OAuth 2 authorization service vulnerable to DDos attacks","state":"PUBLIC","updated":"2021-04-02T09:58:49.120Z","owner":"cxf"},{"_id":"5ffc172adb734996b27a68cf","ID":"CVE-2020-13922","title":"Apache DolphinScheduler (incubating) Permission vulnerability","state":"PUBLIC","updated":"2021-01-11T09:18:42.255Z","owner":"dolphinscheduler"},{"_id":"5ffc1863db734996b27a68d2","ID":"CVE-2020-11995","title":"Apache Dubbo default deserialization protocol Hessian2 cause CRE","state":"PUBLIC","updated":"2021-01-11T09:22:59.963Z","owner":"dubbo"},{"_id":"5ffc1a01db734996b27a68d5","ID":"CVE-2020-17508","title":"Apache Traffic Server ESI plugin has a memory disclosure vulnerability","state":"PUBLIC","updated":"2021-01-11T09:27:29.639Z","owner":"trafficserver"},{"_id":"5ffc1abfdb734996b27a68d7","ID":"CVE-2020-17509","title":"Apache Traffic Server negative cache option is vulnerable to a cache poisoning attack","state":"PUBLIC","updated":"2021-01-11T09:31:44.280Z","owner":"trafficserver"},{"_id":"5ffc2d7fdb734996b27a68db","ID":"CVE-2020-9479","title":"unzip directory traversal","state":"PUBLIC","updated":"2021-03-01T15:49:19.297Z","owner":"asterixdb"},{"_id":"5ffd60aedb734996b27a68df","ID":"CVE-2021-23901","title":"An XML external entity (XXE) injection vulnerability exists in the Nutch DmozParser","state":"PUBLIC","updated":"2021-01-25T09:22:41.311Z","owner":"nutch"},{"_id":"5ffe089ddb734996b27a68e0","ID":"CVE-2021-23926","title":"XMLBeans XML Entity Expansion","state":"PUBLIC","updated":"2021-01-14T14:45:47.410Z","owner":"poi"},{"_id":"5ffeee78db734996b27a68e3","ID":"CVE-2021-23937","title":"DNS proxy and possible amplification attack","state":"PUBLIC","updated":"2021-05-25T08:01:09.799Z","owner":"wicket"},{"_id":"600045b3db734996b27a68eb","ID":"CVE-2021-24122","title":"Apache Tomcat information disclosure","state":"PUBLIC","updated":"2021-01-14T14:26:04.037Z","owner":"tomcat"},{"_id":"60007578db734996b27a68f1","ID":"CVE-2021-25122","title":"Apache Tomcat h2c request mix-up","state":"PUBLIC","updated":"2021-03-01T11:12:28.219Z","owner":"tomcat"},{"_id":"600714c4db734996b27a68f8","ID":"CVE-2021-25329","title":"Incomplete fix for CVE-2020-9484","state":"PUBLIC","updated":"2021-03-01T12:01:51.094Z","owner":"tomcat"},{"_id":"6007e2e5db734996b27a68f9","ID":"CVE-2021-25640","title":"Open Redirect or SSRF vulnerability usage of parseURL","state":"PUBLIC","updated":"2021-05-31T07:23:34.814Z","owner":"dubbo"},{"_id":"6007f07adb734996b27a68fa","ID":"CVE-2021-25641","title":"Dubbo Zookeeper does not check serialization id","state":"PUBLIC","updated":"2021-05-29T07:21:43.205Z","owner":"dubbo"},{"_id":"60081236db734996b27a68fb","ID":"CVE-2021-25642","title":"Apache Hadoop YARN remote code execution in ZKConfigurationStore of capacity scheduler","state":"PUBLIC","updated":"2022-08-25T13:21:18.013Z","owner":"hadoop"},{"_id":"60093d99db734996b27a68ff","ID":"CVE-2021-25646","title":"Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.","state":"PUBLIC","updated":"2021-01-29T19:09:31.597Z","owner":"druid"},{"_id":"600f052cdb734996b27a690a","ID":"CVE-2021-26117","title":"ActiveMQ: LDAP-Authentication does not verify passwords on servers with anonymous bind","state":"PUBLIC","updated":"2021-01-27T18:47:20.605Z","owner":"activemq"},{"_id":"600f0543db734996b27a690b","ID":"CVE-2021-26118","title":"Flaw in ActiveMQ Artemis OpenWire support","state":"PUBLIC","updated":"2021-01-27T18:47:25.710Z","owner":"activemq"},{"_id":"6011d366db734996b27a6927","ID":"CVE-2021-26291","title":"block repositories using http by default","state":"PUBLIC","updated":"2021-04-23T14:14:28.607Z","owner":"maven"},{"_id":"6012b6d3db734996b27a6928","ID":"CVE-2021-26295","title":"RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI","state":"PUBLIC","updated":"2021-03-22T11:54:40.746Z","owner":"ofbiz"},{"_id":"6012c416db734996b27a6929","ID":"CVE-2021-26296","title":"Cross-Site Request Forgery (CSRF) vulnerability in Apache MyFaces","state":"PUBLIC","updated":"2021-02-19T08:27:26.368Z","owner":"myfaces"},{"_id":"601516dc39cecf72e826bf3e","ID":"CVE-2021-26461","title":"malloc, realloc and memalign implementations are vulnerable to integer wrap-arounds","state":"PUBLIC","updated":"2021-06-21T17:05:46.935Z","owner":"nuttx"},{"_id":"6017dc6a39cecf72e826bf45","ID":"CVE-2021-26544","title":"Apache Livy (Incubating) is vulnerable to cross site scripting","state":"PUBLIC","updated":"2021-02-20T08:56:02.977Z","owner":"livy"},{"_id":"6019113339cecf72e826bf4a","ID":"CVE-2021-26558","title":"Deserialization of Untrusted Data","state":"PUBLIC","updated":"2021-11-11T09:28:11.863Z","owner":"shardingsphere"},{"_id":"60192e9d39cecf72e826bf4b","ID":"CVE-2021-26559","title":"CWE-284 Improper Access Control on Configurations Endpoint for the Stable API","state":"PUBLIC","updated":"2021-02-17T13:18:02.283Z","owner":"airflow"},{"_id":"601be05b39cecf72e826bf4c","ID":"CVE-2021-26690","title":"mod_session NULL pointer dereference","state":"PUBLIC","updated":"2021-06-10T07:01:40.445Z","owner":"httpd"},{"_id":"601c0e5239cecf72e826bf4d","ID":"CVE-2021-26691","title":"Apache HTTP Server mod_session response handling heap overflow","state":"PUBLIC","updated":"2021-06-10T07:01:56.009Z","owner":"httpd"},{"_id":"601c3cc039cecf72e826bf4e","ID":"CVE-2021-26697","title":"Apache Airflow: Lineage API endpoint for Experimental API missed authentication check","state":"PUBLIC","updated":"2021-02-17T14:10:43.736Z","owner":"airflow"},{"_id":"60223e8b76453dc6f8fb0823","ID":"CVE-2021-26919","title":"Apache Druid Authenticated users can execute arbitrary code from malicious MySQL database systems.","state":"PUBLIC","updated":"2021-03-30T07:47:52.941Z","owner":"druid"},{"_id":"60223eea76453dc6f8fb0824","ID":"CVE-2021-26920","title":"Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended","state":"PUBLIC","updated":"2021-07-02T07:14:27.176Z","owner":"druid"},{"_id":"6034c7e770f92c039bbba762","ID":"CVE-2021-27576","title":"Apache OpenMeetings: bandwidth can be overloaded with public web service","state":"PUBLIC","updated":"2021-03-14T11:56:54.481Z","owner":"openmeetings"},{"_id":"6034cb3770f92c039bbba763","ID":"CVE-2021-27577","title":"Incorrect handling of url fragment leads to cache poisoning","state":"PUBLIC","updated":"2021-06-28T17:28:40.345Z","owner":"trafficserver"},{"_id":"6034ce7a70f92c039bbba764","ID":"CVE-2021-27578","title":"Cross Site Scripting in markdown interpreter","state":"PUBLIC","updated":"2021-09-02T16:11:07.660Z","owner":"zeppelin"},{"_id":"6036044a70f92c039bbba76b","ID":"CVE-2021-27644","title":"DolphinScheduler mysql jdbc connector parameters deserialize remote code execution","state":"PUBLIC","updated":"2021-11-01T09:12:08.670Z","owner":"dolphinscheduler"},{"_id":"6038aafa70f92c039bbba76c","ID":"CVE-2021-27737","title":"slicer plugin crash","state":"PUBLIC","updated":"2021-05-17T17:41:59.734Z","owner":"trafficserver"},{"_id":"6038ac6570f92c039bbba76d","ID":"CVE-2021-27738","title":"Improper Access Control to Streaming Coordinator & SSRF","state":"PUBLIC","updated":"2022-01-06T12:26:35.086Z","owner":"kylin"},{"_id":"603bbe0870f92c039bbba771","ID":"CVE-2021-27807","title":"A carefully crafted PDF file can trigger an infinite loop while loading the file","state":"PUBLIC","updated":"2021-03-19T16:02:02.671Z","owner":"pdfbox"},{"_id":"603d06fd70f92c039bbba77b","ID":"CVE-2021-27850","title":"Bypass of the fix for CVE-2019-0195","state":"PUBLIC","updated":"2021-04-15T07:35:21.760Z","owner":"tapestry"},{"_id":"603df9d470f92c039bbba782","ID":"CVE-2021-27905","title":"SSRF vulnerability with the Replication handler","state":"PUBLIC","updated":"2021-04-13T06:30:52.402Z","owner":"solr"},{"_id":"603e25f39184c6be36e199c7","ID":"CVE-2021-27906","title":"A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file","state":"PUBLIC","updated":"2021-03-19T16:03:06.161Z","owner":"pdfbox"},{"_id":"603e58269184c6be36e199c8","ID":"CVE-2021-27907","title":"Apache Superset stored XSS on Dashboard markdown","state":"PUBLIC","updated":"2021-03-05T11:29:37.298Z","owner":"superset"},{"_id":"6048913669f58354e0a8c2ca","ID":"CVE-2021-28125","title":"Apache Superset Open Redirect ","state":"PUBLIC","updated":"2021-04-27T09:22:22.370Z","owner":"superset"},{"_id":"6048ed8f69f58354e0a8c2cb","ID":"CVE-2021-28129","title":"DEB packaging for Apache OpenOffice 4.1.8 installed with a non-root userid and groupid","state":"PUBLIC","updated":"2021-10-07T15:24:31.592Z","owner":"openoffice"},{"_id":"6048f35769f58354e0a8c2cc","ID":"CVE-2021-28131","title":"Impala logs contain secrets","state":"PUBLIC","updated":"2021-07-22T09:44:57.855Z","owner":"impala"},{"_id":"604c6a1669f58354e0a8c2cf","ID":"CVE-2021-28359","title":"Apache Airflow Reflected XSS via Origin Query Argument in URL","state":"PUBLIC","updated":"2021-05-02T07:52:16.051Z","owner":"airflow"},{"_id":"6050c49a69f58354e0a8c2db","ID":"CVE-2021-28544","title":"Apache Subversion SVN authz protected copyfrom paths regression","state":"PUBLIC","updated":"2022-04-12T17:46:18.140Z","owner":"subversion"},{"_id":"6051bdd669f58354e0a8c2de","ID":"CVE-2021-28657","title":"Infinite loop in Apache Tika's MP3 parser","state":"PUBLIC","updated":"2021-03-31T07:34:07.284Z","owner":"tika"},{"_id":"6051c4df69f58354e0a8c2df","ID":"CVE-2020-13924","title":"","state":"PUBLIC","updated":"2021-03-17T09:01:22.529Z","owner":"ambari"},{"_id":"605c8fbf69f58354e0a8c30a","ID":"CVE-2021-29200","title":"RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI","state":"PUBLIC","updated":"2021-04-27T19:46:30.140Z","owner":"ofbiz"},{"_id":"605daff269f58354e0a8c30b","ID":"CVE-2021-29262","title":"Misapplied Zookeeper ACLs can result in leakage of configured authentication and authorization settings","state":"PUBLIC","updated":"2021-04-13T06:28:50.304Z","owner":"solr"},{"_id":"6062f69269f58354e0a8c322","ID":"CVE-2021-29425","title":"Possible limited path traversal vulnerabily in Apache Commons IO ","state":"PUBLIC","updated":"2021-04-13T06:36:54.192Z","owner":"commons"},{"_id":"6065846169f58354e0a8c32a","ID":"CVE-2021-29943","title":"Apache Solr Unprivileged users may be able to perform unauthorized read/write to collections","state":"PUBLIC","updated":"2021-04-13T06:29:18.585Z","owner":"solr"},{"_id":"606ae0503c82c956251187ea","ID":"CVE-2021-30128","title":"Unsafe deserialization in Apache OFBiz","state":"PUBLIC","updated":"2021-04-27T19:47:04.244Z","owner":"ofbiz"},{"_id":"606ae8cb3c82c956251187eb","ID":"CVE-2021-30129","title":"DoS/OOM leak vulnerability in Apache Mina SSHD Server","state":"PUBLIC","updated":"2021-07-12T12:00:59.616Z","owner":"mina"},{"_id":"606d5a014d908eaf24043e48","ID":"CVE-2021-30179","title":"Apache Dubbo Pre-auth RCE via Java deserialization in the Generic filter","state":"PUBLIC","updated":"2021-05-31T07:20:28.079Z","owner":"dubbo"},{"_id":"606d5a2d4d908eaf24043e49","ID":"CVE-2021-30180","title":"Apache Dubbo RCE on customers via Condition route poisoning (Unsafe YAML unmarshaling)","state":"PUBLIC","updated":"2021-05-31T07:21:55.266Z","owner":"dubbo"},{"_id":"606d5a664d908eaf24043e4a","ID":"CVE-2021-30181","title":"Apache Dubbo RCE on customers via Script route poisoning (Nashorn script injection)","state":"PUBLIC","updated":"2021-05-29T07:19:20.347Z","owner":"dubbo"},{"_id":"606e0a514d908eaf24043e4d","ID":"CVE-2021-30245","title":"Code execution in Apache OpenOffice via non-http(s) schemes in Hyperlinks","state":"PUBLIC","updated":"2021-04-15T19:28:07.363Z","owner":"openoffice"},{"_id":"606f40ad4d908eaf24043e51","ID":"CVE-2021-30468","title":"Apache CXF Denial of service vulnerability in parsing JSON via JsonMapObjectReaderWriter","state":"PUBLIC","updated":"2021-06-16T11:56:32.302Z","owner":"cxf"},{"_id":"60753b944d908eaf24043e63","ID":"CVE-2021-30638","title":"An Information Disclosure due to insufficient input validation exists in Apache Tapestry 5.4.0 and later","state":"PUBLIC","updated":"2021-04-27T18:27:24.498Z","owner":"tapestry"},{"_id":"6075bd1a4d908eaf24043e65","ID":"CVE-2021-30639","title":"DoS after non-blocking IO error","state":"PUBLIC","updated":"2021-07-12T13:20:34.738Z","owner":"tomcat"},{"_id":"6075bd644d908eaf24043e67","ID":"CVE-2021-30640","title":"Auth weakness in JNDIRealm","state":"PUBLIC","updated":"2021-07-12T13:14:16.116Z","owner":"tomcat"},{"_id":"6075dcf54d908eaf24043e69","ID":"CVE-2021-30641","title":"Unexpected URL matching with 'MergeSlashes OFF'","state":"PUBLIC","updated":"2021-06-10T07:02:16.829Z","owner":"httpd"},{"_id":"6076a5054d908eaf24043e6b","ID":"CVE-2021-31164","title":"Apache Unomi log injection","state":"PUBLIC","updated":"2021-05-04T06:40:34.093Z","owner":"unomi"},{"_id":"60801c787aaefbf622e0a994","ID":"CVE-2021-31522","title":"Apache Kylin unsafe class loading","state":"PUBLIC","updated":"2022-01-06T12:28:58.641Z","owner":"kylin"},{"_id":"608272b77aaefbf622e0a997","ID":"CVE-2021-31618","title":"NULL pointer dereference on specially crafted HTTP/2 request","state":"PUBLIC","updated":"2021-06-15T08:48:10.111Z","owner":"httpd"},{"_id":"6086a5727aaefbf622e0a9a1","ID":"CVE-2021-31805","title":"Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.","state":"PUBLIC","updated":"2022-04-12T15:23:33.186Z","owner":"struts"},{"_id":"6086ed3b7aaefbf622e0a9a5","ID":"CVE-2021-31811","title":"A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading a tiny file","state":"PUBLIC","updated":"2021-06-12T09:40:36.582Z","owner":"pdfbox"},{"_id":"6086ed467aaefbf622e0a9a6","ID":"CVE-2021-31812","title":"A carefully crafted PDF file can trigger an infinite loop while loading the file","state":"PUBLIC","updated":"2021-06-12T09:40:30.803Z","owner":"pdfbox"},{"_id":"609a588f7aaefbf622e0a9ce","ID":"CVE-2021-32565","title":"HTTP Request Smuggling, content length with invalid charters","state":"PUBLIC","updated":"2021-06-28T17:31:31.239Z","owner":"trafficserver"},{"_id":"609a58a27aaefbf622e0a9cf","ID":"CVE-2021-32566","title":"Specific sequence of HTTP/2 frames can cause ATS to crash","state":"PUBLIC","updated":"2021-06-30T07:11:47.425Z","owner":"trafficserver"},{"_id":"609a58b57aaefbf622e0a9d0","ID":"CVE-2021-32567","title":"Reading HTTP/2 frames too many times","state":"PUBLIC","updated":"2021-06-30T07:12:25.231Z","owner":"trafficserver"},{"_id":"609beade7aaefbf622e0a9d5","ID":"CVE-2021-32609","title":"XSS vulnerability on Explore page","state":"PUBLIC","updated":"2021-10-15T15:41:12.188Z","owner":"superset"},{"_id":"609fdea17aaefbf622e0a9d7","ID":"CVE-2021-33035","title":"Buffer overflow from a crafted DBF file","state":"PUBLIC","updated":"2021-10-07T15:21:31.403Z","owner":"openoffice"},{"_id":"60a22a3a7aaefbf622e0a9d8","ID":"CVE-2021-33036","title":"Apache Hadoop Privilege escalation vulnerability","state":"PUBLIC","updated":"2022-06-15T14:23:07.883Z","owner":"hadoop"},{"_id":"60a279277aaefbf622e0a9db","ID":"CVE-2021-33037","title":"Incorrect Transfer-Encoding handling with HTTP/1.0","state":"PUBLIC","updated":"2021-07-12T13:31:58.821Z","owner":"tomcat"},{"_id":"60a4b9ec7aaefbf622e0a9e0","ID":"CVE-2021-33190","title":"Bypass network access control","state":"PUBLIC","updated":"2021-06-08T15:01:51.802Z","owner":"apisix"},{"_id":"60a4feaf7aaefbf622e0a9e1","ID":"CVE-2021-33191","title":"MiNiFi CPP arbitrary script execution is possible on the agent's host machine through the c2 protocol","state":"PUBLIC","updated":"2021-08-24T11:14:05.278Z","owner":"nifi"},{"_id":"60a4ff7f7aaefbf622e0a9e2","ID":"CVE-2021-33192","title":"Display information UI XSS","state":"PUBLIC","updated":"2021-07-05T09:09:33.148Z","owner":"jena"},{"_id":"60a500d17aaefbf622e0a9e3","ID":"CVE-2021-33193","title":"Request splitting via HTTP/2 method injection and mod_proxy","state":"PUBLIC","updated":"2021-09-16T12:49:38.115Z","owner":"httpd"},{"_id":"60ae36a57aaefbf622e0aa03","ID":"CVE-2021-33580","title":"regex injection leading to DoS","state":"PUBLIC","updated":"2021-08-18T07:43:44.770Z","owner":"roller"},{"_id":"60bdda7b7aaefbf622e0aa20","ID":"CVE-2021-33900","title":"StartTLS and SASL confidentiality protection bypass","state":"PUBLIC","updated":"2021-07-26T07:00:11.196Z","owner":"directory"},{"_id":"60c1bbe87aaefbf622e0aa4e","ID":"CVE-2021-34538","title":"Apache Hive Security vulnerability in Hive with UDFs","state":"PUBLIC","updated":"2022-07-16T07:05:22.225Z","owner":"hive"},{"_id":"60c8e161f36d8a143cb47393","ID":"CVE-2021-34797","title":"Apache Geode log file redaction of sensitive information vulnerability","state":"PUBLIC","updated":"2022-06-28T22:46:44.541Z","owner":"geode"},{"_id":"60c9a752f36d8a143cb47396","ID":"CVE-2021-34798","title":"NULL pointer dereference in httpd core","state":"PUBLIC","updated":"2021-09-16T14:31:21.975Z","owner":"httpd"},{"_id":"60d429e7a1eac7365caac7ab","ID":"CVE-2021-35474","title":"Dynamic stack buffer overflow in cachekey plugin","state":"PUBLIC","updated":"2021-06-30T07:12:52.360Z","owner":"trafficserver"},{"_id":"60d8a685a1eac7365caac7b2","ID":"CVE-2021-35515","title":"Apache Commons Compress 1.6 to 1.20 denial of service vulnerability","state":"PUBLIC","updated":"2021-07-13T07:11:36.980Z","owner":"commons"},{"_id":"60d8a690a1eac7365caac7b3","ID":"CVE-2021-35516","title":"Apache Commons Compress 1.6 to 1.20 denial of service vulnerability","state":"PUBLIC","updated":"2021-07-13T07:11:43.957Z","owner":"commons"},{"_id":"60d8a69ca1eac7365caac7b4","ID":"CVE-2021-35517","title":"Apache Commons Compress 1.1 to 1.20 denial of service vulnerability","state":"PUBLIC","updated":"2021-07-13T07:11:53.430Z","owner":"commons"},{"_id":"60db00d5952506e224a8b7ba","ID":"CVE-2021-35936","title":"No Authentication on Logging Server","state":"PUBLIC","updated":"2021-08-16T07:22:38.757Z","owner":"airflow"},{"_id":"60db35b2952506e224a8b7bb","ID":"CVE-2021-35940","title":"Regression of CVE-2017-12613","state":"PUBLIC","updated":"2021-10-11T14:15:55.651Z","owner":"apr"},{"_id":"60dd6f5a952506e224a8b7c8","ID":"CVE-2021-36090","title":"Apache Commons Compress 1.0 to 1.20 denial of service vulnerability","state":"PUBLIC","updated":"2021-07-13T07:12:34.084Z","owner":"commons"},{"_id":"60e2d69c952506e224a8b7e2","ID":"CVE-2021-36151","title":"Local Credentials Disclosure Vulnerability","state":"PUBLIC","updated":"2022-02-03T18:29:46.145Z","owner":"gobblin"},{"_id":"60e2d6ca952506e224a8b7e3","ID":"CVE-2021-36152","title":"Insecure TrustManager used in LDAP connections","state":"PUBLIC","updated":"2022-02-03T18:26:12.111Z","owner":"gobblin"},{"_id":"60e40e60952506e224a8b7e4","ID":"CVE-2021-36160","title":"mod_proxy_uwsgi out of bound read","state":"PUBLIC","updated":"2021-09-16T14:33:49.077Z","owner":"httpd"},{"_id":"60e42e2a952506e224a8b7e5","ID":"CVE-2021-36161","title":"Unprotected input value toString cause RCE","state":"PUBLIC","updated":"2021-09-09T07:39:17.113Z","owner":"dubbo"},{"_id":"60e43b74952506e224a8b7e6","ID":"CVE-2021-36162","title":"Unprotected yaml deserialization cause RCE","state":"PUBLIC","updated":"2021-09-07T09:20:04.687Z","owner":"dubbo"},{"_id":"60e43c1b952506e224a8b7e7","ID":"CVE-2021-36163","title":"Unsafe deserialization in providers using the Hessian protocol","state":"PUBLIC","updated":"2021-09-07T09:21:20.469Z","owner":"dubbo"},{"_id":"60ebe72a952506e224a8b7e8","ID":"CVE-2021-36372","title":"Original block tokens are persisted and can be retrieved","state":"PUBLIC","updated":"2024-01-31T09:17:30.555Z","owner":"ozone"},{"_id":"60ec263e952506e224a8b7ed","ID":"CVE-2021-36373","title":"Apache Ant TAR archive denial of service vulnerability","state":"PUBLIC","updated":"2021-07-14T06:08:32.303Z","owner":"ant"},{"_id":"60ec2643952506e224a8b7ee","ID":"CVE-2021-36374","title":"Apache Ant ZIP, and ZIP based, archive denial of service vulnerability","state":"PUBLIC","updated":"2021-07-19T07:37:04.488Z","owner":"ant"},{"_id":"60ee7e4d04911e417e43a0d0","ID":"CVE-2021-36737","title":"XSS in V3 Demo Portlet","state":"PUBLIC","updated":"2022-01-06T08:47:29.193Z","owner":"portals"},{"_id":"60ee7e9f04911e417e43a0d1","ID":"CVE-2021-36738","title":"XSS vulnerability in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet","state":"PUBLIC","updated":"2022-01-06T08:48:04.239Z","owner":"portals"},{"_id":"60ee7ed504911e417e43a0d2","ID":"CVE-2021-36739","title":"XSS vulnerability in the MVCBean JSP portlet maven archetype","state":"PUBLIC","updated":"2022-01-06T08:48:42.463Z","owner":"portals"},{"_id":"60efe46104911e417e43a0d5","ID":"CVE-2021-36749","title":"Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920)","state":"PUBLIC","updated":"2021-09-23T23:08:21.915Z","owner":"druid"},{"_id":"60f520aa41b4a02dbbfea1a7","ID":"CVE-2021-36774","title":"Mysql JDBC Connector Deserialize RCE","state":"PUBLIC","updated":"2022-01-06T12:29:47.699Z","owner":"kylin"},{"_id":"60f7c3b141b4a02dbbfea1ad","ID":"CVE-2021-37147","title":"Request Smuggling - LF line ending","state":"PUBLIC","updated":"2021-11-02T21:14:21.298Z","owner":"trafficserver"},{"_id":"60f7c3b941b4a02dbbfea1ae","ID":"CVE-2021-37148","title":"Request Smuggling - transfer encoding validation","state":"PUBLIC","updated":"2021-11-02T21:14:46.545Z","owner":"trafficserver"},{"_id":"60f7c3c441b4a02dbbfea1af","ID":"CVE-2021-37149","title":"Request Smuggling - multiple attacks","state":"PUBLIC","updated":"2021-11-02T21:15:10.588Z","owner":"trafficserver"},{"_id":"60f7c3cf41b4a02dbbfea1b0","ID":"CVE-2021-37150","title":"Protocol vs scheme mismatch","state":"PUBLIC","updated":"2022-08-10T05:43:13.024Z","owner":"trafficserver"},{"_id":"60fa604041b4a02dbbfea1b5","ID":"CVE-2021-37404","title":"Heap buffer overflow in libhdfs native library","state":"PUBLIC","updated":"2022-06-13T06:58:30.060Z","owner":"hadoop"},{"_id":"60feab8441b4a02dbbfea1b9","ID":"CVE-2021-37533","title":"Apache Commons Net's FTP client trusts the host from PASV response by default","state":"PUBLIC","updated":"2022-12-03T14:53:25.293Z","owner":"commons"},{"_id":"60ffb00d41b4a02dbbfea1ba","ID":"CVE-2021-37578","title":"Remote code execution via RMI","state":"PUBLIC","updated":"2021-07-29T06:57:59.880Z","owner":"juddi"},{"_id":"60ffb17541b4a02dbbfea1bb","ID":"CVE-2021-37579","title":"Bypass deserialization checks in Apache Dubbo","state":"PUBLIC","updated":"2021-09-09T07:40:35.954Z","owner":"dubbo"},{"_id":"60ffebe241b4a02dbbfea1bc","ID":"CVE-2021-37580","title":"Apache ShenYu Admin bypass JWT authentication","state":"PUBLIC","updated":"2021-11-16T09:33:35.582Z","owner":"shenyu"},{"_id":"610254010fd38cd2922e380d","ID":"CVE-2021-37608","title":"Arbitrary file upload vulnerability in OFBiz","state":"PUBLIC","updated":"2021-08-18T07:45:08.867Z","owner":"ofbiz"},{"_id":"61079e5f0fd38cd2922e380e","ID":"CVE-2021-37839","title":"Improper access to dataset metadata information ","state":"PUBLIC","updated":"2022-07-06T12:31:11.639Z","owner":"superset"},{"_id":"610d52e70fd38cd2922e3817","ID":"CVE-2021-38153","title":"Timing Attack Vulnerability for Apache Kafka Connect and Clients","state":"PUBLIC","updated":"2021-09-22T08:43:16.777Z","owner":"kafka"},{"_id":"610e3b870fd38cd2922e3822","ID":"CVE-2021-38161","title":"Not validating origin TLS certificate","state":"PUBLIC","updated":"2021-11-02T21:16:04.785Z","owner":"trafficserver"},{"_id":"6110d0670fd38cd2922e3823","ID":"CVE-2021-38294","title":"Shell Command Injection Vulnerability in Nimbus Thrift Server","state":"PUBLIC","updated":"2021-10-21T22:16:43.838Z","owner":"storm"},{"_id":"611105a80fd38cd2922e3824","ID":"CVE-2021-38295","title":"Privilege escalation vulnerability when using HTML attachments","state":"PUBLIC","updated":"2021-10-14T16:26:03.894Z","owner":"couchdb"},{"_id":"61113a4f777cafde93e543a7","ID":"CVE-2021-38296","title":"Apache Spark Key Negotiation Vulnerability","state":"PUBLIC","updated":"2022-03-10T08:16:48.042Z","owner":"spark"},{"_id":"611375d5777cafde93e543af","ID":"CVE-2021-38540","title":"Apache Airflow: Variable Import endpoint missed authentication check","state":"PUBLIC","updated":"2021-09-09T14:59:44.637Z","owner":"airflow"},{"_id":"6113e491777cafde93e543b0","ID":"CVE-2021-38542","title":"Apache James vulnerable to STARTTLS command injection (IMAP and POP3)","state":"PUBLIC","updated":"2022-01-04T08:46:18.750Z","owner":"james"},{"_id":"6114007e777cafde93e543b2","ID":"CVE-2021-38555","title":"An XML external entity (XXE) injection vulnerability exists in Apache Any23 StreamUtils.java","state":"PUBLIC","updated":"2021-09-11T10:55:48.141Z","owner":"any23"},{"_id":"611b7e48777cafde93e543d2","ID":"CVE-2021-39231","title":"Missing authentication/authorization on internal RPC endpoints","state":"PUBLIC","updated":"2021-11-19T09:07:59.940Z","owner":"ozone"},{"_id":"611b8019777cafde93e543d7","ID":"CVE-2021-39232","title":"Missing admin check for SCM related admin commands","state":"PUBLIC","updated":"2021-11-19T09:09:30.310Z","owner":"ozone"},{"_id":"611b80b2777cafde93e543db","ID":"CVE-2021-39233","title":"Container-related datanode operations can be called without authorization","state":"PUBLIC","updated":"2021-11-19T09:10:07.173Z","owner":"ozone"},{"_id":"611b814b777cafde93e543dd","ID":"CVE-2021-39234","title":"Raw block data can be read bypassing ACL/authorization","state":"PUBLIC","updated":"2021-11-19T09:10:52.636Z","owner":"ozone"},{"_id":"611b81ef777cafde93e543df","ID":"CVE-2021-39235","title":"Access mode of block tokens are not enforced","state":"PUBLIC","updated":"2021-11-19T09:11:44.999Z","owner":"ozone"},{"_id":"611b824d777cafde93e543e2","ID":"CVE-2021-39236","title":"Owners of the S3 tokens are not validated","state":"PUBLIC","updated":"2021-11-19T09:13:11.634Z","owner":"ozone"},{"_id":"611bcd70777cafde93e543f1","ID":"CVE-2021-39239","title":"XML External Entity (XXE) vulnerability","state":"PUBLIC","updated":"2021-09-16T14:16:06.658Z","owner":"jena"},{"_id":"611d18a7777cafde93e543fb","ID":"CVE-2021-39275","title":"ap_escape_quotes buffer overflow","state":"PUBLIC","updated":"2021-09-16T14:35:11.663Z","owner":"httpd"},{"_id":"6125f54c777cafde93e54415","ID":"CVE-2021-40110","title":"Apache James IMAP vulnerable to a ReDoS","state":"PUBLIC","updated":"2022-01-04T08:47:33.579Z","owner":"james"},{"_id":"6125f554777cafde93e54416","ID":"CVE-2021-40111","title":"Apache James IMAP parsing Denial Of Service","state":"PUBLIC","updated":"2022-01-04T08:48:24.795Z","owner":"james"},{"_id":"6127463f777cafde93e54420","ID":"CVE-2021-40146","title":"A Remote Code Execution (RCE) vulnerability exists in Apache Any23 YAMLExtractor.java","state":"PUBLIC","updated":"2021-09-11T10:59:07.858Z","owner":"any23"},{"_id":"612f992f777cafde93e54443","ID":"CVE-2021-40369","title":"XSS vulnerability on Denounce plugin","state":"PUBLIC","updated":"2021-11-23T11:34:08.535Z","owner":"jspwiki"},{"_id":"613113717b16cf83ee16d07d","ID":"CVE-2021-40438","title":"mod_proxy SSRF","state":"PUBLIC","updated":"2021-09-16T14:37:10.201Z","owner":"httpd"},{"_id":"61311e807b16cf83ee16d07e","ID":"CVE-2021-40439","title":"Billion Laughs","state":"PUBLIC","updated":"2021-10-07T15:23:25.432Z","owner":"openoffice"},{"_id":"6135f5577b16cf83ee16d093","ID":"CVE-2021-40525","title":"Sieve file storage vulnerable to path traversal attacks","state":"PUBLIC","updated":"2022-01-04T08:49:17.932Z","owner":"james"},{"_id":"613874057b16cf83ee16d0b9","ID":"CVE-2021-40690","title":"Bypass of the secureValidation property","state":"PUBLIC","updated":"2021-09-19T17:20:51.491Z","owner":"santuario"},{"_id":"613db5ed7b16cf83ee16d0d1","ID":"CVE-2021-40865","title":"Unsafe Pre-Authentication Deserialization In Workers","state":"PUBLIC","updated":"2021-10-21T21:27:58.697Z","owner":"storm"},{"_id":"614217df7b16cf83ee16d0de","ID":"CVE-2021-41079","title":"Apache Tomcat DoS with unexpected TLS packet","state":"PUBLIC","updated":"2021-09-15T17:56:16.883Z","owner":"tomcat"},{"_id":"6142ebcc7b16cf83ee16d0e5","ID":"CVE-2021-41303","title":"Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass","state":"PUBLIC","updated":"2021-09-17T08:17:09.454Z","owner":"shiro"},{"_id":"61488a117b16cf83ee16d10e","ID":"CVE-2021-41524","title":"null pointer dereference in h2 fuzzing","state":"PUBLIC","updated":"2021-10-05T11:31:17.600Z","owner":"httpd"},{"_id":"61491bd47b16cf83ee16d113","ID":"CVE-2021-41532","title":"Unauthenticated access to Ozone Recon HTTP endpoints","state":"PUBLIC","updated":"2021-11-19T09:13:58.824Z","owner":"ozone"},{"_id":"614aebce7b16cf83ee16d11a","ID":"CVE-2021-41561","title":"Apache Parquet-MR potential DoS in case of malicious Parquet file","state":"PUBLIC","updated":"2021-12-20T11:09:26.601Z","owner":"parquet"},{"_id":"614c3c777b16cf83ee16d122","ID":"CVE-2021-41571","title":"Pulsar Admin API allows access to data from other tenants using getMessageById API","state":"PUBLIC","updated":"2022-01-31T12:57:16.188Z","owner":"pulsar"},{"_id":"614d75967b16cf83ee16d131","ID":"CVE-2021-41585","title":"ATS stops accepting connections on FreeBSD","state":"PUBLIC","updated":"2021-11-02T21:16:43.796Z","owner":"trafficserver"},{"_id":"61501f837b16cf83ee16d134","ID":"CVE-2021-41616","title":"Apache ddlutils 1.0 readobject vulnerability","state":"PUBLIC","updated":"2021-09-30T07:51:31.141Z","owner":"db"},{"_id":"6151bceb7b16cf83ee16d136","ID":"CVE-2021-41766","title":"Insecure Java Deserialization in Apache Karaf","state":"PUBLIC","updated":"2022-01-25T14:39:43.793Z","owner":"karaf"},{"_id":"6152c2dd7b16cf83ee16d138","ID":"CVE-2021-41767","title":"Private tunnel identifier may be included in the non-private details of active connections","state":"PUBLIC","updated":"2022-01-11T22:07:33.145Z","owner":"guacamole"},{"_id":"615414867b16cf83ee16d13a","ID":"CVE-2021-41773","title":"Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49","state":"PUBLIC","updated":"2021-10-11T14:15:40.313Z","owner":"httpd"},{"_id":"6155f5467b16cf83ee16d146","ID":"CVE-2021-41830","title":"Double Certificate Attack","state":"PUBLIC","updated":"2021-10-11T08:05:11.193Z","owner":"openoffice"},{"_id":"6155f54c7b16cf83ee16d147","ID":"CVE-2021-41831","title":"Timestamp Manipulation with Signature Wrapping","state":"PUBLIC","updated":"2021-10-11T08:05:48.311Z","owner":"openoffice"},{"_id":"6155f5567b16cf83ee16d148","ID":"CVE-2021-41832","title":"Content Manipulation with Certificate Validation Attack","state":"PUBLIC","updated":"2021-10-11T08:06:50.243Z","owner":"openoffice"},{"_id":"615ab92d7b16cf83ee16d14f","ID":"CVE-2021-41971","title":"Possible SQL Injection when template processing is enabled","state":"PUBLIC","updated":"2021-10-15T15:41:52.156Z","owner":"superset"},{"_id":"615abb027b16cf83ee16d150","ID":"CVE-2021-41972","title":"Credentials leak","state":"PUBLIC","updated":"2021-11-12T15:41:43.888Z","owner":"superset"},{"_id":"615af49e7b16cf83ee16d15b","ID":"CVE-2021-41973","title":"Apache MINA HTTP listener DOS","state":"PUBLIC","updated":"2021-11-01T08:33:24.585Z","owner":"mina"},{"_id":"615c06617b16cf83ee16d162","ID":"CVE-2021-42009","title":"Apache Traffic Control Traffic Ops Email Injection Vulnerability","state":"PUBLIC","updated":"2021-10-12T07:37:49.253Z","owner":"trafficcontrol"},{"_id":"615c8ac97b16cf83ee16d17c","ID":"CVE-2021-42010","title":"CRLF log injection","state":"PUBLIC","updated":"2022-10-23T15:07:00.844Z","owner":"heron"},{"_id":"615d51b27b16cf83ee16d18b","ID":"CVE-2021-42013","title":"Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)","state":"PUBLIC","updated":"2021-10-11T17:31:43.275Z","owner":"httpd"},{"_id":"61642ad07b16cf83ee16d1b7","ID":"CVE-2021-42250","title":"Possible log injection","state":"PUBLIC","updated":"2021-11-17T15:04:59.176Z","owner":"superset"},{"_id":"61669a8d9810b87bec8bcbc1","ID":"CVE-2021-42340","title":"DoS via memory leak with WebSocket connections","state":"PUBLIC","updated":"2021-10-14T14:26:25.345Z","owner":"tomcat"},{"_id":"616859989810b87bec8bcbc7","ID":"CVE-2021-42357","title":"DOM based XSS Vulnerability in Apache Knox","state":"PUBLIC","updated":"2022-01-17T19:19:12.317Z","owner":"knox"},{"_id":"61795bbf9810b87bec8bcbde","ID":"CVE-2021-43045","title":"Possible DOS vulnerabilities in C# Avro SDK","state":"PUBLIC","updated":"2022-01-06T17:58:30.429Z","owner":"avro"},{"_id":"617cffcc9810b87bec8bcbe2","ID":"CVE-2021-43082","title":"heap-buffer-overflow with stats-over-http plugin","state":"PUBLIC","updated":"2021-11-02T21:16:59.675Z","owner":"trafficserver"},{"_id":"617d2ccf9810b87bec8bcbe3","ID":"CVE-2021-43083","title":"Apache PLC4X 0.9.0 Buffer overflow in PLC4C via crafted server response","state":"PUBLIC","updated":"2022-02-04T08:46:33.224Z","owner":"plc4x"},{"_id":"61824a9e9810b87bec8bcc00","ID":"CVE-2021-43297","title":"Dubbo Hessian cause RCE when parse error","state":"PUBLIC","updated":"2022-01-10T06:23:23.358Z","owner":"dubbo"},{"_id":"6182e7ea9810b87bec8bcc01","ID":"CVE-2021-43350","title":"LDAP filter injection vulnerability in Traffic Ops","state":"PUBLIC","updated":"2021-11-11T20:52:57.271Z","owner":"trafficcontrol"},{"_id":"61864f346fa6f319fdfff07f","ID":"CVE-2021-43410","title":"airavata-django-portal allows CRLF log injection because of the lack of escaping in the log statements","state":"PUBLIC","updated":"2021-12-09T08:58:17.423Z","owner":"airavata"},{"_id":"618a31ee6fa6f319fdfff080","ID":"CVE-2021-43557","title":"Path traversal in request_uri variable","state":"PUBLIC","updated":"2021-11-22T08:20:29.238Z","owner":"apisix"},{"_id":"61954a416fa6f319fdfff0a8","ID":"CVE-2021-43980","title":"Apache Tomcat: Information disclosure","state":"PUBLIC","updated":"2022-09-28T13:18:54.072Z","owner":"tomcat"},{"_id":"619623656fa6f319fdfff0a9","ID":"CVE-2021-43999","title":"Improper validation of SAML responses","state":"PUBLIC","updated":"2022-01-11T22:07:28.747Z","owner":"guacamole"},{"_id":"6197f29f6fa6f319fdfff0d6","ID":"CVE-2021-44040","title":"HTTP request line fuzzing attacks","state":"PUBLIC","updated":"2022-03-23T14:04:02.939Z","owner":"trafficserver"},{"_id":"619b7cef6fa6f319fdfff0dd","ID":"CVE-2021-44140","title":"Arbitrary file deletion on logout","state":"PUBLIC","updated":"2021-11-23T11:34:55.319Z","owner":"jspwiki"},{"_id":"619c074d6fa6f319fdfff0e6","ID":"CVE-2021-44145","title":"Apache NiFi information disclosure by XXE","state":"PUBLIC","updated":"2021-12-17T08:46:07.497Z","owner":"nifi"},{"_id":"619fc2686fa6f319fdfff0ec","ID":"CVE-2021-44224","title":"Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlier","state":"PUBLIC","updated":"2021-12-20T11:06:17.917Z","owner":"httpd"},{"_id":"61a0ff5d6fa6f319fdfff0f2","ID":"CVE-2021-44228","title":"Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints","state":"PUBLIC","updated":"2021-12-23T21:53:38.756Z","owner":"logging"},{"_id":"61a64e6d6fa6f319fdfff0f7","ID":"CVE-2021-44451","title":"API sensitive information leak","state":"PUBLIC","updated":"2022-02-01T11:29:10.593Z","owner":"superset"},{"_id":"61a8a8a66fa6f319fdfff103","ID":"CVE-2021-44521","title":"Remote code execution for scripted UDFs","state":"PUBLIC","updated":"2022-02-11T12:02:55.157Z","owner":"cassandra"},{"_id":"61aab76e6fa6f319fdfff104","ID":"CVE-2021-44548","title":"Apache Solr information disclosure vulnerability through DataImportHandler","state":"PUBLIC","updated":"2021-12-23T08:51:22.228Z","owner":"solr"},{"_id":"61abd5db6fa6f319fdfff10a","ID":"CVE-2021-44549","title":"SMTPS server hostname not checked when making TLS connection to SMTPS server","state":"PUBLIC","updated":"2021-12-14T15:10:31.167Z","owner":"sling"},{"_id":"61b1ba136fa6f319fdfff11e","ID":"CVE-2021-44759","title":"Improper authentication vulnerability in TLS origin verification","state":"PUBLIC","updated":"2022-03-23T14:03:27.211Z","owner":"trafficserver"},{"_id":"61b30d4f6fa6f319fdfff12e","ID":"CVE-2021-44790","title":"Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier","state":"PUBLIC","updated":"2021-12-20T11:07:20.265Z","owner":"httpd"},{"_id":"61b311d36fa6f319fdfff132","ID":"CVE-2021-44791","title":"Reflected XSS on certain HTTP endpoints","state":"PUBLIC","updated":"2022-07-07T18:29:34.319Z","owner":"druid"},{"_id":"61b4cc016fa6f319fdfff13c","ID":"CVE-2021-44832","title":"Apache Log4j2 vulnerable to RCE via JDBC Appender when attacker controls configuration server","state":"PUBLIC","updated":"2021-12-30T08:25:52.491Z","owner":"logging"},{"_id":"61b723406fa6f319fdfff13f","ID":"CVE-2021-45029","title":"Apache ShenYu (incubating) Groovy Code Injection and SpEL Injection","state":"PUBLIC","updated":"2022-01-26T06:19:24.052Z","owner":"shenyu"},{"_id":"61b736046fa6f319fdfff140","ID":"CVE-2021-4104","title":"Deserialization of untrusted data in JMSAppender in Apache Log4j 1.2","state":"PUBLIC","updated":"2022-02-04T08:45:46.335Z","owner":"logging"},{"_id":"61b8b7536fa6f319fdfff15a","ID":"CVE-2021-45046","title":"Apache Log4j2 Thread Context Lookup Pattern vulnerable to remote code execution in certain non-default configurations","state":"PUBLIC","updated":"2022-02-04T08:46:08.709Z","owner":"logging"},{"_id":"61bb54f76fa6f319fdfff1a0","ID":"CVE-2021-45105","title":"Apache Log4j2 does not always protect from infinite recursion in lookup evaluation","state":"PUBLIC","updated":"2021-12-23T21:55:58.182Z","owner":"logging"},{"_id":"61bc488a6fa6f319fdfff1c8","ID":"CVE-2021-45229","title":"Apache Airflow: Reflected XSS via Origin Query Argument in URL","state":"PUBLIC","updated":"2022-02-25T08:21:17.026Z","owner":"airflow"},{"_id":"61bc52126fa6f319fdfff1ca","ID":"CVE-2021-45230","title":"Apache Airflow: Creating DagRuns didn't respect Dag-level permissions in the Webserver","state":"PUBLIC","updated":"2022-01-20T09:06:03.334Z","owner":"airflow"},{"_id":"61bde3b56fa6f319fdfff1df","ID":"CVE-2021-45232","title":"security vulnerability on unauthorized access.","state":"PUBLIC","updated":"2021-12-27T14:49:25.542Z","owner":"apisix"},{"_id":"61c18d0f6fa6f319fdfff204","ID":"CVE-2021-45456","title":"Command injection","state":"PUBLIC","updated":"2022-01-06T12:30:40.650Z","owner":"kylin"},{"_id":"61c18d226fa6f319fdfff205","ID":"CVE-2021-45457","title":"Overly broad CORS configuration ","state":"PUBLIC","updated":"2022-01-06T12:32:08.962Z","owner":"kylin"},{"_id":"61c18d306fa6f319fdfff206","ID":"CVE-2021-45458","title":"Hardcoded credentials","state":"PUBLIC","updated":"2022-01-06T12:33:02.681Z","owner":"kylin"},{"_id":"61d6e2dbae6d4a786e33dd22","ID":"CVE-2022-22719","title":"mod_lua Use of uninitialized value of in r:parsebody","state":"PUBLIC","updated":"2022-03-14T10:10:30.113Z","owner":"httpd"},{"_id":"61d6ebc2ae6d4a786e33dd23","ID":"CVE-2022-22720","title":"HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier","state":"PUBLIC","updated":"2022-03-14T10:09:48.647Z","owner":"httpd"},{"_id":"61d6ed7cae6d4a786e33dd24","ID":"CVE-2022-22721","title":"core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody","state":"PUBLIC","updated":"2022-03-14T10:08:56.550Z","owner":"httpd"},{"_id":"61d72b9cae6d4a786e33dd28","ID":"CVE-2022-22728","title":"libapreq2 multipart form parse memory corruption","state":"PUBLIC","updated":"2022-08-25T14:13:38.823Z","owner":"httpd"},{"_id":"61d808c9ae6d4a786e33dd2b","ID":"CVE-2022-22733","title":"Access-Token in ElasticJob UI causes password disclosure","state":"PUBLIC","updated":"2022-01-27T12:11:17.849Z","owner":"shardingsphere"},{"_id":"61dbf0d5ae6d4a786e33dd37","ID":"CVE-2022-22931","title":"Path traversal in Apache James 3.6.1","state":"PUBLIC","updated":"2022-02-07T18:45:09.142Z","owner":"james"},{"_id":"61dbf102ae6d4a786e33dd38","ID":"CVE-2022-22932","title":"Path traversal flaws","state":"PUBLIC","updated":"2022-01-25T14:53:17.546Z","owner":"karaf"},{"_id":"61dee9f4ae6d4a786e33dd54","ID":"CVE-2022-23181","title":"Local privilege escalation with FileStore","state":"PUBLIC","updated":"2022-01-26T11:25:59.878Z","owner":"tomcat"},{"_id":"61df7748ae6d4a786e33dd55","ID":"CVE-2022-23206","title":"Server-Side Request Forgery in Traffic Ops endpoint POST /user/login/oauth","state":"PUBLIC","updated":"2022-02-06T15:11:05.215Z","owner":"trafficcontrol"},{"_id":"61e19a08ae6d4a786e33dd5b","ID":"CVE-2022-23223","title":"Apache ShenYu (incubating) Password leakage","state":"PUBLIC","updated":"2022-01-26T06:44:20.022Z","owner":"shenyu"},{"_id":"61e44390ae6d4a786e33dd5c","ID":"CVE-2022-23302","title":"Deserialization of untrusted data in JMSSink in Apache Log4j 1.x","state":"PUBLIC","updated":"2022-01-18T16:52:09.053Z","owner":"logging"},{"_id":"61e56325ae6d4a786e33dd66","ID":"CVE-2022-23305","title":"SQL injection in JDBC Appender in Apache Log4j V1","state":"PUBLIC","updated":"2022-01-18T15:19:05.615Z","owner":"logging"},{"_id":"61e5642fae6d4a786e33dd68","ID":"CVE-2022-23307","title":" A deserialization flaw in the Chainsaw component of Log4j 1 can lead to malicious code execution.","state":"PUBLIC","updated":"2022-01-18T15:19:48.077Z","owner":"logging"},{"_id":"61e7bd12fed864f22d9ede71","ID":"CVE-2022-23437","title":"Infinite loop within Apache XercesJ xml parser","state":"PUBLIC","updated":"2022-01-24T14:59:39.857Z","owner":"xerces"},{"_id":"61eef2fcfed864f22d9ede86","ID":"CVE-2022-23913","title":"Apache ActiveMQ Artemis DoS","state":"PUBLIC","updated":"2022-02-04T08:26:48.236Z","owner":"activemq"},{"_id":"61efb1bafed864f22d9ede8f","ID":"CVE-2022-23942","title":"Apache Doris hardcoded cryptography initialization","state":"PUBLIC","updated":"2022-04-26T14:49:46.143Z","owner":"doris"},{"_id":"61efb53dfed864f22d9ede91","ID":"CVE-2022-23943","title":"mod_sed: Read/write beyond bounds","state":"PUBLIC","updated":"2022-03-14T10:07:36.342Z","owner":"httpd"},{"_id":"61efb63afed864f22d9ede92","ID":"CVE-2022-23944","title":"Apache ShenYu (incubating) Improper access control","state":"PUBLIC","updated":"2022-01-26T06:27:42.604Z","owner":"shenyu"},{"_id":"61efb7c1fed864f22d9ede94","ID":"CVE-2022-23945","title":"Apache ShenYu (incubating) missing authentication allows gateway registration","state":"PUBLIC","updated":"2022-01-26T06:39:24.870Z","owner":"shenyu"},{"_id":"61f12a72fed864f22d9edebb","ID":"CVE-2022-23974","title":"Pinot segment push endpoint has a vulnerability in unprotected environments","state":"PUBLIC","updated":"2022-04-05T19:51:49.065Z","owner":"pinot"},{"_id":"61f2efc6fed864f22d9edebf","ID":"CVE-2022-24070","title":"Apache Subversion mod_dav_svn is vulnerable to memory corruption","state":"PUBLIC","updated":"2022-04-12T17:46:14.441Z","owner":"subversion"},{"_id":"61f3dc83fed864f22d9edec1","ID":"CVE-2022-24112","title":"apisix/batch-requests plugin allows overwriting the X-REAL-IP header","state":"PUBLIC","updated":"2022-02-11T12:00:02.021Z","owner":"apisix"},{"_id":"61f7dbc1fed864f22d9edecc","ID":"CVE-2022-24280","title":"Apache Pulsar Proxy target broker address isn't validated","state":"PUBLIC","updated":"2022-09-23T09:22:34.280Z","owner":"pulsar"},{"_id":"61f8f66afed864f22d9eded8","ID":"CVE-2022-24288","title":"Apache Airflow: RCE in example DAGs","state":"PUBLIC","updated":"2022-02-25T08:21:43.680Z","owner":"airflow"},{"_id":"61f949fdfed864f22d9edede","ID":"CVE-2022-24289","title":"Deserialization of untrusted data in the Hessian Component of Apache Cayenne 4.1 with older Java versions","state":"PUBLIC","updated":"2022-02-11T22:06:23.179Z","owner":"cayenne"},{"_id":"61f97e14fed864f22d9edee0","ID":"CVE-2022-24294","title":"ReDoS in Apache MXNet RTC Module","state":"PUBLIC","updated":"2022-07-24T17:40:13.807Z","owner":"mxnet"},{"_id":"62037669fed864f22d9edf1a","ID":"CVE-2022-24697","title":"Apache Kylin prior to 4.0.2 allows command injection when the configuration overwrites function overwrites system parameters","state":"PUBLIC","updated":"2022-10-13T13:05:28.696Z","owner":"kylin"},{"_id":"62050d93fed864f22d9edf1b","ID":"CVE-2022-24706","title":"Remote Code Execution Vulnerability in Packaging","state":"PUBLIC","updated":"2022-04-26T09:18:02.724Z","owner":"couchdb"},{"_id":"6205a23ffed864f22d9edf1d","ID":"CVE-2022-24947","title":"Apache JSPWiki CSRF Account Takeover","state":"PUBLIC","updated":"2022-02-25T08:22:54.524Z","owner":"jspwiki"},{"_id":"6205a299fed864f22d9edf1e","ID":"CVE-2022-24948","title":"Apache JSPWiki Cross-site scripting vulnerability on User Preferences screen","state":"PUBLIC","updated":"2022-02-25T08:23:32.881Z","owner":"jspwiki"},{"_id":"6206981ffed864f22d9edf2f","ID":"CVE-2022-24969","title":"bypass of CVE-2021-25640","state":"PUBLIC","updated":"2022-06-06T21:43:07.547Z","owner":"dubbo"},{"_id":"620b5190fed864f22d9edf39","ID":"CVE-2022-25167","title":"Apache Flume vulnerable to a JNDI RCE in JMSSource ","state":"PUBLIC","updated":"2022-06-14T07:51:07.443Z","owner":"flume"},{"_id":"620b5457fed864f22d9edf3a","ID":"CVE-2022-25168","title":"Command injection in org.apache.hadoop.fs.FileUtil.unTarUsingTar","state":"PUBLIC","updated":"2022-08-04T14:28:32.587Z","owner":"hadoop"},{"_id":"620b56f6fed864f22d9edf3b","ID":"CVE-2022-25169","title":"Apache Tika BPGParser Memory Usage DoS","state":"PUBLIC","updated":"2022-05-16T16:59:35.802Z","owner":"tika"},{"_id":"620ef1eafed864f22d9edf3d","ID":"CVE-2022-25312","title":"An XML external entity (XXE) injection vulnerability exists in the Apache Any23 RDFa XSLTStylesheet extractor","state":"PUBLIC","updated":"2022-03-04T23:18:57.830Z","owner":"any23"},{"_id":"621277c6fed864f22d9edf3f","ID":"CVE-2022-25370","title":"Unauth Stored XSS vulnerability in the Birt plugin of Apache OFBiz","state":"PUBLIC","updated":"2022-09-02T06:58:56.611Z","owner":"ofbiz"},{"_id":"6212785ffed864f22d9edf40","ID":"CVE-2022-25371","title":"Unauth Path Traversal with file corruption affecting the Birt plugin of Apache OFBiz","state":"PUBLIC","updated":"2022-09-02T07:00:04.371Z","owner":"ofbiz"},{"_id":"621344eafed864f22d9edf4b","ID":"CVE-2022-25598","title":"Apache DolphinScheduler user registration is vulnerable to ReDoS attacks","state":"PUBLIC","updated":"2022-11-01T03:18:38.664Z","owner":"dolphinscheduler"},{"_id":"6214de61fed864f22d9edf4e","ID":"CVE-2022-25757","title":"Apache APISIX: the body_schema check in request-validation plugin can be bypassed","state":"PUBLIC","updated":"2022-03-28T06:57:28.175Z","owner":"apisix"},{"_id":"6215182cfed864f22d9edf4f","ID":"CVE-2022-25762","title":"Response mix-up with WebSocket concurrent send and close","state":"PUBLIC","updated":"2022-05-12T20:00:18.925Z","owner":"tomcat"},{"_id":"62152d86fed864f22d9edf53","ID":"CVE-2022-25763","title":"Improper input validation on HTTP/2 headers ","state":"PUBLIC","updated":"2022-10-20T20:25:04.197Z","owner":"trafficserver"},{"_id":"62160087fed864f22d9edf5b","ID":"CVE-2022-25813","title":"Server-Side Template Injection affecting the ecommerce plugin of Apache OFBiz","state":"PUBLIC","updated":"2022-09-02T07:01:21.926Z","owner":"ofbiz"},{"_id":"621890a8fed864f22d9edf6d","ID":"CVE-2022-26112","title":"Pinot query endpoint and the realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support","state":"PUBLIC","updated":"2022-09-23T03:13:43.429Z","owner":"pinot"},{"_id":"621e81526d067df1d660e148","ID":"CVE-2022-26336","title":"A carefully crafted TNEF file can cause an out of memory exception","state":"PUBLIC","updated":"2022-03-04T15:58:59.057Z","owner":"poi"},{"_id":"6220bf8d6d067df1d660e14d","ID":"CVE-2022-26377","title":"mod_proxy_ajp: Possible request smuggling","state":"PUBLIC","updated":"2022-06-08T09:44:32.521Z","owner":"httpd"},{"_id":"622239ce6d067df1d660e159","ID":"CVE-2022-26477","title":"Denial of service in readExternal method","state":"PUBLIC","updated":"2022-06-27T17:04:45.966Z","owner":"systemds"},{"_id":"6225bc176d067df1d660e160","ID":"CVE-2022-26612","title":"Arbitrary file write in FileUtil#unpackEntries on Windows","state":"PUBLIC","updated":"2022-04-07T17:32:32.075Z","owner":"hadoop"},{"_id":"6225f5376d067df1d660e161","ID":"CVE-2022-26650","title":"Apache ShenYu (incubating) Regular expression denial of service","state":"PUBLIC","updated":"2022-06-18T12:30:20.191Z","owner":"shenyu"},{"_id":"6228bff06d067df1d660e166","ID":"CVE-2022-26779","title":"Apache Cloudstack insecure random number generation affects project email invitation","state":"PUBLIC","updated":"2022-07-13T11:28:52.383Z","owner":"cloudstack"},{"_id":"622a2feb6d067df1d660e173","ID":"CVE-2022-26850","title":"Insufficiently protected credentials","state":"PUBLIC","updated":"2022-04-06T20:48:13.265Z","owner":"nifi"},{"_id":"622afbde6d067df1d660e177","ID":"CVE-2022-26884","title":"Apache DolphinScheduler exposes files without authentication","state":"PUBLIC","updated":"2022-10-28T01:44:55.028Z","owner":"dolphinscheduler"},{"_id":"622afc0b6d067df1d660e178","ID":"CVE-2022-26885","title":"Apache DolphinScheduler config file read by task risk","state":"PUBLIC","updated":"2022-11-24T11:55:57.562Z","owner":"dolphinscheduler"},{"_id":"622efec16d067df1d660e17c","ID":"CVE-2022-27166","title":"XSS vulnerability on XHRHtml2Markup.jsp in JSPWiki 2.11.2","state":"PUBLIC","updated":"2022-08-04T06:09:11.060Z","owner":"jspwiki"},{"_id":"62383d796d067df1d660e19d","ID":"CVE-2022-27479","title":"SQL injection vulnerability in chart data API","state":"PUBLIC","updated":"2022-04-13T19:02:41.528Z","owner":"superset"},{"_id":"62406b066d067df1d660e1aa","ID":"CVE-2022-27949","title":"Apache Airflow prior to 2.3.1 may include sensitive values in rendered template","state":"PUBLIC","updated":"2022-11-15T11:12:08.938Z","owner":"airflow"},{"_id":"624211756d067df1d660e1b1","ID":"CVE-2022-28129","title":" Insufficient Validation of HTTP/1.x Headers","state":"PUBLIC","updated":"2022-08-10T05:42:44.803Z","owner":"trafficserver"},{"_id":"62441e686d067df1d660e1b8","ID":"CVE-2022-28220","title":"STARTTLS command injection in Apache JAMES","state":"PUBLIC","updated":"2022-09-20T08:36:32.785Z","owner":"james"},{"_id":"6246f3086d067df1d660e1bc","ID":"CVE-2022-28330","title":"read beyond bounds in mod_isapi","state":"PUBLIC","updated":"2022-06-08T09:44:43.156Z","owner":"httpd"},{"_id":"624af4a46d067df1d660e1c0","ID":"CVE-2022-28614","title":"read beyond bounds via ap_rwrite() ","state":"PUBLIC","updated":"2022-06-10T17:43:34.235Z","owner":"httpd"},{"_id":"624af4d36d067df1d660e1c1","ID":"CVE-2022-28615","title":"Read beyond bounds in ap_strcmp_match()","state":"PUBLIC","updated":"2022-06-08T09:45:23.244Z","owner":"httpd"},{"_id":"624c9b1d6d067df1d660e1c9","ID":"CVE-2022-28730","title":"Apache JSPWiki Cross-site scripting vulnerability on AJAXPreview.jsp","state":"PUBLIC","updated":"2022-08-04T06:07:39.234Z","owner":"jspwiki"},{"_id":"624c9b2b6d067df1d660e1ca","ID":"CVE-2022-28731","title":"Apache JSPWiki CSRF in UserPreferences.jsp","state":"PUBLIC","updated":"2022-08-04T06:11:26.241Z","owner":"jspwiki"},{"_id":"624c9b3b6d067df1d660e1cb","ID":"CVE-2022-28732","title":"Apache JSPWiki Cross-site scripting vulnerability on WeblogPlugin","state":"PUBLIC","updated":"2022-08-04T06:09:44.097Z","owner":"jspwiki"},{"_id":"625139026d067df1d660e1e7","ID":"CVE-2022-28889","title":"Clickjacking in the web console","state":"PUBLIC","updated":"2022-07-07T18:30:27.570Z","owner":"druid"},{"_id":"6251e7f36d067df1d660e1e9","ID":"CVE-2022-28890","title":"Processing external DTDs","state":"PUBLIC","updated":"2022-05-05T08:34:36.622Z","owner":"jena"},{"_id":"62544c2c95207d0ff58a45fd","ID":"CVE-2022-29063","title":"Java Deserialization via RMI Connection from the Solr plugin of Apache OFBiz","state":"PUBLIC","updated":"2022-09-02T07:04:01.683Z","owner":"ofbiz"},{"_id":"62567f6995207d0ff58a460f","ID":"CVE-2022-29158","title":"Regular Expression Denial of Service (ReDoS) vulnerability in Apache OFBiz","state":"PUBLIC","updated":"2022-09-02T07:05:27.871Z","owner":"ofbiz"},{"_id":"6258344c95207d0ff58a4614","ID":"CVE-2022-29265","title":"Improper Restriction of XML External Entity References in Multiple Components","state":"PUBLIC","updated":"2022-04-30T08:01:30.969Z","owner":"nifi"},{"_id":"6259153595207d0ff58a461e","ID":"CVE-2022-29266","title":"apisix/jwt-auth may leak secrets in error response","state":"PUBLIC","updated":"2022-05-03T06:58:33.689Z","owner":"apisix"},{"_id":"625ae3e395207d0ff58a4624","ID":"CVE-2022-29404","title":"Denial of service in mod_lua r:parsebody","state":"PUBLIC","updated":"2022-06-08T09:45:33.924Z","owner":"httpd"},{"_id":"625d0a0a95207d0ff58a4625","ID":"CVE-2022-29405","title":"Apache Archiva Arbitrary user password reset vulnerability","state":"PUBLIC","updated":"2022-05-25T07:11:14.322Z","owner":"archiva"},{"_id":"62653d8595207d0ff58a4633","ID":"CVE-2022-29599","title":"Commandline class shell injection vulnerabilities","state":"PUBLIC","updated":"2022-05-23T10:22:16.632Z","owner":"maven"},{"_id":"626a4dfb95207d0ff58a4652","ID":"CVE-2022-29885","title":"EncryptInterceptor does not provide complete protection on insecure networks","state":"PUBLIC","updated":"2022-05-11T16:28:52.897Z","owner":"tomcat"},{"_id":"6270cfbc95207d0ff58a4662","ID":"CVE-2022-30126","title":"Apache Tika Regular Expression Denial of Service in Standards Extractor","state":"PUBLIC","updated":"2022-05-16T16:58:52.830Z","owner":"tika"},{"_id":"62790c4795207d0ff58a4669","ID":"CVE-2022-30522","title":"mod_sed denial of service","state":"PUBLIC","updated":"2022-06-08T09:45:43.331Z","owner":"httpd"},{"_id":"627beff295207d0ff58a466c","ID":"CVE-2022-30556","title":"Information Disclosure in mod_lua with websockets","state":"PUBLIC","updated":"2022-06-08T09:45:55.863Z","owner":"httpd"},{"_id":"6283da1494807fd7307c7367","ID":"CVE-2022-30973","title":"Missing fix for CVE-2022-30126 in 1.28.2","state":"PUBLIC","updated":"2022-05-31T13:14:46.730Z","owner":"tika"},{"_id":"62908b6694807fd7307c7378","ID":"CVE-2022-31764","title":"Apache ShardingSphere ElasticJob-UI allows RCE via event trace data source JDBC","state":"PUBLIC","updated":"2022-11-01T08:18:58.682Z","owner":"shardingsphere"},{"_id":"6290fd6e94807fd7307c737c","ID":"CVE-2022-31777","title":"Apache Spark XSS vulnerability in log viewer UI Javascript","state":"PUBLIC","updated":"2022-11-01T15:31:47.242Z","owner":"spark"},{"_id":"6291054294807fd7307c737d","ID":"CVE-2022-31778","title":"Transfer-Encoding not treated as hop-by-hop","state":"PUBLIC","updated":"2022-08-10T05:44:15.239Z","owner":"trafficserver"},{"_id":"6291081794807fd7307c737e","ID":"CVE-2022-31779","title":"Improper HTTP/2 scheme and method validation","state":"PUBLIC","updated":"2022-10-27T00:00:36.092Z","owner":"trafficserver"},{"_id":"629109f094807fd7307c7380","ID":"CVE-2022-31780","title":"HTTP/2 framing vulnerabilities ","state":"PUBLIC","updated":"2022-08-10T05:45:38.174Z","owner":"trafficserver"},{"_id":"62912f8a94807fd7307c7383","ID":"CVE-2022-31781","title":"Regular Expression Denial of Service (ReDoS) in ContentType.java. (GHSL-2022-022)","state":"PUBLIC","updated":"2022-07-13T07:23:23.997Z","owner":"tapestry"},{"_id":"6294b34c94807fd7307c7384","ID":"CVE-2022-31813","title":"mod_proxy X-Forwarded-For dropped by hop-by-hop mechanism","state":"PUBLIC","updated":"2022-06-08T09:46:07.679Z","owner":"httpd"},{"_id":"629a0fda94807fd7307c7392","ID":"CVE-2022-32287","title":"Apache UIMA prior to 3.3.1 has a path traversal vulnerability when extracting (PEAR) archives","state":"PUBLIC","updated":"2022-11-03T11:49:10.523Z","owner":"uima"},{"_id":"629f18a894807fd7307c73a2","ID":"CVE-2022-32532","title":"Authentication Bypass Vulnerability","state":"PUBLIC","updated":"2022-06-28T23:13:16.050Z","owner":"shiro"},{"_id":"629f4a9194807fd7307c73a3","ID":"CVE-2022-32533","title":"Apache Portals Jetspeed XSS, CSRF, SSRF, and XXE issues","state":"PUBLIC","updated":"2022-07-06T09:38:32.582Z","owner":"portals"},{"_id":"62a0ab8894807fd7307c73c1","ID":"CVE-2022-32549","title":"log injection in Sling logging","state":"PUBLIC","updated":"2022-06-22T14:22:34.319Z","owner":"sling"},{"_id":"62a7442194807fd7307c73cf","ID":"CVE-2022-33140","title":"Improper Neutralization of Command Elements in Shell User Group Provider","state":"PUBLIC","updated":"2022-06-15T14:21:09.085Z","owner":"nifi"},{"_id":"62a9279f94807fd7307c73db","ID":"CVE-2022-33681","title":"Improper Hostname Verification in Java Client and Proxy can expose authentication data via MITM","state":"PUBLIC","updated":"2022-09-23T09:22:48.001Z","owner":"pulsar"},{"_id":"62a927d494807fd7307c73dc","ID":"CVE-2022-33682","title":"Disabled Hostname Verification makes Brokers, Proxies vulnerable to MITM attack","state":"PUBLIC","updated":"2022-09-23T09:23:08.927Z","owner":"pulsar"},{"_id":"62a927ff94807fd7307c73dd","ID":"CVE-2022-33683","title":"Disabled Certificate Validation makes Broker, Proxy Admin Clients vulnerable to MITM attack ","state":"PUBLIC","updated":"2022-09-23T09:23:30.771Z","owner":"pulsar"},{"_id":"62a9282894807fd7307c73de","ID":"CVE-2022-33684","title":"Apache Pulsar C++/Python OAuth Clients prior to 3.0.0 were vulnerable to an MITM attack due to Disabled Certificate Validation","state":"PUBLIC","updated":"2022-11-04T15:46:59.823Z","owner":"pulsar"},{"_id":"62ab298794807fd7307c73ea","ID":"CVE-2022-33879","title":"Incomplete fix and new regex DoS in StandardsExtractingContentHandler","state":"PUBLIC","updated":"2022-06-27T21:35:12.489Z","owner":"tika"},{"_id":"62abc58994807fd7307c73ed","ID":"CVE-2022-33891","title":"Apache Spark shell command injection vulnerability via Spark UI","state":"PUBLIC","updated":"2022-07-18T06:58:42.467Z","owner":"spark"},{"_id":"62adc53694807fd7307c73f4","ID":"CVE-2022-33980","title":"Apache Commons Configuration insecure interpolation defaults","state":"PUBLIC","updated":"2022-07-06T13:03:54.020Z","owner":"commons"},{"_id":"62b01d8494807fd7307c73f6","ID":"CVE-2022-34158","title":"User Group Privilege Escalation","state":"PUBLIC","updated":"2022-08-04T06:10:42.676Z","owner":"jspwiki"},{"_id":"62b177b994807fd7307c73ff","ID":"CVE-2022-34169","title":"Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets","state":"PUBLIC","updated":"2022-07-21T12:21:22.370Z","owner":"xalan"},{"_id":"62b3323794807fd7307c7408","ID":"CVE-2022-34305","title":"XSS in examples web application","state":"PUBLIC","updated":"2022-06-23T10:22:24.067Z","owner":"tomcat"},{"_id":"62b9861b94807fd7307c7417","ID":"CVE-2022-34662","title":"Apache DolphinScheduler prior to 3.0.0 allows path traversal","state":"PUBLIC","updated":"2022-11-01T15:28:47.599Z","owner":"dolphinscheduler"},{"_id":"62bd6dd194807fd7307c7434","ID":"CVE-2022-34870","title":"Apache Geode stored Cross-Site Scripting (XSS) via data injection vulnerability in Pulse web application","state":"PUBLIC","updated":"2022-10-24T18:09:52.450Z","owner":"geode"},{"_id":"62c2d75994807fd7307c743a","ID":"CVE-2022-34916","title":"Improper Input Validation (JNDI Injection) in JMSMessageConsumer","state":"PUBLIC","updated":"2022-08-21T08:11:17.200Z","owner":"flume"},{"_id":"62c2d83e94807fd7307c743b","ID":"CVE-2022-34917","title":"Unauthenticated clients may cause OutOfMemoryError on Apache Kafka Brokers","state":"PUBLIC","updated":"2022-09-30T05:44:20.899Z","owner":"kafka"},{"_id":"62c5d1c3b24c622e530757cc","ID":"CVE-2022-35278","title":"HTML Injection in ActiveMQ Artemis Web Console","state":"PUBLIC","updated":"2022-08-18T07:52:49.472Z","owner":"activemq"},{"_id":"62cdfc09b24c622e530757e0","ID":"CVE-2022-35724","title":"Denial of service while reading data in Avro Rust SDK","state":"PUBLIC","updated":"2022-08-09T06:43:41.354Z","owner":"avro"},{"_id":"62cea2c0b24c622e530757e2","ID":"CVE-2022-35741","title":"Apache CloudStack SAML Single Sign-On XXE","state":"PUBLIC","updated":"2022-07-18T14:26:13.768Z","owner":"cloudstack"},{"_id":"62d21424b24c622e530757ed","ID":"CVE-2022-36124","title":"Memory overconsumption in Avro Rust SDK","state":"PUBLIC","updated":"2022-08-09T06:46:06.388Z","owner":"avro"},{"_id":"62d21471b24c622e530757ee","ID":"CVE-2022-36125","title":"Integer overflow when reading corrupted .avro file in Avro Rust SDK","state":"PUBLIC","updated":"2022-08-09T06:44:50.447Z","owner":"avro"},{"_id":"62d41a7bb24c622e530757f0","ID":"CVE-2022-36127","title":"Service unavailability impact in NodeJS agent(version <= 0.5.0)","state":"PUBLIC","updated":"2022-07-18T11:24:38.575Z","owner":"skywalking"},{"_id":"62d9d75bb24c622e5307581a","ID":"CVE-2022-36364","title":"Apache Calcite Avatica JDBC driver `httpclient_impl` connection property can be used as an RCE vector","state":"PUBLIC","updated":"2022-07-28T08:30:13.087Z","owner":"calcite"},{"_id":"62e39880b24c622e53075837","ID":"CVE-2022-37021","title":"Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 8. ","state":"PUBLIC","updated":"2022-08-31T06:54:22.083Z","owner":"geode"},{"_id":"62e3988db24c622e53075838","ID":"CVE-2022-37022","title":"Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 11","state":"PUBLIC","updated":"2022-08-31T06:56:24.123Z","owner":"geode"},{"_id":"62e39a2bb24c622e53075843","ID":"CVE-2022-37023","title":"Apache Geode deserialization of untrusted data flaw when using REST API on Java 8 or Java 11","state":"PUBLIC","updated":"2022-08-31T06:58:07.415Z","owner":"geode"},{"_id":"62ec4adffc0ffe88e06f4ae6","ID":"CVE-2022-37400","title":"Apache OpenOffice Static Initialization Vector Allows to Recover Passwords for Web Connections Without Knowing the Master Password","state":"PUBLIC","updated":"2022-08-13T06:33:55.145Z","owner":"openoffice"},{"_id":"62ec4bbdfc0ffe88e06f4ae7","ID":"CVE-2022-37401","title":"Apache OpenOffice Weak Master Keys","state":"PUBLIC","updated":"2022-08-13T06:35:06.833Z","owner":"openoffice"},{"_id":"62ecdd5bfc0ffe88e06f4afa","ID":"CVE-2022-37435","title":"Apache ShenYu Admin Improper Privilege Management","state":"PUBLIC","updated":"2022-09-01T13:57:00.985Z","owner":"shenyu"},{"_id":"62f0feb7fc0ffe88e06f4b00","ID":"CVE-2022-37865","title":"Apache Ivy allows creating/overwriting any file on the system","state":"PUBLIC","updated":"2022-11-07T10:53:07.179Z","owner":"ant"},{"_id":"62f0fecdfc0ffe88e06f4b01","ID":"CVE-2022-37866","title":"Apache Ivy allows path traversal in the presence of a malicious repository","state":"PUBLIC","updated":"2022-11-07T13:15:44.826Z","owner":"ant"},{"_id":"62f208a6fc0ffe88e06f4b0b","ID":"CVE-2022-38054","title":"Session Fixation","state":"PUBLIC","updated":"2022-09-13T08:39:38.357Z","owner":"airflow"},{"_id":"62f4b06dfc0ffe88e06f4b1d","ID":"CVE-2022-38170","title":"Overly permissive umask for daemons","state":"PUBLIC","updated":"2022-09-02T07:07:24.352Z","owner":"airflow"},{"_id":"62fa6006fc0ffe88e06f4b27","ID":"CVE-2022-38362","title":"Docker Provider <3.0 RCE vulnerability in example dag","state":"PUBLIC","updated":"2022-08-16T14:05:03.199Z","owner":"airflow"},{"_id":"62fb561efc0ffe88e06f4b2b","ID":"CVE-2022-38369","title":"Login check vulnerability by session Id","state":"PUBLIC","updated":"2022-09-05T09:42:50.630Z","owner":"iotdb"},{"_id":"62fb5646fc0ffe88e06f4b2c","ID":"CVE-2022-38370","title":"No authorization of DatabaseConnectController in grafana-connector. ","state":"PUBLIC","updated":"2022-09-05T09:43:12.381Z","owner":"iotdb"},{"_id":"62fde5eaefdd1b039e157076","ID":"CVE-2022-38398","title":"Server-Side Request Forgery Information Disclosure Vulnerability","state":"PUBLIC","updated":"2022-09-22T14:36:45.719Z","owner":"xmlgraphics"},{"_id":"630351bbefdd1b039e15707c","ID":"CVE-2022-38648","title":"PDFTranscoder does not block external resources","state":"PUBLIC","updated":"2022-09-22T14:37:30.540Z","owner":"xmlgraphics"},{"_id":"630360ccefdd1b039e15707f","ID":"CVE-2022-38649","title":"Apache Airflow Pinot provider allowed Command Injection","state":"PUBLIC","updated":"2022-11-22T09:35:10.175Z","owner":"airflow"},{"_id":"63106695efdd1b039e1570a2","ID":"CVE-2022-39135","title":"Apache Calcite: potential XEE attacks","state":"PUBLIC","updated":"2023-09-18T12:55:46.886Z","owner":"calcite"},{"_id":"6311b2b77ec12b51e9102497","ID":"CVE-2022-39198","title":"Apache Dubbo Hession Deserialization Vulnerability Gadgets Bypass","state":"PUBLIC","updated":"2022-10-18T18:50:42.549Z","owner":"dubbo"},{"_id":"6315c7b67ec12b51e91024ac","ID":"CVE-2022-39944","title":"The Apache Linkis JDBC EngineConn module has a RCE Vulnerability","state":"PUBLIC","updated":"2022-10-26T12:44:23.967Z","owner":"linkis"},{"_id":"6316f7997ec12b51e91024b6","ID":"CVE-2022-40127","title":"Apache Airflow <2.4.0 has an RCE in a bash example","state":"PUBLIC","updated":"2022-11-14T09:30:08.330Z","owner":"airflow"},{"_id":"6318570c7ec12b51e91024ba","ID":"CVE-2022-40146","title":"Jar url should be blocked by DefaultScriptSecurity","state":"PUBLIC","updated":"2022-11-23T18:09:53.965Z","owner":"xmlgraphics"},{"_id":"6319d5507ec12b51e91024bd","ID":"CVE-2022-40189","title":"Apache Airlfow Pig Provider RCE","state":"PUBLIC","updated":"2022-11-22T09:39:35.331Z","owner":"airflow"},{"_id":"631ae5757ec12b51e91024be","ID":"CVE-2022-40308","title":"Apache Archiva prior to 2.2.9 may allow the anonymous user to read arbitrary files","state":"PUBLIC","updated":"2022-11-15T13:08:09.007Z","owner":"archiva"},{"_id":"631ae5b37ec12b51e91024bf","ID":"CVE-2022-40309","title":"Apache Archiva prior to 2.2.9 allows an authenticated user to delete arbitrary directories","state":"PUBLIC","updated":"2022-11-15T13:09:01.491Z","owner":"archiva"},{"_id":"631f22727ec12b51e91024e5","ID":"CVE-2022-40604","title":"Format String Vulnerability","state":"PUBLIC","updated":"2022-09-21T07:22:50.780Z","owner":"airflow"},{"_id":"6320eb337ec12b51e91024e8","ID":"CVE-2022-40664","title":"Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher","state":"PUBLIC","updated":"2022-10-12T07:07:53.344Z","owner":"shiro"},{"_id":"6321d7847ec12b51e91024ee","ID":"CVE-2022-40705","title":"Apache SOAP: XML External Entity Injection (XXE) allows unauthenticated users to read arbitrary files via HTTP","state":"PUBLIC","updated":"2022-09-22T08:11:36.490Z","owner":"ws"},{"_id":"6324b8aa7ec12b51e91024fa","ID":"CVE-2022-40754","title":"Open Redirect","state":"PUBLIC","updated":"2022-09-21T07:22:31.671Z","owner":"airflow"},{"_id":"6328157e7ec12b51e9102501","ID":"CVE-2022-40954","title":"Apache Airflow Spark Provider RCE that bypass restrictions to read arbitrary files","state":"PUBLIC","updated":"2022-11-22T09:40:32.614Z","owner":"airflow"},{"_id":"632856a97ec12b51e9102502","ID":"CVE-2022-40955","title":"Deserialization attack in Apache InLong prior to version 1.3.0 allows RCE via JDBC","state":"PUBLIC","updated":"2023-02-01T03:30:57.303Z","owner":"inlong"},{"_id":"6328cf8f7ec12b51e9102509","ID":"CVE-2022-41131","title":"Apache Airflow Hive Provider vulnerability (command injection via hive_cli connection)","state":"PUBLIC","updated":"2022-11-22T09:38:16.454Z","owner":"airflow"},{"_id":"6333727359d32ad28d399979","ID":"CVE-2022-41672","title":"Session still functional after user is deactivated","state":"PUBLIC","updated":"2022-10-07T06:56:43.156Z","owner":"airflow"},{"_id":"633464c459d32ad28d39997f","ID":"CVE-2022-41704","title":"Apache Batik prior to 1.16 allows RCE when loading untrusted SVG input","state":"PUBLIC","updated":"2022-10-25T11:02:56.969Z","owner":"xmlgraphics"},{"_id":"633a9b86e8c5552605ffb332","ID":"CVE-2022-42252","title":"Apache Tomcat request smuggling via malformed content-length","state":"PUBLIC","updated":"2022-11-18T12:36:02.907Z","owner":"tomcat"},{"_id":"633fc6abe8c5552605ffb339","ID":"CVE-2022-42466","title":"XSS vulnerability, eg for String properties.","state":"PUBLIC","updated":"2022-10-19T07:20:06.791Z","owner":"isis"},{"_id":"633fc6bae8c5552605ffb33a","ID":"CVE-2022-42467","title":"h2 webconsole (available only in prototype mode) should nevertheless be disabled by default.","state":"PUBLIC","updated":"2022-10-19T07:19:59.555Z","owner":"isis"},{"_id":"633fc6cce8c5552605ffb33b","ID":"CVE-2022-42468","title":"Apache Flume prior to 1.11.0 has an Improper Input Validation (JNDI Injection) in JMSSource","state":"PUBLIC","updated":"2022-10-26T13:08:08.448Z","owner":"flume"},{"_id":"634666cbe8c5552605ffb349","ID":"CVE-2022-42889","title":"Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults","state":"PUBLIC","updated":"2022-10-13T13:03:35.541Z","owner":"commons"},{"_id":"6346b739e8c5552605ffb34e","ID":"CVE-2022-42890","title":"Apache Batik prior to 1.16 allows RCE via scripting","state":"PUBLIC","updated":"2022-10-25T11:25:19.555Z","owner":"xmlgraphics"},{"_id":"63490f1ad452f031d6bfcbaf","ID":"CVE-2022-42920","title":"Apache Commons BCEL prior to 6.6.0 allows producing arbitrary bytecode via out-of-bounds writing","state":"PUBLIC","updated":"2022-11-07T12:25:20.461Z","owner":"commons"},{"_id":"63540a0ad452f031d6bfcbee","ID":"CVE-2022-43670","title":"XSS in Sling CMS Reference App Taxonomy Path","state":"PUBLIC","updated":"2022-11-02T12:20:10.764Z","owner":"sling"},{"_id":"6358f6dbd452f031d6bfcc1d","ID":"CVE-2022-43766","title":"Apache IoTDB prior to 0.13.3 allows DoS","state":"PUBLIC","updated":"2022-10-26T16:04:23.572Z","owner":"iotdb"},{"_id":"635c109dd452f031d6bfcc40","ID":"CVE-2022-43982","title":"Apache Airflow prior to 2.4.2 allows reflected XSS via Origin Query Argument in URL","state":"PUBLIC","updated":"2022-11-02T08:37:19.773Z","owner":"airflow"},{"_id":"635c3736d452f031d6bfcc44","ID":"CVE-2022-43985","title":"Apache Airflow prior to 2.4.2 has an open redirect","state":"PUBLIC","updated":"2022-11-02T08:40:14.097Z","owner":"airflow"},{"_id":"63628116d452f031d6bfcc6b","ID":"CVE-2022-44635","title":"Apache Fineract allowed an authenticated user to perform remote code execution due to path traversal","state":"PUBLIC","updated":"2022-11-29T14:22:31.295Z","owner":"fineract"},{"_id":"636a1b16d452f031d6bfcc97","ID":"CVE-2022-45047","title":"Apache MINA SSHD: Java unsafe deserialization vulnerability","state":"PUBLIC","updated":"2022-11-16T09:03:02.600Z","owner":"mina"},{"_id":"636cb6c9d452f031d6bfcc9f","ID":"CVE-2022-45136","title":"Apache Jena SDB allows arbitrary deserialisation via JDBC","state":"PUBLIC","updated":"2022-11-14T15:41:09.479Z","owner":"jena"},{"_id":"63723e61d452f031d6bfccbb","ID":"CVE-2022-45378","title":"Apache SOAP allows unauthenticated users to potentially invoke arbitrary code","state":"PUBLIC","updated":"2022-11-14T14:06:51.577Z","owner":"ws"},{"_id":"63726095d452f031d6bfccc2","ID":"CVE-2022-45402","title":"Apache Airflow: Open redirect during login","state":"PUBLIC","updated":"2022-11-15T08:49:17.848Z","owner":"airflow"},{"_id":"6376102dd452f031d6bfcce8","ID":"CVE-2022-45462","title":"Apache DolphinScheduler prior to 2.0.5 have command execution vulnerability","state":"PUBLIC","updated":"2022-11-23T02:24:20.816Z","owner":"dolphinscheduler"},{"_id":"63777b12d452f031d6bfcce9","ID":"CVE-2022-45470","title":"Apache Hama allows XSS and information disclosure","state":"PUBLIC","updated":"2022-11-21T13:30:47.145Z","owner":"hama"},{"_id":"6389e593e35af603c3de35db","ID":"CVE-2022-46366","title":"Apache Tapestry prior to version 4 (EOL) allows RCE though deserialization of untrusted input","state":"PUBLIC","updated":"2022-12-02T13:44:12.576Z","owner":"tapestry"},{"_id":"638de6acd2699a69659aee54","ID":"CVE-2022-32531","title":"Java Client Uses Connection to Host that Failed Hostname Verification","state":"PUBLIC","updated":"2023-07-12T14:53:21.686Z","owner":"bookkeeper"},{"_id":"638de6e6d2699a69659aee6d","ID":"CVE-2022-38745","title":"Empty entry in Java class path","state":"PUBLIC","updated":"2023-03-24T15:56:44.525Z","owner":"openoffice"},{"_id":"638de718d2699a69659aee86","ID":"CVE-2022-40145","title":"JDBC JAAS LDAP injection","state":"PUBLIC","updated":"2022-12-21T15:53:26.357Z","owner":"karaf"},{"_id":"638de797d2699a69659aeebb","ID":"CVE-2022-41678","title":"Insufficient API restrictions on Jolokia allow authenticated users to perform RCE","state":"PUBLIC","updated":"2024-05-31T08:42:39.786Z","owner":"activemq"},{"_id":"638de7f6d2699a69659aeeda","ID":"CVE-2022-42009","title":"A malicious authenticated user can remotely execute arbitrary code in the context of the application.","state":"PUBLIC","updated":"2023-07-12T09:58:16.769Z","owner":"ambari"},{"_id":"638de86ed2699a69659aeef3","ID":"CVE-2022-42735","title":"Apache ShenYu Admin ultra vires","state":"PUBLIC","updated":"2023-02-15T09:38:50.099Z","owner":"shenyu"},{"_id":"638de89cd2699a69659aef0c","ID":"CVE-2022-43396","title":"Command injection by Useless configuration","state":"PUBLIC","updated":"2022-12-30T10:30:28.434Z","owner":"kylin"},{"_id":"638de919d2699a69659aef3e","ID":"CVE-2022-44621","title":"Command injection by Diagnosis Controller","state":"PUBLIC","updated":"2022-12-30T10:31:39.045Z","owner":"kylin"},{"_id":"638de94fd2699a69659aef57","ID":"CVE-2022-44729","title":"Information disclosure vulnerability","state":"PUBLIC","updated":"2023-08-22T14:12:19.621Z","owner":"xmlgraphics"},{"_id":"638de982d2699a69659aef70","ID":"CVE-2022-44730","title":"Information disclosure vulnerability","state":"PUBLIC","updated":"2023-08-22T14:04:18.758Z","owner":"xmlgraphics"},{"_id":"638de9b5d2699a69659aef89","ID":"CVE-2022-45048","title":"code execution vulnerability in policy expressions","state":"PUBLIC","updated":"2023-05-05T07:50:14.288Z","owner":"ranger"},{"_id":"638de9d6d2699a69659aefa2","ID":"CVE-2022-45064","title":"Include-based XSS","state":"PUBLIC","updated":"2023-04-13T10:01:10.930Z","owner":"sling"},{"_id":"638dea02d2699a69659aefbb","ID":"CVE-2022-45135","title":"SQL injection in DatabaseCookieAuthenticatorAction","state":"PUBLIC","updated":"2023-11-30T08:05:43.177Z","owner":"cocoon"},{"_id":"638dea6ad2699a69659aefd4","ID":"CVE-2022-45801","title":"LDAP Injection Vulnerability","state":"PUBLIC","updated":"2023-05-01T14:50:06.013Z","owner":"streampark"},{"_id":"638dea8cd2699a69659aefed","ID":"CVE-2022-45802","title":"Upload any file to any directory","state":"PUBLIC","updated":"2023-06-26T10:23:44.595Z","owner":"streampark"},{"_id":"638deabed2699a69659af006","ID":"CVE-2022-45855","title":"Allows authenticated metrics consumers to perform RCE","state":"PUBLIC","updated":"2023-07-12T09:59:42.590Z","owner":"ambari"},{"_id":"638deae8d2699a69659af01f","ID":"CVE-2022-46363","title":"Apache CXF directory listing / code exfiltration","state":"PUBLIC","updated":"2022-12-13T14:47:26.050Z","owner":"cxf"},{"_id":"638deb19d2699a69659af03b","ID":"CVE-2022-25147","title":"out-of-bounds writes in the apr_base64 family of functions","state":"PUBLIC","updated":"2023-01-31T15:54:46.758Z","owner":"apr"},{"_id":"638deb59d2699a69659af054","ID":"CVE-2022-46364","title":"Apache CXF SSRF Vulnerability","state":"PUBLIC","updated":"2022-12-13T15:44:20.951Z","owner":"cxf"},{"_id":"638deb79d2699a69659af076","ID":"CVE-2022-46365","title":"Logic error causing any account reset","state":"PUBLIC","updated":"2023-05-01T14:53:47.030Z","owner":"streampark"},{"_id":"638deba6d2699a69659af08f","ID":"CVE-2022-46421","title":"Hive Provider RCE vulnerability with hive_cli_params","state":"PUBLIC","updated":"2022-12-20T10:18:24.768Z","owner":"airflow"},{"_id":"638dec84d2699a69659af0ae","ID":"CVE-2022-46337","title":"LDAP injection vulnerability in authenticator","state":"PUBLIC","updated":"2024-01-02T18:36:19.559Z","owner":"db"},{"_id":"638ded23d2699a69659af0e8","ID":"CVE-2022-45935","title":"Temporary File Information Disclosure","state":"PUBLIC","updated":"2023-07-12T10:18:16.935Z","owner":"james"},{"_id":"638dedfcd2699a69659af11a","ID":"CVE-2022-45910","title":"LDAP Injection Vulnerability - ActiveDirectory Authorities","state":"PUBLIC","updated":"2022-12-07T09:50:35.935Z","owner":"manifoldcf"},{"_id":"638def13d2699a69659af147","ID":"CVE-2022-45787","title":"Temporary File Information Disclosure in MIME4J TempFileStorageProvider","state":"PUBLIC","updated":"2023-01-16T10:25:33.637Z","owner":"james"},{"_id":"638def95d2699a69659af174","ID":"CVE-2022-45438","title":"Dashboard metadata information leak","state":"PUBLIC","updated":"2023-01-25T08:27:38.187Z","owner":"superset"},{"_id":"638deff7d2699a69659af194","ID":"CVE-2022-45347","title":"MySQL authentication bypass","state":"PUBLIC","updated":"2023-02-15T02:21:01.314Z","owner":"shardingsphere"},{"_id":"638df073d2699a69659af1b0","ID":"CVE-2022-45143","title":"JsonErrorReportValve escaping","state":"PUBLIC","updated":"2025-10-29T11:35:28.968Z","owner":"tomcat"},{"_id":"638df101d2699a69659af1cc","ID":"CVE-2022-41137","title":"Deserialization of untrusted data when fetching partitions from the Metastore","state":"PUBLIC","updated":"2024-12-05T10:01:39.567Z","owner":"hive"},{"_id":"638df1a9d2699a69659af1fb","ID":"CVE-2022-34321","title":"Improper Authentication for Pulsar Proxy Statistics Endpoint","state":"PUBLIC","updated":"2024-03-12T18:17:04.384Z","owner":"pulsar"},{"_id":"638df209d2699a69659af22b","ID":"CVE-2022-24963","title":"out-of-bound writes in the apr_encode family of functions ","state":"PUBLIC","updated":"2023-01-31T15:51:53.920Z","owner":"apr"},{"_id":"638df63cd2699a69659af27a","ID":"CVE-2021-40331","title":"Permissions problem in the Apache Ranger Hive Plugin","state":"PUBLIC","updated":"2023-05-05T07:55:02.663Z","owner":"ranger"},{"_id":"638df869d2699a69659af340","ID":"CVE-2022-34271","title":"zip path traversal in import functionality","state":"PUBLIC","updated":"2022-12-14T08:34:57.194Z","owner":"atlas"},{"_id":"638df902d2699a69659af364","ID":"CVE-2022-44645","title":"The DatasourceManager module has a serialization attack vulnerability","state":"PUBLIC","updated":"2023-02-03T07:43:51.516Z","owner":"linkis"},{"_id":"638dfa7bd2699a69659af39b","ID":"CVE-2022-44644","title":"The DatasourceManager module has a Local File Read Vulnerability","state":"PUBLIC","updated":"2023-03-15T08:36:49.053Z","owner":"linkis"},{"_id":"638dfb60d2699a69659af3e4","ID":"CVE-2022-32749","title":"Improperly handled requests can cause crashes in specific plugins","state":"PUBLIC","updated":"2022-12-19T10:51:20.718Z","owner":"trafficserver"},{"_id":"638dfbdcd2699a69659af401","ID":"CVE-2022-37392","title":"Improperly reading the client requests","state":"PUBLIC","updated":"2022-12-19T10:58:23.000Z","owner":"trafficserver"},{"_id":"638dfc17d2699a69659af41a","ID":"CVE-2022-40743","title":"Security issues with the xdebug plugin","state":"PUBLIC","updated":"2023-07-17T14:33:07.403Z","owner":"trafficserver"},{"_id":"638dfc7dd2699a69659af436","ID":"CVE-2021-28655","title":"Arbitrary file deletion vulnerability","state":"PUBLIC","updated":"2022-12-20T09:49:02.814Z","owner":"zeppelin"},{"_id":"638dfcd5d2699a69659af468","ID":"CVE-2021-28656","title":"CSRF vulnerability in the Credentials page","state":"PUBLIC","updated":"2024-04-09T09:12:56.855Z","owner":"zeppelin"},{"_id":"638dfd83d2699a69659af484","ID":"CVE-2022-41703","title":"SQL injection vulnerability in adhoc clauses","state":"PUBLIC","updated":"2023-04-11T14:58:41.701Z","owner":"superset"},{"_id":"638dfde3d2699a69659af4b5","ID":"CVE-2022-43717","title":"Cross-Site Scripting on dashboards","state":"PUBLIC","updated":"2023-02-02T10:14:19.691Z","owner":"superset"},{"_id":"638dfe20d2699a69659af4ce","ID":"CVE-2022-43718","title":"Cross-Site Scripting vulnerability on upload forms","state":"PUBLIC","updated":"2023-02-02T10:15:07.131Z","owner":"superset"},{"_id":"638dfe66d2699a69659af4e7","ID":"CVE-2022-43719","title":"Cross Site Request Forgery (CSRF) on accept, request access API","state":"PUBLIC","updated":"2023-02-02T10:16:06.095Z","owner":"superset"},{"_id":"638dfea1d2699a69659af500","ID":"CVE-2022-43720","title":"Improper rendering of user input","state":"PUBLIC","updated":"2023-02-02T10:16:28.581Z","owner":"superset"},{"_id":"638dfeecd2699a69659af519","ID":"CVE-2022-43721","title":"Open Redirect Vulnerability","state":"PUBLIC","updated":"2023-02-02T10:16:45.887Z","owner":"superset"},{"_id":"638dff6dd2699a69659af53a","ID":"CVE-2022-37436","title":"mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting","state":"PUBLIC","updated":"2023-01-17T19:13:19.999Z","owner":"httpd"},{"_id":"638e0013d2699a69659af57e","ID":"CVE-2022-36760","title":"mod_proxy_ajp Possible request smuggling","state":"PUBLIC","updated":"2023-01-17T19:12:02.488Z","owner":"httpd"},{"_id":"638e00f5d2699a69659af5b6","ID":"CVE-2006-20001","title":"mod_dav out of  bounds read, or write of zero byte","state":"PUBLIC","updated":"2023-01-17T19:07:17.134Z","owner":"httpd"},{"_id":"638e017ad2699a69659af5ec","ID":"CVE-2022-28331","title":" Windows out-of-bounds write in apr_socket_sendv function","state":"PUBLIC","updated":"2023-07-07T15:26:37.824Z","owner":"apr"},{"_id":"638e0225d2699a69659af62a","ID":"CVE-2022-45786","title":"Python and Golang drivers allow data manipulation and exposure due to SQL injection","state":"PUBLIC","updated":"2023-02-04T20:40:55.771Z","owner":"age"},{"_id":"638e73a818cced14b2898c97","ID":"CVE-2022-46651","title":"Security vulnerability on AirFlow Connections","state":"PUBLIC","updated":"2023-07-12T09:16:59.771Z","owner":"airflow"},{"_id":"639085c343ab9fc46824edd3","ID":"CVE-2022-46751","title":"XML External Entity vulnerability in Apache Ivy","state":"PUBLIC","updated":"2023-08-21T06:54:55.281Z","owner":"ant"},{"_id":"6390e3f443ab9fc46824ede9","ID":"CVE-2022-46769","title":"XSS in CMS Site Group Detail","state":"PUBLIC","updated":"2023-01-25T03:51:12.925Z","owner":"sling"},{"_id":"6391c67f0466ef7973201cd5","ID":"CVE-2022-45875","title":"Remote command execution Vulnerability in script alert plugin","state":"PUBLIC","updated":"2023-11-22T08:37:58.550Z","owner":"dolphinscheduler"},{"_id":"6393406fd9d009030ccba489","ID":"CVE-2022-46870","title":"Stored XSS in note permissions","state":"PUBLIC","updated":"2022-12-16T12:54:56.815Z","owner":"zeppelin"},{"_id":"6394a200d9d009030ccba4bd","ID":"CVE-2022-46907","title":"XSS Injection points in several plugins","state":"PUBLIC","updated":"2023-05-25T06:58:08.238Z","owner":"jspwiki"},{"_id":"63974d1948838e1c488a36af","ID":"CVE-2022-47184","title":"The TRACE method can be use to disclose network information","state":"PUBLIC","updated":"2023-06-14T07:42:29.792Z","owner":"trafficserver"},{"_id":"63974e4748838e1c488a36d9","ID":"CVE-2022-47185","title":"Invalid Range header causes a crash","state":"PUBLIC","updated":"2023-08-09T06:57:36.707Z","owner":"trafficserver"},{"_id":"639ae4dc48838e1c488a39c9","ID":"CVE-2022-47500","title":"Open redirect","state":"PUBLIC","updated":"2022-12-19T09:23:48.197Z","owner":"helix"},{"_id":"639b095d48838e1c488a3a0f","ID":"CVE-2022-47501","title":"Arbitrary file reading vulnerability","state":"PUBLIC","updated":"2023-04-14T15:00:25.628Z","owner":"ofbiz"},{"_id":"639b5d2048838e1c488a3a6a","ID":"CVE-2022-47502","title":"Macro URL arbitrary script execution","state":"PUBLIC","updated":"2023-04-05T12:45:10.294Z","owner":"openoffice"},{"_id":"63a327925110bac75f339ef0","ID":"CVE-2022-47894","title":"connecting to a malicious SAP server allowed it to perform XXE","state":"PUBLIC","updated":"2024-04-09T09:29:15.865Z","owner":"zeppelin"},{"_id":"63a5a7a45110bac75f33a01b","ID":"CVE-2022-47937","title":"Multiple parsing problems in the Apache Sling Commons JSON module","state":"PUBLIC","updated":"2024-03-29T09:39:29.809Z","owner":"sling"},{"_id":"63b4bfc946d013ee9ccfac2b","ID":"CVE-2023-22602","title":"Apache Shiro before 1.11.0, when used with Spring Boot 2.6+, may allow authentication bypass through a specially crafted HTTP request","state":"PUBLIC","updated":"2023-01-14T09:33:37.695Z","owner":"shiro"},{"_id":"63b6e1808182480c59414a71","ID":"CVE-2023-22665","title":"Exposure of arbitrary execution in script engine expressions.","state":"PUBLIC","updated":"2023-04-25T07:09:43.803Z","owner":"jena"},{"_id":"63b888258182480c59414afe","ID":"CVE-2023-22832","title":"Improper Restriction of XML External Entity References in ExtractCCDAAttributes","state":"PUBLIC","updated":"2023-02-10T07:45:29.071Z","owner":"nifi"},{"_id":"63b997cf8182480c59414ba9","ID":"CVE-2023-22849","title":"XSS in CMS Reference / UI Components","state":"PUBLIC","updated":"2023-02-03T23:38:07.612Z","owner":"sling"},{"_id":"63bc69698182480c59414c78","ID":"CVE-2023-22884","title":"Arbitrary file read via MySQL provider in Apache Airflow","state":"PUBLIC","updated":"2023-01-21T13:02:09.736Z","owner":"airflow"},{"_id":"63bc6a018182480c59414c7c","ID":"CVE-2023-22886","title":"RCE Vulnerability","state":"PUBLIC","updated":"2023-06-29T09:40:58.058Z","owner":"airflow"},{"_id":"63bc6ccf8182480c59414cce","ID":"CVE-2023-22887","title":"Apache Airflow path traversal by authenticated user","state":"PUBLIC","updated":"2023-07-13T10:31:08.518Z","owner":"airflow"},{"_id":"63bc6d818182480c59414cd4","ID":"CVE-2023-22888","title":"Scheduler remote DoS","state":"PUBLIC","updated":"2023-07-12T09:17:51.316Z","owner":"airflow"},{"_id":"63be0e7d8182480c59414d47","ID":"CVE-2023-22946","title":"Apache Spark proxy-user privilege escalation from malicious configuration class","state":"PUBLIC","updated":"2023-04-17T07:30:17.426Z","owner":"spark"},{"_id":"63c61f658182480c5941522e","ID":"CVE-2023-23638","title":"Apache Dubbo Deserialization Vulnerability Gadgets Bypass","state":"PUBLIC","updated":"2023-03-08T08:51:34.345Z","owner":"dubbo"},{"_id":"63d7d81f79ea8b04f365c3fd","ID":"CVE-2023-24829","title":"apache/iotdb-web-workbench: forge the JWTToken to access workbench","state":"PUBLIC","updated":"2023-03-08T16:15:02.969Z","owner":"iotdb"},{"_id":"63d7e5869bbc4bafa3d4214c","ID":"CVE-2023-24830","title":"apache/iotdb-web-workbench: create a user without authorization","state":"PUBLIC","updated":"2023-03-08T16:15:22.623Z","owner":"iotdb"},{"_id":"63d7e7ef9bbc4bafa3d4217b","ID":"CVE-2023-24831","title":"Apache IoTDB grafana-connector Login Bypass Vulnerability","state":"PUBLIC","updated":"2023-04-18T01:31:44.944Z","owner":"iotdb"},{"_id":"63d9d9d09bbc4bafa3d42447","ID":"CVE-2023-24977","title":"Jdbc Connection causes arbitrary file reading in InLong","state":"PUBLIC","updated":"2023-02-01T09:09:46.267Z","owner":"inlong"},{"_id":"63da3f1b9bbc4bafa3d424ce","ID":"CVE-2023-24997","title":"Jdbc Connection Security Bypass","state":"PUBLIC","updated":"2023-03-27T09:06:20.067Z","owner":"inlong"},{"_id":"63da3fa59bbc4bafa3d424da","ID":"CVE-2023-24998","title":"FileUpload DoS with excessive parts","state":"PUBLIC","updated":"2023-02-23T09:34:40.480Z","owner":"commons"},{"_id":"63dd02879bbc4bafa3d42677","ID":"CVE-2023-25141","title":"JNDI injection into Apache sling-org-apache-sling-jcr-base","state":"PUBLIC","updated":"2023-02-14T10:19:00.558Z","owner":"sling"},{"_id":"63dfd7659bbc4bafa3d42758","ID":"CVE-2023-25194","title":"Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration using Kafka Connect ","state":"PUBLIC","updated":"2023-07-21T11:35:22.991Z","owner":"kafka"},{"_id":"63e058959bbc4bafa3d42856","ID":"CVE-2023-25195","title":"SSRF template type vulnerability in certain authenticated users","state":"PUBLIC","updated":"2023-03-28T11:16:21.425Z","owner":"fineract"},{"_id":"63e058c69bbc4bafa3d42858","ID":"CVE-2023-25196","title":"SQL injection vulnerability ","state":"PUBLIC","updated":"2023-03-28T11:16:50.126Z","owner":"fineract"},{"_id":"63e058eb9bbc4bafa3d4285a","ID":"CVE-2023-25197","title":"SQL injection vulnerability in certain procedure calls ","state":"PUBLIC","updated":"2023-03-28T11:17:16.072Z","owner":"fineract"},{"_id":"63e16e939bbc4bafa3d4294b","ID":"CVE-2023-25504","title":"Possible SSRF on import datasets","state":"PUBLIC","updated":"2023-04-17T16:29:38.744Z","owner":"superset"},{"_id":"63e360529bbc4bafa3d42a5f","ID":"CVE-2023-25601","title":"Apache DolphinScheduler 3.0.0 to 3.1.1 python gateway has improper authentication","state":"PUBLIC","updated":"2023-04-20T15:06:54.846Z","owner":"dolphinscheduler"},{"_id":"63e4c13d9bbc4bafa3d42b74","ID":"CVE-2023-25613","title":"LDAP Injection Vulnerability in Apache Kerby","state":"PUBLIC","updated":"2024-01-18T09:14:01.669Z","owner":"directory"},{"_id":"63e504c29bbc4bafa3d42b9f","ID":"CVE-2023-25621","title":"Apache Sling does not allow to handle i18n content in a secure way","state":"PUBLIC","updated":"2023-02-23T08:41:12.080Z","owner":"sling"},{"_id":"63e8e97f9bbc4bafa3d42c39","ID":"CVE-2023-25690","title":"HTTP request splitting with mod_rewrite and mod_proxy","state":"PUBLIC","updated":"2023-03-07T15:08:45.400Z","owner":"httpd"},{"_id":"63e955a79bbc4bafa3d42c43","ID":"CVE-2023-25691","title":"Google Cloud Sql Provider Remote Command Execution","state":"PUBLIC","updated":"2023-02-24T11:35:47.925Z","owner":"airflow"},{"_id":"63e96eff9bbc4bafa3d42c5f","ID":"CVE-2023-25692","title":"Google Cloud Sql Provider Denial Of Service","state":"PUBLIC","updated":"2023-02-24T11:47:58.411Z","owner":"airflow"},{"_id":"63e976359bbc4bafa3d42c69","ID":"CVE-2023-25693","title":"Sqoop Apache Airflow Provider Remote Code Execution Vulnerability","state":"PUBLIC","updated":"2023-02-24T11:48:09.839Z","owner":"airflow"},{"_id":"63e9828a9bbc4bafa3d42c7d","ID":"CVE-2023-25695","title":"Information disclosure in Apache Airflow","state":"PUBLIC","updated":"2023-03-15T09:37:07.873Z","owner":"airflow"},{"_id":"63e99b769bbc4bafa3d42c8b","ID":"CVE-2023-25696","title":"Apache Airflow Hive Provider Beeline RCE","state":"PUBLIC","updated":"2023-02-24T11:48:19.499Z","owner":"airflow"},{"_id":"63ea45c69bbc4bafa3d42cef","ID":"CVE-2023-25753","title":"Server-Side Request Forgery in Apache ShenYu","state":"PUBLIC","updated":"2023-10-19T08:35:28.691Z","owner":"shenyu"},{"_id":"63ea4deb9bbc4bafa3d42d21","ID":"CVE-2023-25754","title":"Privilege escalation using airflow logs","state":"PUBLIC","updated":"2023-05-08T11:57:41.997Z","owner":"airflow"},{"_id":"63ef52f39bbc4bafa3d42fe1","ID":"CVE-2023-25956","title":"Arbitrary file read via AWS provider","state":"PUBLIC","updated":"2023-03-07T08:23:39.736Z","owner":"airflow"},{"_id":"63efd8049bbc4bafa3d42fe3","ID":"CVE-2023-26031","title":"Privilege escalation in Apache Hadoop Yarn container-executor binary on Linux systems","state":"PUBLIC","updated":"2024-12-31T00:51:13.948Z","owner":"hadoop"},{"_id":"63f47ea39bbc4bafa3d4319f","ID":"CVE-2023-26268","title":"Information sharing via couchjs processes","state":"PUBLIC","updated":"2023-12-12T22:58:48.382Z","owner":"couchdb"},{"_id":"63f485569bbc4bafa3d431a9","ID":"CVE-2023-26269","title":"Privilege escalation through unauthenticated JMX","state":"PUBLIC","updated":"2023-04-03T07:59:07.659Z","owner":"james"},{"_id":"63f7910b59a8d61f6ce48dff","ID":"CVE-2023-26464","title":"Apache Log4j 1.x (EOL) allows DoS in Chainsaw and SocketAppender","state":"PUBLIC","updated":"2023-04-20T07:55:37.341Z","owner":"logging"},{"_id":"63f8789959a8d61f6ce491cd","ID":"CVE-2023-26512","title":"Apache EventMesh RabbitMQ-Connector plugin allows RCE through deserialization of untrusted data","state":"PUBLIC","updated":"2023-07-27T09:32:16.269Z","owner":"eventmesh"},{"_id":"63f890fd59a8d61f6ce49258","ID":"CVE-2023-26513","title":"Requests to certain paths managed by the Apache Sling Resource Merger can lead to DoS","state":"PUBLIC","updated":"2023-03-20T12:19:53.778Z","owner":"sling"},{"_id":"63fd6b4b59a8d61f6ce493bd","ID":"CVE-2023-27296","title":"JDBC Deserialization Vulnerability in InLong","state":"PUBLIC","updated":"2023-03-27T08:57:01.107Z","owner":"inlong"},{"_id":"6400958f59a8d61f6ce4964e","ID":"CVE-2023-27522","title":"mod_proxy_uwsgi HTTP response splitting","state":"PUBLIC","updated":"2023-03-07T15:09:26.534Z","owner":"httpd"},{"_id":"64009c9059a8d61f6ce49654","ID":"CVE-2023-27523","title":"Improper data permission validation on Jinja templated queries","state":"PUBLIC","updated":"2023-09-06T09:50:25.921Z","owner":"superset"},{"_id":"6400a47359a8d61f6ce496ac","ID":"CVE-2023-27524","title":"Session validation vulnerability when using provided default SECRET_KEY","state":"PUBLIC","updated":"2024-04-08T09:07:29.864Z","owner":"superset"},{"_id":"6400ada459a8d61f6ce49717","ID":"CVE-2023-27525","title":"Incorrect default permissions for Gamma role","state":"PUBLIC","updated":"2023-04-17T16:27:58.172Z","owner":"superset"},{"_id":"6400af8659a8d61f6ce49742","ID":"CVE-2023-27526","title":"Improper Authorization check on import charts","state":"PUBLIC","updated":"2023-09-06T09:49:27.778Z","owner":"superset"},{"_id":"6403218b6b36e903c1bf967b","ID":"CVE-2023-27602","title":"Apache Linkis publicsercice module unrestricted upload of file","state":"PUBLIC","updated":"2023-04-11T03:15:38.418Z","owner":"linkis"},{"_id":"6403221f6b36e903c1bf968e","ID":"CVE-2023-27603","title":"Apache Linkis Mangaer module engineConn material upload exists Zip Slip issue","state":"PUBLIC","updated":"2023-04-14T07:17:48.297Z","owner":"linkis"},{"_id":"6403760e6b36e903c1bf96a6","ID":"CVE-2023-27604","title":"Airflow Sqoop Provider RCE Vulnerability","state":"PUBLIC","updated":"2023-08-28T07:47:27.394Z","owner":"airflow"},{"_id":"640990bf6b36e903c1bf99bb","ID":"CVE-2023-27987","title":"Apache Linkis gateway module token authentication bypass","state":"PUBLIC","updated":"2023-04-14T07:51:52.905Z","owner":"linkis"},{"_id":"640e8c726b36e903c1bf9afb","ID":"CVE-2023-28158","title":"Apache Archiva privilege escalation","state":"PUBLIC","updated":"2023-03-29T12:21:30.415Z","owner":"archiva"},{"_id":"64103da86b36e903c1bf9bb2","ID":"CVE-2023-28326","title":"allows user impersonation","state":"PUBLIC","updated":"2023-03-28T14:34:57.762Z","owner":"openmeetings"},{"_id":"6419cc096b36e903c1bf9e44","ID":"CVE-2023-28706","title":"Apache Airflow Hive Provider Beeline Remote Command Execution","state":"PUBLIC","updated":"2023-04-07T14:54:35.049Z","owner":"airflow"},{"_id":"6419d9566b36e903c1bf9e89","ID":"CVE-2023-28707","title":"Airflow Apache Drill Provider Arbitrary File Read Vulnerability","state":"PUBLIC","updated":"2023-04-07T14:53:21.428Z","owner":"airflow"},{"_id":"6419e8c46b36e903c1bf9eb4","ID":"CVE-2023-28708","title":"JSESSIONID Cookie missing secure attribute in some configurations","state":"PUBLIC","updated":"2025-10-29T12:07:08.322Z","owner":"tomcat"},{"_id":"6419e94f6b36e903c1bf9ec0","ID":"CVE-2023-28709","title":"Fix for CVE-2023-24998 is incomplete","state":"PUBLIC","updated":"2023-05-22T10:09:00.405Z","owner":"tomcat"},{"_id":"641a0ebb6b36e903c1bf9ece","ID":"CVE-2023-28710","title":"Apache Airflow Spark Provider Arbitrary File Read via JDBC","state":"PUBLIC","updated":"2023-04-07T14:55:42.112Z","owner":"airflow"},{"_id":"641bba926b36e903c1bf9ffb","ID":"CVE-2023-28754","title":"Deserialization vulnerability in ShardingSphere Agent","state":"PUBLIC","updated":"2023-07-19T07:15:27.885Z","owner":"shardingsphere"},{"_id":"6422d0596b36e903c1bfa4f7","ID":"CVE-2023-28935","title":"DUCC (EOL) allows RCE","state":"PUBLIC","updated":"2023-03-30T09:10:09.175Z","owner":"uima"},{"_id":"64230b0a6b36e903c1bfa538","ID":"CVE-2023-28936","title":"insufficient check of invitation hash","state":"PUBLIC","updated":"2023-05-12T01:19:31.368Z","owner":"openmeetings"},{"_id":"6425126a6b36e903c1bfa6f0","ID":"CVE-2023-29032","title":"allows bypass authentication","state":"PUBLIC","updated":"2023-05-12T01:19:51.993Z","owner":"openmeetings"},{"_id":"64257f516b36e903c1bfa77c","ID":"CVE-2023-29055","title":"Insufficiently protected credentials in config file","state":"PUBLIC","updated":"2024-01-29T12:20:52.048Z","owner":"kylin"},{"_id":"642ae765746394764120c1bd","ID":"CVE-2023-29215","title":"Apache Linkis JDBC EngineCon  has a deserialization command execution","state":"PUBLIC","updated":"2023-04-10T07:35:21.175Z","owner":"linkis"},{"_id":"642aeaee746394764120c1f8","ID":"CVE-2023-29216","title":"Apache Linkis DatasourceManager module has a deserialization command execution","state":"PUBLIC","updated":"2024-07-13T14:57:28.538Z","owner":"linkis"},{"_id":"642bee5d746394764120c2d1","ID":"CVE-2023-29234","title":"Bypass serialize checks in Apache Dubbo","state":"PUBLIC","updated":"2023-12-15T05:49:00.876Z","owner":"dubbo"},{"_id":"642c42b7746394764120c3d4","ID":"CVE-2023-29246","title":"allows null-byte Injection","state":"PUBLIC","updated":"2023-05-12T01:21:14.732Z","owner":"openmeetings"},{"_id":"642c599e746394764120c419","ID":"CVE-2023-29247","title":"Stored XSS on Apache Airflow","state":"PUBLIC","updated":"2023-05-08T09:01:33.604Z","owner":"airflow"},{"_id":"6430dd89746394764120c89e","ID":"CVE-2023-30428","title":"Incorrect Authorization Validation for Rest Producer","state":"PUBLIC","updated":"2023-07-12T09:11:23.044Z","owner":"pulsar"},{"_id":"6430dfcc746394764120c8a8","ID":"CVE-2023-30429","title":"Incorrect Authorization for Function Worker when using mTLS Authentication through Pulsar Proxy","state":"PUBLIC","updated":"2023-07-12T09:08:18.670Z","owner":"pulsar"},{"_id":"6433d0f4746394764120ca05","ID":"CVE-2023-30465","title":"SQL injection in apache inLong 1.5.0","state":"PUBLIC","updated":"2023-04-11T14:18:47.907Z","owner":"inlong"},{"_id":"64371a62746394764120ce5c","ID":"CVE-2023-30575","title":"Incorrect calculation of Guacamole protocol element lengths","state":"PUBLIC","updated":"2023-06-15T07:27:08.313Z","owner":"guacamole"},{"_id":"64371adc746394764120ce62","ID":"CVE-2023-30576","title":"Use-after-free in handling of RDP audio input buffer","state":"PUBLIC","updated":"2023-06-06T17:26:55.108Z","owner":"guacamole"},{"_id":"6437b5b5746394764120cea8","ID":"CVE-2023-30601","title":"Privilege escalation when enabling FQL/Audit logs","state":"PUBLIC","updated":"2023-05-30T07:25:46.970Z","owner":"cassandra"},{"_id":"6438456a746394764120cee9","ID":"CVE-2023-30631","title":"Configuration option to block the PUSH method in ATS didn't work","state":"PUBLIC","updated":"2023-06-14T07:44:52.725Z","owner":"trafficserver"},{"_id":"643b5f43746394764120d03d","ID":"CVE-2023-30771","title":"apache/iotdb-web-workbench: forge the JWTToken to access workbench","state":"PUBLIC","updated":"2023-04-17T07:26:11.955Z","owner":"iotdb"},{"_id":"643d31c6746394764120d201","ID":"CVE-2023-30776","title":"Database connection password leak","state":"PUBLIC","updated":"2023-06-15T07:29:48.154Z","owner":"superset"},{"_id":"643fc5e0746394764120d30d","ID":"CVE-2023-30867","title":"Authenticated system users could trigger SQL injection vulnerability","state":"PUBLIC","updated":"2023-12-15T12:13:59.544Z","owner":"streampark"},{"_id":"6442ee8f746394764120d4b1","ID":"CVE-2023-31007","title":"Broker does not always disconnect client when authentication data expires","state":"PUBLIC","updated":"2023-07-13T08:27:41.124Z","owner":"pulsar"},{"_id":"64442438746394764120d50b","ID":"CVE-2023-31038","title":"SQL injection when using ODBC appender","state":"PUBLIC","updated":"2023-05-08T08:55:53.262Z","owner":"logging"},{"_id":"6444a5d8746394764120d53b","ID":"CVE-2023-31039","title":"ServerOptions.pid_file may cause arbitrary code execution","state":"PUBLIC","updated":"2023-05-08T08:57:09.633Z","owner":"brpc"},{"_id":"6445e865746394764120d5b3","ID":"CVE-2023-31058","title":"JDBC URL bypassing by adding blanks","state":"PUBLIC","updated":"2023-05-22T15:48:32.710Z","owner":"inlong"},{"_id":"6445ecbe746394764120d5f5","ID":"CVE-2023-31062","title":"Privilege escalation vulnerability for InLong","state":"PUBLIC","updated":"2023-05-22T15:47:33.464Z","owner":"inlong"},{"_id":"6445f05e746394764120d64d","ID":"CVE-2023-31064","title":"Insecurity direct object references cancelling applications","state":"PUBLIC","updated":"2023-05-22T15:44:19.190Z","owner":"inlong"},{"_id":"6445f510746394764120d677","ID":"CVE-2023-31065","title":"Insufficient Session Expiration in InLong","state":"PUBLIC","updated":"2023-05-22T15:40:53.524Z","owner":"inlong"},{"_id":"6445f873746394764120d69b","ID":"CVE-2023-31066","title":"Insecure direct object references for inlong sources","state":"PUBLIC","updated":"2023-05-22T15:35:37.675Z","owner":"inlong"},{"_id":"64461dec746394764120d6cd","ID":"CVE-2023-31098","title":"Weak Password Implementation in InLong","state":"PUBLIC","updated":"2023-05-22T15:31:51.278Z","owner":"inlong"},{"_id":"64461f64746394764120d718","ID":"CVE-2023-31101","title":"Users who joined later can see the data of deleted users","state":"PUBLIC","updated":"2023-05-22T15:18:30.325Z","owner":"inlong"},{"_id":"644620ae746394764120d750","ID":"CVE-2023-31103","title":"Attackers can change the immutable name and type of cluster","state":"PUBLIC","updated":"2023-05-22T15:13:26.771Z","owner":"inlong"},{"_id":"6446be7711bbb5d8dafe1d9f","ID":"CVE-2023-31122","title":"mod_macro buffer over-read","state":"PUBLIC","updated":"2023-10-23T06:51:56.755Z","owner":"httpd"},{"_id":"644747d911bbb5d8dafe1e01","ID":"CVE-2023-31206","title":"Attackers can change the immutable name and type of nodes","state":"PUBLIC","updated":"2023-05-22T13:58:15.628Z","owner":"inlong"},{"_id":"644b973255591d607b0a144e","ID":"CVE-2023-31453","title":"IDOR make users can delete others' subscription","state":"PUBLIC","updated":"2023-05-22T13:25:45.562Z","owner":"inlong"},{"_id":"644b989055591d607b0a1466","ID":"CVE-2023-31454","title":"IDOR make users can bind any cluster","state":"PUBLIC","updated":"2023-05-22T13:22:59.589Z","owner":"inlong"},{"_id":"644c1a9255591d607b0a1482","ID":"CVE-2023-31469","title":"Privilege escalation through non-admin user","state":"PUBLIC","updated":"2023-06-23T07:07:40.534Z","owner":"streampipes"},{"_id":"644fd4d855591d607b0a1582","ID":"CVE-2023-32007","title":"Shell command injection via Spark UI","state":"PUBLIC","updated":"2023-05-02T08:37:02.283Z","owner":"spark"},{"_id":"6453a9de55591d607b0a193a","ID":"CVE-2023-32200","title":"Exposure of execution in script engine expressions.","state":"PUBLIC","updated":"2023-07-12T07:50:01.786Z","owner":"jena"},{"_id":"645cfb1f55591d607b0a1cf6","ID":"CVE-2023-32672","title":"SQL parser edge case bypasses data access authorization","state":"PUBLIC","updated":"2023-09-06T13:15:55.981Z","owner":"superset"},{"_id":"64637ba355591d607b0a1e97","ID":"CVE-2023-33008","title":"Prevent inefficient internal conversion from BigDecimal at large scale","state":"PUBLIC","updated":"2023-07-07T09:07:15.097Z","owner":"johnzon"},{"_id":"6466793b55591d607b0a1fe9","ID":"CVE-2023-33234","title":"KubernetesPodOperator RCE via connection configuration","state":"PUBLIC","updated":"2023-05-30T10:56:52.167Z","owner":"airflow"},{"_id":"6469d25c55591d607b0a20de","ID":"CVE-2023-33246","title":"Possible remote code execution vulnerability when using the update configuration function","state":"PUBLIC","updated":"2023-05-24T14:45:21.368Z","owner":"rocketmq"},{"_id":"646ce8cd55591d607b0a266b","ID":"CVE-2023-33933","title":"s3_auth plugin problem with hash calculation","state":"PUBLIC","updated":"2023-08-31T19:49:23.749Z","owner":"trafficserver"},{"_id":"646d2aa755591d607b0a26b0","ID":"CVE-2023-33934","title":"Differential fuzzing for HTTP request parsing discrepancies","state":"PUBLIC","updated":"2023-09-28T08:24:06.964Z","owner":"trafficserver"},{"_id":"64731fd56f9427011c9b79ed","ID":"CVE-2023-34149","title":"DoS via OOM owing to not properly checking of list bounds","state":"PUBLIC","updated":"2023-06-14T07:48:49.995Z","owner":"struts"},{"_id":"647372fc6f9427011c9b7a01","ID":"CVE-2023-34150","title":"Possible excessive allocation of resources reading input.","state":"PUBLIC","updated":"2023-07-14T08:51:32.515Z","owner":"any23"},{"_id":"647555f86f9427011c9b7a5b","ID":"CVE-2023-34189","title":"General user can delete and update process","state":"PUBLIC","updated":"2023-07-25T07:08:51.094Z","owner":"inlong"},{"_id":"647620bcc19b1ea341facdd6","ID":"CVE-2023-34212","title":"Potential Deserialization of Untrusted Data with JNDI in JMS Components","state":"PUBLIC","updated":"2023-06-12T15:10:30.889Z","owner":"nifi"},{"_id":"6478e91021f9f903aa0d4c4b","ID":"CVE-2023-34340","title":"Accumulo 2.1.0 may incorrectly validate cached credentials","state":"PUBLIC","updated":"2023-06-21T07:01:43.546Z","owner":"accumulo"},{"_id":"647b5b950292e903af3d9e81","ID":"CVE-2023-34395","title":"Remote code execution vulnerability","state":"PUBLIC","updated":"2023-06-27T11:36:51.331Z","owner":"airflow"},{"_id":"647c3e680292e903af3d9ea2","ID":"CVE-2023-34396","title":"DoS via OOM owing to no sanity limit on normal form fields in multipart forms","state":"PUBLIC","updated":"2023-06-14T07:50:57.318Z","owner":"struts"},{"_id":"647f15690292e903af3d9ff3","ID":"CVE-2023-34434","title":"JDBC URL bypassing by allowLoadLocalInfileInPath param","state":"PUBLIC","updated":"2023-07-25T07:09:55.864Z","owner":"inlong"},{"_id":"647f4be90292e903af3da043","ID":"CVE-2023-34442","title":"Temporary file information disclosure in Camel-Jira","state":"PUBLIC","updated":"2023-07-10T09:31:01.757Z","owner":"camel"},{"_id":"647f6d2f0292e903af3da0d5","ID":"CVE-2023-34468","title":"Potential Code Injection with Database Services using H2","state":"PUBLIC","updated":"2023-06-12T15:09:17.702Z","owner":"nifi"},{"_id":"6480d15f0292e903af3da1c7","ID":"CVE-2023-34478","title":"Apache Shiro before 1.12.0, or 2.0.0-alpha-3, may be susceptible to a path traversal attack when used together with APIs or other web frameworks that route requests based on non-normalized requests.","state":"PUBLIC","updated":"2023-07-24T18:24:43.013Z","owner":"shiro"},{"_id":"6481ce1c0292e903af3da214","ID":"CVE-2023-34981","title":"AJP response header mix-up","state":"PUBLIC","updated":"2023-06-21T10:26:13.887Z","owner":"tomcat"},{"_id":"648350860292e903af3da276","ID":"CVE-2023-35005","title":"Information disclosure on configuration view","state":"PUBLIC","updated":"2023-06-19T08:15:11.464Z","owner":"airflow"},{"_id":"6488467b0292e903af3da447","ID":"CVE-2023-35088","title":"SQL injection in audit endpoint","state":"PUBLIC","updated":"2023-07-25T07:10:17.507Z","owner":"inlong"},{"_id":"648b0a8b0292e903af3da660","ID":"CVE-2023-35701","title":"Arbitrary command execution via JDBC driver","state":"PUBLIC","updated":"2024-05-03T08:11:05.595Z","owner":"hive"},{"_id":"648e0b5a6858c603adea0f3e","ID":"CVE-2023-35797","title":"Apache Airflow Hive Provider Beeline RCE with Principal","state":"PUBLIC","updated":"2023-07-03T09:08:49.038Z","owner":"airflow"},{"_id":"648e10ce6858c603adea0f6c","ID":"CVE-2023-35798","title":"Airflow Apache ODBC and MSSQL Providers Arbitrary File Read Vulnerability","state":"PUBLIC","updated":"2023-06-27T11:39:49.794Z","owner":"airflow"},{"_id":"649079216858c603adea0fe8","ID":"CVE-2023-35887","title":"Information disclosure bugs with RootedFilesystem","state":"PUBLIC","updated":"2023-07-19T07:18:05.211Z","owner":"mina"},{"_id":"64911a9f6858c603adea1084","ID":"CVE-2023-35908","title":"Access to DAGs without relevant permission","state":"PUBLIC","updated":"2023-07-12T09:14:08.022Z","owner":"airflow"},{"_id":"649303ebcd49112d28eedb10","ID":"CVE-2023-36387","title":"Improper API permission for low privilege users","state":"PUBLIC","updated":"2023-10-17T07:53:17.128Z","owner":"superset"},{"_id":"649309cccd49112d28eedb54","ID":"CVE-2023-36388","title":"Improper API permission for low privilege users allows for SSRF","state":"PUBLIC","updated":"2023-09-06T12:53:55.132Z","owner":"superset"},{"_id":"6494b9eccd49112d28eedc0e","ID":"CVE-2023-36542","title":"Potential Code Injection with Properties Referencing Remote Resources","state":"PUBLIC","updated":"2023-07-29T07:12:37.941Z","owner":"nifi"},{"_id":"6494e7f4cd49112d28eedc4f","ID":"CVE-2023-36543","title":"ReDoS via dags function","state":"PUBLIC","updated":"2023-07-21T10:49:41.270Z","owner":"airflow"},{"_id":"64a3ff2c83913f03aec27b6d","ID":"CVE-2023-37379","title":"Exposure of sensitive connection information, DOS and SSRF on \"test connection\" feature","state":"PUBLIC","updated":"2023-08-23T15:38:53.691Z","owner":"airflow"},{"_id":"64a5a17883913f03aec27bdc","ID":"CVE-2023-37415","title":"Improper Input Validation in Hive Provider with proxy_user","state":"PUBLIC","updated":"2023-07-13T07:35:30.726Z","owner":"airflow"},{"_id":"64a7a8d983913f03aec27d28","ID":"CVE-2023-37544","title":"Improper Authentication for WebSocket Proxy Endpoint Allows DoS","state":"PUBLIC","updated":"2023-12-20T08:33:58.071Z","owner":"pulsar"},{"_id":"64a88a8183913f03aec2805d","ID":"CVE-2023-37579","title":"Incorrect Authorization for Function Worker Can Leak Sink/Source Credentials","state":"PUBLIC","updated":"2023-07-12T09:05:20.256Z","owner":"pulsar"},{"_id":"64a9d3f183913f03aec28118","ID":"CVE-2023-37581","title":"Roller's weblog category, weblog settings and file-upload features did not properly sanitize input could be exploited to perform Reflected Cross Site Scripting (XSS) even on a Roller site configured for untrusted users.","state":"PUBLIC","updated":"2023-08-24T08:15:22.581Z","owner":"roller"},{"_id":"64aa99fa83913f03aec28181","ID":"CVE-2023-37582","title":"Possible remote code execution when using the update configuration function","state":"PUBLIC","updated":"2023-07-12T09:26:16.623Z","owner":"rocketmq"},{"_id":"64ac449983913f03aec2828c","ID":"CVE-2023-37895","title":"Apache Jackrabbit RMI access can lead to RCE","state":"PUBLIC","updated":"2023-07-25T14:02:07.695Z","owner":"jackrabbit"},{"_id":"64ac9bc483913f03aec283a0","ID":"CVE-2023-37924","title":"SQL injection from unauthorized login","state":"PUBLIC","updated":"2023-11-22T09:19:18.697Z","owner":"submarine"},{"_id":"64ad23d683913f03aec286b5","ID":"CVE-2023-37941","title":"Metadata db write access can lead to remote code execution","state":"PUBLIC","updated":"2023-09-29T16:22:05.089Z","owner":"superset"},{"_id":"64b60cdac7f9bc8c1e10dac1","ID":"CVE-2023-38435","title":"XSS in healthcheck webconsole plugin","state":"PUBLIC","updated":"2023-07-31T08:08:18.396Z","owner":"felix"},{"_id":"64b6eee0c7f9bc8c1e10db33","ID":"CVE-2023-38522","title":"Incomplete field name check allows request smuggling","state":"PUBLIC","updated":"2024-08-13T08:46:41.192Z","owner":"trafficserver"},{"_id":"64babebfc7f9bc8c1e10de0c","ID":"CVE-2023-38647","title":"Deserialization vulnerability in Helix workflow and REST","state":"PUBLIC","updated":"2023-07-26T07:52:23.420Z","owner":"helix"},{"_id":"64beba16c7f9bc8c1e10decf","ID":"CVE-2023-38709","title":"HTTP response splitting","state":"PUBLIC","updated":"2025-01-17T11:15:18.205Z","owner":"httpd"},{"_id":"64bff253c7f9bc8c1e10e0ee","ID":"CVE-2023-39196","title":"Missing mutual TLS authentication in one of the service internal Ozone Storage Container Manager endpoints","state":"PUBLIC","updated":"2024-02-07T12:56:26.948Z","owner":"ozone"},{"_id":"64c13611c4724003ab4aa5ca","ID":"CVE-2023-39264","title":"Stack traces enabled by default","state":"PUBLIC","updated":"2023-09-06T12:58:57.264Z","owner":"superset"},{"_id":"64c13c06c4724003ab4aa626","ID":"CVE-2023-39265","title":"Possible Unauthorized Registration of SQLite Database Connections","state":"PUBLIC","updated":"2023-09-06T13:00:09.688Z","owner":"superset"},{"_id":"64c7f58943c0c17535d0213f","ID":"CVE-2023-39410","title":"Memory when deserializing untrusted data in Avro Java SDK","state":"PUBLIC","updated":"2025-02-06T14:33:53.747Z","owner":"avro"},{"_id":"64ca4b7343c0c17535d02218","ID":"CVE-2023-39441","title":"SMTP/IMAP client components allowed MITM due to missing Certificate Validation","state":"PUBLIC","updated":"2023-08-23T15:39:49.970Z","owner":"airflow"},{"_id":"64cac21943c0c17535d02253","ID":"CVE-2023-39456","title":"Malformed http/2 frames can cause an abort","state":"PUBLIC","updated":"2023-10-17T06:58:15.367Z","owner":"trafficserver"},{"_id":"64cb669943c0c17535d0226f","ID":"CVE-2023-39508","title":"Airflow \"Run task\" feature allows execution with unnecessary priviledges","state":"PUBLIC","updated":"2023-08-05T06:47:11.955Z","owner":"airflow"},{"_id":"64ce569d43c0c17535d02322","ID":"CVE-2023-39553","title":"Apache Airflow Drill Provider Arbitrary File Read Vulnerability","state":"PUBLIC","updated":"2023-08-11T18:42:20.040Z","owner":"airflow"},{"_id":"64d0b64643c0c17535d023d9","ID":"CVE-2023-39913","title":"Potential untrusted code execution when deserializing certain binary CAS formats","state":"PUBLIC","updated":"2023-11-08T08:04:19.712Z","owner":"uima"},{"_id":"64d26de443c0c17535d02437","ID":"CVE-2023-40037","title":"Incomplete Validation of JDBC and JNDI Connection URLs","state":"PUBLIC","updated":"2023-08-18T21:54:49.856Z","owner":"nifi"},{"_id":"64d4ad5743c0c17535d02502","ID":"CVE-2023-40195","title":"Apache Airflow Spark Provider Deserialization Vulnerability RCE","state":"PUBLIC","updated":"2023-08-28T07:49:59.173Z","owner":"airflow"},{"_id":"64d726e1cfe4a503ac50ffc5","ID":"CVE-2023-40272","title":"Apache Airflow Spark Provider Arbitrary File Read via JDBC","state":"PUBLIC","updated":"2023-08-17T13:52:26.145Z","owner":"airflow"},{"_id":"64d8f8c5cfe4a503ac51002b","ID":"CVE-2023-40273","title":"Session fixation in Apache Airflow web interface","state":"PUBLIC","updated":"2023-09-12T06:41:25.454Z","owner":"airflow"},{"_id":"64de18eecfe4a503ac51008b","ID":"CVE-2023-40610","title":"Privilege escalation with default examples database","state":"PUBLIC","updated":"2023-11-27T10:22:38.966Z","owner":"superset"},{"_id":"64de2829cfe4a503ac5100e1","ID":"CVE-2023-40611","title":"Apache Airflow Dag Runs Broken Access Control Vulnerability","state":"PUBLIC","updated":"2023-09-12T11:05:20.884Z","owner":"airflow"},{"_id":"64e269b5cfe4a503ac51024f","ID":"CVE-2023-40712","title":"Secrets can be unmasked in the \"Rendered Template\" ","state":"PUBLIC","updated":"2023-09-12T11:05:46.999Z","owner":"airflow"},{"_id":"64e35363cfe4a503ac51033d","ID":"CVE-2023-40743","title":"Apache Axis 1.x (EOL) may allow RCE when untrusted input is passed to getService","state":"PUBLIC","updated":"2023-09-05T14:42:08.579Z","owner":"axis"},{"_id":"64e4fcafcfe4a503ac510522","ID":"CVE-2023-41080","title":"Open redirect with FORM authentication","state":"PUBLIC","updated":"2025-10-29T12:04:38.029Z","owner":"tomcat"},{"_id":"64e4ffe0cfe4a503ac51052b","ID":"CVE-2023-41081","title":"Unexpected use of first declared worker in mod_jk for unmapped request","state":"PUBLIC","updated":"2023-09-28T21:30:55.612Z","owner":"tomcat"},{"_id":"64e77571cfe4a503ac5106f9","ID":"CVE-2023-41180","title":"Incorrect Certificate Validation in InvokeHTTP for MiNiFi C++","state":"PUBLIC","updated":"2023-09-03T15:52:48.640Z","owner":"nifi"},{"_id":"64ebbfcdcfe4a503ac5108b7","ID":"CVE-2023-41267","title":"Apache HDFS Provider error message suggested installation of incorrect pip package","state":"PUBLIC","updated":"2023-09-14T07:46:36.891Z","owner":"airflow"},{"_id":"64ecc137cfe4a503ac5109b7","ID":"CVE-2023-41313","title":"Timing Attack weakness","state":"PUBLIC","updated":"2024-03-12T10:16:14.512Z","owner":"doris"},{"_id":"64ecc2aecfe4a503ac5109b9","ID":"CVE-2023-41314","title":"Missing API authentication allowed DoS","state":"PUBLIC","updated":"2023-12-18T08:27:49.193Z","owner":"doris"},{"_id":"64f0fe320cb38103bcc28ad7","ID":"CVE-2023-41752","title":"s3_auth plugin problem with hash calculation","state":"PUBLIC","updated":"2023-10-17T06:57:44.046Z","owner":"trafficserver"},{"_id":"64f24be00cb38103bcc28b9f","ID":"CVE-2023-41834","title":"Apache Flink Stateful Functions allowed HTTP header injection due to Improper Neutralization of CRLF Sequences","state":"PUBLIC","updated":"2023-09-19T12:34:13.497Z","owner":"flink"},{"_id":"64f58cef0cb38103bcc28c25","ID":"CVE-2023-41835","title":"excessive disk usage","state":"PUBLIC","updated":"2023-12-12T08:42:17.762Z","owner":"struts"},{"_id":"64f6de0bc0d8cf03ac5a9737","ID":"CVE-2023-41916","title":"DatasourceManager module has a  JDBC parameter judgment logic vulnerability that allows for arbitrary file reading","state":"PUBLIC","updated":"2024-07-15T07:53:56.163Z","owner":"linkis"},{"_id":"64fed7ca5e1f7fc024a52abb","ID":"CVE-2023-42501","title":"Unnecessary read permissions within the Gamma role","state":"PUBLIC","updated":"2023-11-27T10:23:45.368Z","owner":"superset"},{"_id":"64fef7e15e1f7fc024a52af1","ID":"CVE-2023-42502","title":"Open Redirect Vulnerability","state":"PUBLIC","updated":"2023-11-28T16:25:40.797Z","owner":"superset"},{"_id":"64ff012c5e1f7fc024a52b47","ID":"CVE-2023-42503","title":"Denial of service via CPU consumption for malformed TAR file","state":"PUBLIC","updated":"2023-09-14T07:45:08.532Z","owner":"commons"},{"_id":"64ff03ab5e1f7fc024a52b57","ID":"CVE-2023-42504","title":"Lack of rate limiting allows for possible denial of service","state":"PUBLIC","updated":"2023-11-29T09:18:09.316Z","owner":"superset"},{"_id":"64ff09445e1f7fc024a52bad","ID":"CVE-2023-42505","title":"Sensitive information disclosure on db connection details","state":"PUBLIC","updated":"2023-11-28T16:26:56.352Z","owner":"superset"},{"_id":"6500b5e85e1f7fc024a52d2e","ID":"CVE-2023-42663","title":"Bypass permission verification to view task instances of other dags","state":"PUBLIC","updated":"2023-10-14T09:47:24.055Z","owner":"airflow"},{"_id":"6502a8125e1f7fc024a52e46","ID":"CVE-2023-42780","title":"Improper access control vulnerability in the \"List dag warnings\" feature","state":"PUBLIC","updated":"2023-10-14T09:46:05.032Z","owner":"airflow"},{"_id":"6502afde5e1f7fc024a52e4c","ID":"CVE-2023-42781","title":"Permission verification bypass allows viewing dagruns of other dags","state":"PUBLIC","updated":"2023-11-12T13:14:05.928Z","owner":"airflow"},{"_id":"6502d3255e1f7fc024a52e9e","ID":"CVE-2023-42792","title":"Improper access control to DAG resources","state":"PUBLIC","updated":"2023-10-14T09:47:04.851Z","owner":"airflow"},{"_id":"6502f7215e1f7fc024a52ec1","ID":"CVE-2023-42794","title":"FileUpload: DoS due to accumulation of temporary files on Windows","state":"PUBLIC","updated":"2025-10-29T12:04:08.371Z","owner":"tomcat"},{"_id":"6502f86e5e1f7fc024a52ec3","ID":"CVE-2023-42795","title":"Failure during request clean-up leads to sensitive data leaking to subsequent requests","state":"PUBLIC","updated":"2025-10-29T12:02:56.986Z","owner":"tomcat"},{"_id":"65082dd95e1f7fc024a52f3a","ID":"CVE-2023-43123","title":"Local Information Disclosure Vulnerability in Storm-core on Unix-Like systems due temporary files","state":"PUBLIC","updated":"2023-11-23T09:16:32.695Z","owner":"storm"},{"_id":"650aa3116cc91403ba4272b5","ID":"CVE-2023-43622","title":"DoS in HTTP/2 with initial windows size 0","state":"PUBLIC","updated":"2023-10-23T06:50:49.104Z","owner":"httpd"},{"_id":"650bb86c6cc91403ba427315","ID":"CVE-2023-43666","title":"General user Unauthorized access User Management","state":"PUBLIC","updated":"2023-10-16T01:54:42.830Z","owner":"inlong"},{"_id":"650bba8a6cc91403ba427334","ID":"CVE-2023-43667","title":"Log Injection in Global functions","state":"PUBLIC","updated":"2024-09-27T11:45:32.709Z","owner":"inlong"},{"_id":"650bbc866cc91403ba427350","ID":"CVE-2023-43668","title":"Jdbc Connection Security Bypass in InLong","state":"PUBLIC","updated":"2023-11-14T09:51:43.493Z","owner":"inlong"},{"_id":"650c2d046cc91403ba427400","ID":"CVE-2023-43701","title":"Stored XSS on API endpoint","state":"PUBLIC","updated":"2025-02-06T14:29:43.997Z","owner":"superset"},{"_id":"651105f96cc91403ba427463","ID":"CVE-2023-43826","title":"Integer overflow in handling of VNC image buffers","state":"PUBLIC","updated":"2023-12-19T19:50:08.611Z","owner":"guacamole"},{"_id":"65157cfb472cdec1e9207e14","ID":"CVE-2023-44312","title":"attacker can query all environment variables of the service-center server","state":"PUBLIC","updated":"2024-01-31T08:49:10.176Z","owner":"servicecomb"},{"_id":"65157d04472cdec1e9207e16","ID":"CVE-2023-44313","title":"attacker can perform SSRF through the frontend API","state":"PUBLIC","updated":"2024-01-31T08:49:43.083Z","owner":"servicecomb"},{"_id":"6516e7a0472cdec1e9207e78","ID":"CVE-2023-44483","title":"Private Key disclosure in debug-log output","state":"PUBLIC","updated":"2023-10-20T09:23:50.763Z","owner":"santuario"},{"_id":"651a830a472cdec1e9207f0f","ID":"CVE-2023-44981","title":"Authorization bypass in SASL Quorum Peer Authentication","state":"PUBLIC","updated":"2023-10-11T11:55:41.759Z","owner":"zookeeper"},{"_id":"65230447bff76503bb31c1f2","ID":"CVE-2023-45348","title":"Configuration information leakage vulnerability","state":"PUBLIC","updated":"2023-10-14T09:46:37.359Z","owner":"airflow"},{"_id":"65253603bff76503bb31c2a8","ID":"CVE-2023-45648","title":"Trailer header parsing too lenient","state":"PUBLIC","updated":"2025-10-29T12:00:45.261Z","owner":"tomcat"},{"_id":"6525c3a3bff76503bb31c3a9","ID":"CVE-2023-45725","title":"Privilege Escalation Using _design Documents","state":"PUBLIC","updated":"2023-12-13T08:02:15.239Z","owner":"couchdb"},{"_id":"6527bc30bff76503bb31c47c","ID":"CVE-2023-45757","title":"The builtin service rpcz page has an XSS attack vulnerability","state":"PUBLIC","updated":"2023-10-16T08:01:36.036Z","owner":"brpc"},{"_id":"6529116fbff76503bb31c55c","ID":"CVE-2023-45802","title":"HTTP/2 stream memory not reclaimed right away on RST","state":"PUBLIC","updated":"2024-10-14T09:01:43.211Z","owner":"httpd"},{"_id":"652d53c2bff76503bb31c998","ID":"CVE-2023-46104","title":"Allows for uncontrolled resource consumption via a ZIP bomb","state":"PUBLIC","updated":"2023-12-19T09:30:51.642Z","owner":"superset"},{"_id":"653056b1bff76503bb31ce13","ID":"CVE-2023-46215","title":"Sensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backend","state":"PUBLIC","updated":"2023-10-28T07:10:54.392Z","owner":"airflow"},{"_id":"653085b6bff76503bb31ce69","ID":"CVE-2023-46226","title":"Remote Code Execution (RCE) risk via the UDF","state":"PUBLIC","updated":"2024-01-15T10:36:23.883Z","owner":"iotdb"},{"_id":"65309186bff76503bb31cea1","ID":"CVE-2023-46227","title":"Apache inlong has an Arbitrary File Read Vulnerability","state":"PUBLIC","updated":"2023-10-19T09:40:37.360Z","owner":"inlong"},{"_id":"65322426bff76503bb31d0bd","ID":"CVE-2023-46279","title":"Bypass deny serialize list check in Apache Dubbo","state":"PUBLIC","updated":"2023-12-15T05:50:43.130Z","owner":"dubbo"},{"_id":"653299c2a9c90ab4b747718b","ID":"CVE-2023-46288","title":"Sensitive parameters exposed in API when \"non-sensitive-only\" configuration is set","state":"PUBLIC","updated":"2023-10-23T18:13:01.162Z","owner":"airflow"},{"_id":"6534e87984096103b5e078ee","ID":"CVE-2023-46302","title":"Fix CVE-2022-1471 SnakeYaml unsafe deserialization","state":"PUBLIC","updated":"2023-11-20T08:46:49.527Z","owner":"submarine"},{"_id":"65362b4984096103b5e07988","ID":"CVE-2023-46589","title":"HTTP request smuggling via malformed trailer headers","state":"PUBLIC","updated":"2025-10-29T12:00:21.984Z","owner":"tomcat"},{"_id":"6537868384096103b5e07a17","ID":"CVE-2023-46604","title":"Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack","state":"PUBLIC","updated":"2023-11-28T15:02:26.708Z","owner":"activemq"},{"_id":"6539648684096103b5e07a93","ID":"CVE-2023-46749","title":"Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting ","state":"PUBLIC","updated":"2024-01-19T18:12:43.905Z","owner":"shiro"},{"_id":"6539685084096103b5e07ab3","ID":"CVE-2023-46750","title":"URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Shiro.","state":"PUBLIC","updated":"2023-12-14T08:15:56.341Z","owner":"shiro"},{"_id":"653a764184096103b5e07b63","ID":"CVE-2023-46801","title":"DataSource Remote code execution vulnerability","state":"PUBLIC","updated":"2024-07-15T07:55:28.176Z","owner":"linkis"},{"_id":"653b64d284096103b5e07ba2","ID":"CVE-2023-46819","title":"Execution of Solr plugin queries without authentication","state":"PUBLIC","updated":"2023-12-04T16:11:06.466Z","owner":"ofbiz"},{"_id":"653be32a84096103b5e07cbf","ID":"CVE-2023-46851","title":"sensitive information exposure via import","state":"PUBLIC","updated":"2023-11-07T08:56:30.662Z","owner":"allura"},{"_id":"653f812884096103b5e07db2","ID":"CVE-2023-47037","title":"Apache Airflow missing fix for CVE-2023-40611 in 2.7.1 (DAG run broken access)","state":"PUBLIC","updated":"2023-11-12T13:12:20.076Z","owner":"airflow"},{"_id":"654692a9dabc5b03ae572ac7","ID":"CVE-2023-47248","title":"Arbitrary code execution when loading a malicious data file","state":"PUBLIC","updated":"2023-11-10T14:10:15.590Z","owner":"arrow"},{"_id":"6547cfabdabc5b03ae572b8e","ID":"CVE-2023-47265","title":"DAG Params alllow to embed unchecked Javascript","state":"PUBLIC","updated":"2023-12-21T09:28:05.966Z","owner":"airflow"},{"_id":"6550ca04dabc5b03ae5730c8","ID":"CVE-2023-47804","title":"Macro URL arbitrary script execution","state":"PUBLIC","updated":"2023-12-29T14:31:22.075Z","owner":"openoffice"},{"_id":"6553632edabc5b03ae573217","ID":"CVE-2023-48291","title":"Improper access control to DAG resources","state":"PUBLIC","updated":"2023-12-21T09:30:40.260Z","owner":"airflow"},{"_id":"6554f53bdabc5b03ae5732f2","ID":"CVE-2023-48362","title":"XXE Vulnerability in XML Format Reader","state":"PUBLIC","updated":"2024-07-24T07:45:42.417Z","owner":"drill"},{"_id":"6555bcefdabc5b03ae5733f7","ID":"CVE-2023-48396","title":"Authentication bypass","state":"PUBLIC","updated":"2024-07-30T08:15:30.810Z","owner":"seatunnel"},{"_id":"655ad837dabc5b03ae573551","ID":"CVE-2023-48796","title":"Sensitive information disclosure","state":"PUBLIC","updated":"2025-11-28T05:01:20.066Z","owner":"dolphinscheduler"},{"_id":"655c428bdabc5b03ae573696","ID":"CVE-2023-49068","title":"Information Leakage Vulnerability","state":"PUBLIC","updated":"2023-11-27T09:49:38.223Z","owner":"dolphinscheduler"},{"_id":"655c9cdb10b20203a9860fe2","ID":"CVE-2023-49070","title":"Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present","state":"PUBLIC","updated":"2023-12-20T10:48:11.952Z","owner":"ofbiz"},{"_id":"655db86f10b20203a9861115","ID":"CVE-2023-49109","title":"Remote Code Execution in Apache Dolphinscheduler","state":"PUBLIC","updated":"2024-02-20T06:02:40.133Z","owner":"dolphinscheduler"},{"_id":"655e5bab10b20203a986122c","ID":"CVE-2023-49145","title":"Improper Neutralization of Input in Advanced User Interface for Jolt","state":"PUBLIC","updated":"2023-11-27T22:29:16.184Z","owner":"nifi"},{"_id":"655f0fe810b20203a98612be","ID":"CVE-2023-49198","title":"Arbitrary file read vulnerability","state":"PUBLIC","updated":"2024-08-21T09:37:50.824Z","owner":"seatunnel"},{"_id":"656082b110b20203a986164a","ID":"CVE-2023-49250","title":"Insecure TLS TrustManager used in HttpUtil","state":"PUBLIC","updated":"2024-02-20T05:59:07.770Z","owner":"dolphinscheduler"},{"_id":"656317ee10b20203a9861766","ID":"CVE-2023-49299","title":"Arbitrary js execute as root for authenticated users","state":"PUBLIC","updated":"2023-12-30T16:30:14.065Z","owner":"dolphinscheduler"},{"_id":"65649125123040aec379fd8a","ID":"CVE-2023-49566","title":"JDBC Datasource Module with DB2 has JNDI Injection vulnerability","state":"PUBLIC","updated":"2024-07-15T07:56:41.397Z","owner":"linkis"},{"_id":"6564daf8123040aec379fe2a","ID":"CVE-2023-49582","title":"Unexpected lax shared memory permissions","state":"PUBLIC","updated":"2026-08-06T13:47:55.389Z","owner":"apr"},{"_id":"65658a09123040aec379fed6","ID":"CVE-2023-49619","title":"Repeated submissions using scripts resulted in an abnormal number of collections for questions.","state":"PUBLIC","updated":"2024-01-10T08:24:57.576Z","owner":"answer"},{"_id":"65659710123040aec379ff15","ID":"CVE-2023-49620","title":"Authenticated users could delete UDFs in resource center they were not authorized for","state":"PUBLIC","updated":"2023-11-30T08:16:57.761Z","owner":"dolphinscheduler"},{"_id":"65665dfb123040aec37a0193","ID":"CVE-2023-49657","title":"Stored XSS in Dashboard Title and Chart Title","state":"PUBLIC","updated":"2024-01-29T08:35:36.887Z","owner":"superset"},{"_id":"65686ceb123040aec37a02fa","ID":"CVE-2023-49733","title":"Apache Cocoon's StreamGenerator is vulnerable to XXE injection","state":"PUBLIC","updated":"2023-11-30T11:29:43.636Z","owner":"cocoon"},{"_id":"65688047123040aec37a0374","ID":"CVE-2023-49734","title":"Privilege Escalation Vulnerability","state":"PUBLIC","updated":"2023-12-19T09:52:11.087Z","owner":"superset"},{"_id":"65688a46123040aec37a0399","ID":"CVE-2023-49735","title":"Unvalidated input may lead to path traversal and XXE","state":"PUBLIC","updated":"2023-12-12T08:40:25.303Z","owner":"tiles"},{"_id":"65688b27123040aec37a039f","ID":"CVE-2023-49736","title":"SQL Injection on where_in JINJA macro","state":"PUBLIC","updated":"2023-12-19T09:33:08.370Z","owner":"superset"},{"_id":"65694f1d123040aec37a084e","ID":"CVE-2023-49898","title":"Authenticated system users could trigger remote command execution","state":"PUBLIC","updated":"2023-12-15T12:13:22.953Z","owner":"streampark"},{"_id":"656b4e54123040aec37a093f","ID":"CVE-2023-49920","title":"Missing CSRF protection on DAG/trigger","state":"PUBLIC","updated":"2023-12-21T09:27:07.715Z","owner":"airflow"},{"_id":"656d8fe5123040aec37a09a1","ID":"CVE-2023-50164","title":"File upload component had a directory traversal vulnerability","state":"PUBLIC","updated":"2023-12-12T09:26:27.763Z","owner":"struts"},{"_id":"656fdb85123040aec37a0b99","ID":"CVE-2023-50270","title":"Session do not expire after password change","state":"PUBLIC","updated":"2024-02-23T10:17:33.021Z","owner":"dolphinscheduler"},{"_id":"6570b0dc123040aec37a0bf5","ID":"CVE-2023-50290","title":"Host environment variables are published via the Metrics API","state":"PUBLIC","updated":"2024-01-15T09:32:41.749Z","owner":"solr"},{"_id":"6570b5c0123040aec37a0c0f","ID":"CVE-2023-50291","title":"System Property redaction logic inconsistency can lead to leaked passwords","state":"PUBLIC","updated":"2024-02-09T17:29:31.072Z","owner":"solr"},{"_id":"6570bbf1123040aec37a0c2b","ID":"CVE-2023-50292","title":"Solr Schema Designer blindly \"trusts\" all configsets, possibly leading to RCE by unauthenticated users","state":"PUBLIC","updated":"2024-02-09T17:29:19.451Z","owner":"solr"},{"_id":"6570c9cf123040aec37a0c93","ID":"CVE-2023-50298","title":"Solr can expose ZooKeeper credentials via Streaming Expressions","state":"PUBLIC","updated":"2024-02-09T17:29:05.785Z","owner":"solr"},{"_id":"6571d06f123040aec37a0da2","ID":"CVE-2023-50378","title":"Various XSS problems","state":"PUBLIC","updated":"2024-10-03T12:23:04.013Z","owner":"ambari"},{"_id":"6571d2a2123040aec37a0da4","ID":"CVE-2023-50379","title":"authenticated users could perform command injection to perform RCE","state":"PUBLIC","updated":"2024-02-27T08:26:54.321Z","owner":"ambari"},{"_id":"6571d349123040aec37a0daa","ID":"CVE-2023-50380","title":"authenticated users could perform XXE to read arbitrary files on the server","state":"PUBLIC","updated":"2024-02-27T16:51:31.875Z","owner":"ambari"},{"_id":"6571fd6e123040aec37a0dc0","ID":"CVE-2023-50386","title":"Backup/Restore APIs allow for deployment of executables in malicious ConfigSets","state":"PUBLIC","updated":"2024-02-09T17:28:49.163Z","owner":"solr"},{"_id":"65780a7dd388b103c1a7189c","ID":"CVE-2023-50740","title":"DataSource module Oracle SQL Database Password Logged","state":"PUBLIC","updated":"2024-03-06T13:44:51.798Z","owner":"linkis"},{"_id":"6579ade2d388b103c1a71bad","ID":"CVE-2023-50780","title":"Authenticated users could perform RCE via Jolokia MBeans","state":"PUBLIC","updated":"2024-10-14T16:03:33.323Z","owner":"activemq"},{"_id":"657a18b8d388b103c1a71d26","ID":"CVE-2023-50783","title":"Improper access control vulnerability on the \"varimport\" endpoint","state":"PUBLIC","updated":"2023-12-21T09:28:46.089Z","owner":"airflow"},{"_id":"657dca1cd388b103c1a71f69","ID":"CVE-2023-50943","title":"Potential pickle deserialization vulnerability in XComs","state":"PUBLIC","updated":"2024-01-24T12:57:05.049Z","owner":"airflow"},{"_id":"657dcb75d388b103c1a71f6b","ID":"CVE-2023-50944","title":"Bypass permission verification to read code of other dags","state":"PUBLIC","updated":"2024-01-24T12:58:17.032Z","owner":"airflow"},{"_id":"657ef063d388b103c1a71f79","ID":"CVE-2023-50968","title":"Arbitrary file properties reading and SSRF attack","state":"PUBLIC","updated":"2023-12-26T10:21:57.552Z","owner":"ofbiz"},{"_id":"658134a6d388b103c1a72060","ID":"CVE-2023-51437","title":"Timing attack in SASL token signature verification","state":"PUBLIC","updated":"2024-07-22T08:38:34.087Z","owner":"pulsar"},{"_id":"65819da9d388b103c1a7226f","ID":"CVE-2023-51441","title":"Apache Axis 1.x (EOL) may allow SSRF when untrusted input is passed to the service admin HTTP API","state":"PUBLIC","updated":"2024-01-31T09:07:08.922Z","owner":"axis"},{"_id":"6582dab2d388b103c1a72552","ID":"CVE-2023-51467","title":"Pre-authentication Remote Code Execution (RCE) vulnerability","state":"PUBLIC","updated":"2024-02-02T10:13:56.898Z","owner":"ofbiz"},{"_id":"658312fad388b103c1a725c9","ID":"CVE-2023-51518","title":"Privilege escalation via JMX pre-authentication deserialisation","state":"PUBLIC","updated":"2024-02-27T09:09:28.523Z","owner":"james"},{"_id":"658417f2d388b103c1a726f7","ID":"CVE-2023-51656","title":"Unsafe deserialize map in Sync Tool","state":"PUBLIC","updated":"2023-12-21T11:47:55.799Z","owner":"iotdb"},{"_id":"6584c33bd388b103c1a72770","ID":"CVE-2023-51702","title":"Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service","state":"PUBLIC","updated":"2024-01-24T12:56:15.440Z","owner":"airflow"},{"_id":"6585b571d388b103c1a72834","ID":"CVE-2023-51747","title":"SMTP smuggling in Apache James","state":"PUBLIC","updated":"2024-02-27T13:07:59.703Z","owner":"james"},{"_id":"6588fa4bd388b103c1a72930","ID":"CVE-2023-51770","title":"Arbitrary File Read Vulnerability","state":"PUBLIC","updated":"2024-02-20T06:00:50.765Z","owner":"dolphinscheduler"},{"_id":"658a334ad388b103c1a72946","ID":"CVE-2023-51784","title":"Remote Code Execution vulnerability in Apache InLong Manager","state":"PUBLIC","updated":"2024-01-03T09:39:13.790Z","owner":"inlong"},{"_id":"658a3524d388b103c1a72962","ID":"CVE-2023-51785","title":"Arbitrary File Read Vulnerability in Apache InLong Manager","state":"PUBLIC","updated":"2024-01-03T09:36:21.640Z","owner":"inlong"},{"_id":"65912210d388b103c1a72d4a","ID":"CVE-2023-52290","title":"Unchecked SQL query fields trigger SQL injection vulnerability","state":"PUBLIC","updated":"2024-07-16T07:37:36.828Z","owner":"streampark"},{"_id":"65912ad0d388b103c1a72d69","ID":"CVE-2023-52291","title":"Unchecked maven build params could trigger remote command execution","state":"PUBLIC","updated":"2024-07-17T08:16:10.844Z","owner":"streampark"},{"_id":"65929706d388b103c1a72dac","ID":"CVE-2024-21733","title":"Leaking of unrelated request bodies in default error page","state":"PUBLIC","updated":"2025-10-29T11:59:57.792Z","owner":"tomcat"},{"_id":"6593b260d388b103c1a72e2c","ID":"CVE-2024-21742","title":"Mime4J DOM header injection","state":"PUBLIC","updated":"2025-05-06T13:11:31.892Z","owner":"james"},{"_id":"659c4bc25760f07449474c87","ID":"CVE-2024-22281","title":"Helix front hard-coded secret in the express-session","state":"PUBLIC","updated":"2024-08-20T22:11:36.792Z","owner":"helix"},{"_id":"659d15eb5760f07449474e3b","ID":"CVE-2024-22369","title":"Camel-SQL: Unsafe Deserialization from JDBCAggregationRepository","state":"PUBLIC","updated":"2024-02-20T15:01:05.582Z","owner":"camel"},{"_id":"659d364b5760f07449474f03","ID":"CVE-2024-22371","title":"Apache Camel issue on ExchangeCreatedEvent","state":"PUBLIC","updated":"2024-02-26T09:22:36.071Z","owner":"camel"},{"_id":"659e651a5760f0744947504d","ID":"CVE-2024-22393","title":"Pixel Flood Attack by uploading the large pixel file","state":"PUBLIC","updated":"2024-02-22T09:51:41.833Z","owner":"answer"},{"_id":"659e75535760f07449475095","ID":"CVE-2024-22399","title":"Remote Code Execution vulnerability via Hessian Deserialization in Apache Seata Server","state":"PUBLIC","updated":"2024-09-16T11:42:03.440Z","owner":"seata"},{"_id":"65a023ed5760f07449475163","ID":"CVE-2024-23114","title":"Camel-CassandraQL: Unsafe Deserialization from CassandraAggregationRepository","state":"PUBLIC","updated":"2024-02-20T14:59:36.356Z","owner":"camel"},{"_id":"65a50dbd5760f074494752d1","ID":"CVE-2024-23320","title":"Arbitrary js execution as root for authenticated users","state":"PUBLIC","updated":"2024-02-23T16:36:40.046Z","owner":"dolphinscheduler"},{"_id":"65a524055760f074494752ed","ID":"CVE-2024-23321","title":"Unauthorized Exposure of Sensitive Data","state":"PUBLIC","updated":"2024-07-22T09:24:05.796Z","owner":"rocketmq"},{"_id":"65a5eec05760f0744947530b","ID":"CVE-2024-23349","title":"XSS vulnerability when submitting summary","state":"PUBLIC","updated":"2024-02-22T09:48:18.347Z","owner":"answer"},{"_id":"65a741615760f0744947536c","ID":"CVE-2024-23452","title":"HTTP request smuggling vulnerability","state":"PUBLIC","updated":"2024-02-08T09:00:00.820Z","owner":"brpc"},{"_id":"65a7a4885760f0744947537c","ID":"CVE-2024-23454","title":"Temporary File Local Information Disclosure","state":"PUBLIC","updated":"2025-09-05T09:09:35.509Z","owner":"hadoop"},{"_id":"65a8b0245760f074494753b6","ID":"CVE-2024-23537","title":"Under certain circumstances, this vulnerability allowed users, without specific permissions, to escalate their privileges to any role. ","state":"PUBLIC","updated":"2024-03-29T14:38:03.872Z","owner":"fineract"},{"_id":"65a8b2ec5760f074494753ee","ID":"CVE-2024-23538","title":"Under certain system configurations, the sqlSearch parameter was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries.","state":"PUBLIC","updated":"2024-03-29T14:37:38.535Z","owner":"fineract"},{"_id":"65a8b3215760f074494753f8","ID":"CVE-2024-23539","title":"Under certain system configurations, the sqlSearch parameter for specific endpoints was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries. ","state":"PUBLIC","updated":"2024-03-29T14:36:56.073Z","owner":"fineract"},{"_id":"65a901be5760f07449475455","ID":"CVE-2024-23590","title":"Session fixation in web interface","state":"PUBLIC","updated":"2024-11-04T09:27:04.256Z","owner":"kylin"},{"_id":"65aa60925760f07449475512","ID":"CVE-2024-23672","title":"WebSocket DoS with incomplete closing handshake","state":"PUBLIC","updated":"2025-10-29T11:57:07.493Z","owner":"tomcat"},{"_id":"65aa7f135760f07449475528","ID":"CVE-2024-23673","title":"Malicious code execution via path traversal","state":"PUBLIC","updated":"2024-02-06T10:04:18.646Z","owner":"sling"},{"_id":"65ae9a8a5760f07449475616","ID":"CVE-2024-23807","title":"Use-after-free on external DTD scan","state":"PUBLIC","updated":"2024-02-28T13:50:38.265Z","owner":"xerces"},{"_id":"65b0e64e5760f074494757c0","ID":"CVE-2024-23944","title":"Information disclosure in persistent watcher handling","state":"PUBLIC","updated":"2025-07-03T14:52:54.955Z","owner":"zookeeper"},{"_id":"65b0eaa45760f07449475810","ID":"CVE-2024-23945","title":"CookieSigner exposes the correct signature when message verification fails","state":"PUBLIC","updated":"2024-12-23T15:26:52.096Z","owner":"hive"},{"_id":"65b0faf35760f074494758af","ID":"CVE-2024-23946","title":"Path traversal or file inclusion","state":"PUBLIC","updated":"2024-02-28T15:44:32.259Z","owner":"ofbiz"},{"_id":"65b125015760f0744947591a","ID":"CVE-2024-23952","title":"Allows for uncontrolled resource consumption via a ZIP bomb (version range fix for CVE-2023-46104)","state":"PUBLIC","updated":"2024-02-14T11:09:45.113Z","owner":"superset"},{"_id":"65b12ed45760f0744947592e","ID":"CVE-2024-23953","title":"Timing Attack Against Signature in LLAP util","state":"PUBLIC","updated":"2025-01-28T06:25:01.840Z","owner":"hive"},{"_id":"65b24e9679cf4303b970a0c6","ID":"CVE-2024-24549","title":"HTTP/2 header handling DoS","state":"PUBLIC","updated":"2025-10-29T11:56:21.050Z","owner":"tomcat"},{"_id":"65b379c248ea1dbe265129dc","ID":"CVE-2024-24683","title":"ID isn't escaped when generating HTML","state":"PUBLIC","updated":"2024-03-19T08:20:12.966Z","owner":"hop"},{"_id":"65b77e5b48ea1dbe26512b05","ID":"CVE-2024-24746","title":"Denial of service in NimBLE Bluetooth stack","state":"PUBLIC","updated":"2024-04-10T07:39:33.115Z","owner":"mynewt"},{"_id":"65b8c1c548ea1dbe26512c64","ID":"CVE-2024-24772","title":"Improper Neutralisation of custom SQL on embedded context","state":"PUBLIC","updated":"2025-02-12T09:26:35.721Z","owner":"superset"},{"_id":"65b8cb8548ea1dbe26512c84","ID":"CVE-2024-24773","title":"Improper validation of SQL statements allows for unauthorized access to data ","state":"PUBLIC","updated":"2024-02-28T11:24:56.349Z","owner":"superset"},{"_id":"65b8ce6148ea1dbe26512cd8","ID":"CVE-2024-24778","title":"Resources Permission Escalation","state":"PUBLIC","updated":"2025-03-03T10:37:02.610Z","owner":"streampipes"},{"_id":"65b8d17b48ea1dbe26512d17","ID":"CVE-2024-24779","title":"Improper data authorization when creating a new dataset","state":"PUBLIC","updated":"2024-02-28T11:28:00.354Z","owner":"superset"},{"_id":"65b8d2b848ea1dbe26512d21","ID":"CVE-2024-24780","title":"Remote Code Execution with untrusted URI of User-defined function","state":"PUBLIC","updated":"2025-05-14T10:42:18.799Z","owner":"iotdb"},{"_id":"65ba500648ea1dbe26512e36","ID":"CVE-2024-24795","title":"HTTP Response Splitting in multiple modules","state":"PUBLIC","updated":"2024-10-03T12:15:08.331Z","owner":"httpd"},{"_id":"65bf495c48ea1dbe26512f50","ID":"CVE-2024-25065","title":"Path traversal allowing authentication bypass.","state":"PUBLIC","updated":"2024-02-28T15:42:48.263Z","owner":"ofbiz"},{"_id":"65c0199748ea1dbe26512faa","ID":"CVE-2024-25090","title":"Insufficient input validation for some user profile and bookmark fields when Roller in untested-users mode","state":"PUBLIC","updated":"2024-07-26T08:36:45.293Z","owner":"roller"},{"_id":"65c1f5ec48ea1dbe265130e5","ID":"CVE-2024-25141","title":"Certificate validation isn't respected even if SSL is enabled for apache-airflow-providers-mongo ","state":"PUBLIC","updated":"2024-02-20T20:30:25.779Z","owner":"airflow"},{"_id":"65c1f7b848ea1dbe265130fd","ID":"CVE-2024-25142","title":"Cache Control - Storage of Sensitive Data in Browser Cache ","state":"PUBLIC","updated":"2024-06-14T08:25:32.229Z","owner":"airflow"},{"_id":"65c80a6e593cd803a98a8d46","ID":"CVE-2024-25710","title":"Denial of service caused by an infinite loop for a corrupted DUMP file","state":"PUBLIC","updated":"2024-02-19T08:33:36.725Z","owner":"commons"},{"_id":"65cca16d593cd803a98a8f4a","ID":"CVE-2024-26016","title":"Improper authorization validation on dashboards and charts import","state":"PUBLIC","updated":"2024-02-28T11:28:36.984Z","owner":"superset"},{"_id":"65ce29f4593cd803a98a9047","ID":"CVE-2024-26280","title":"Overly broad default permissions for Viewer/Ops (audit logs)","state":"PUBLIC","updated":"2024-03-01T11:05:52.165Z","owner":"airflow"},{"_id":"65d010c9593cd803a98a9151","ID":"CVE-2024-26307","title":"Possible race condition","state":"PUBLIC","updated":"2024-03-21T09:38:16.580Z","owner":"doris"},{"_id":"65d12e6c593cd803a98a91ee","ID":"CVE-2024-26308","title":"OutOfMemoryError unpacking broken Pack200 file","state":"PUBLIC","updated":"2024-02-19T08:31:48.197Z","owner":"commons"},{"_id":"65d30311593cd803a98a9308","ID":"CVE-2024-26578","title":"Repeated submission at registration created duplicate users with the same name","state":"PUBLIC","updated":"2024-02-22T09:28:11.636Z","owner":"answer"},{"_id":"65d31be3593cd803a98a9404","ID":"CVE-2024-26579","title":"Apache Inlong JDBC Vulnerability","state":"PUBLIC","updated":"2024-05-08T14:57:16.261Z","owner":"inlong"},{"_id":"65d32046593cd803a98a94c0","ID":"CVE-2024-26580","title":"Logged-in user could exploit an arbitrary file read vulnerability","state":"PUBLIC","updated":"2024-08-02T09:40:25.011Z","owner":"inlong"},{"_id":"65d491ea593cd803a98a98d4","ID":"CVE-2024-27135","title":"Improper Input Validation in Pulsar Function Worker allows Remote Code Execution","state":"PUBLIC","updated":"2024-03-12T18:18:04.587Z","owner":"pulsar"},{"_id":"65d4975b593cd803a98a991a","ID":"CVE-2024-27136","title":"Cross-site scripting vulnerability on upload page","state":"PUBLIC","updated":"2024-06-24T07:44:28.700Z","owner":"jspwiki"},{"_id":"65d49b13593cd803a98a9940","ID":"CVE-2024-27137","title":"unrestricted deserialization of JMX authentication credentials","state":"PUBLIC","updated":"2025-02-04T10:19:42.511Z","owner":"cassandra"},{"_id":"65d4c5d4593cd803a98a99af","ID":"CVE-2024-27138","title":"disabling user registration is not effective","state":"PUBLIC","updated":"2024-03-01T15:41:11.276Z","owner":"archiva"},{"_id":"65d4cb36593cd803a98a99b5","ID":"CVE-2024-27139","title":"incorrect authentication potentially leading to account takeover","state":"PUBLIC","updated":"2024-03-01T15:40:48.119Z","owner":"archiva"},{"_id":"65d4cbbc593cd803a98a99bb","ID":"CVE-2024-27140","title":"reflected XSS","state":"PUBLIC","updated":"2024-03-01T15:40:06.489Z","owner":"archiva"},{"_id":"65d56808593cd803a98a9a3f","ID":"CVE-2024-27181","title":"Privilege Escalation Attack vulnerability","state":"PUBLIC","updated":"2024-08-02T09:27:34.414Z","owner":"linkis"},{"_id":"65d56861593cd803a98a9a41","ID":"CVE-2024-27182","title":"Engine material management Arbitrary file deletion vulnerability","state":"PUBLIC","updated":"2024-08-02T09:29:36.766Z","owner":"linkis"},{"_id":"65d7933a25aaa903bd96c795","ID":"CVE-2024-27309","title":"Potential incorrect access control during migration from ZK mode to KRaft mode","state":"PUBLIC","updated":"2024-04-12T06:58:42.007Z","owner":"kafka"},{"_id":"65d8622925aaa903bd96c7be","ID":"CVE-2024-27315","title":"Improper error handling on alerts","state":"PUBLIC","updated":"2024-10-03T12:30:58.178Z","owner":"superset"},{"_id":"65d8a9c825aaa903bd96c8bf","ID":"CVE-2024-27316","title":"HTTP/2 DoS by memory exhaustion on endless continuation frames","state":"PUBLIC","updated":"2024-07-22T08:42:12.197Z","owner":"httpd"},{"_id":"65d8cd3e25aaa903bd96c970","ID":"CVE-2024-27317","title":"Pulsar Functions Worker's Archive Extraction Vulnerability Allows Unauthorized File Modification","state":"PUBLIC","updated":"2024-03-12T18:18:50.985Z","owner":"pulsar"},{"_id":"65d9c7fe25aaa903bd96c9f5","ID":"CVE-2024-27347","title":"SSRF in Hubble connection page","state":"PUBLIC","updated":"2024-04-22T14:07:30.816Z","owner":"hugegraph"},{"_id":"65d9c86c25aaa903bd96c9fb","ID":"CVE-2024-27348","title":"Command execution in gremlin","state":"PUBLIC","updated":"2024-04-22T14:08:03.374Z","owner":"hugegraph"},{"_id":"65d9c89d25aaa903bd96c9fd","ID":"CVE-2024-27349","title":"Bypass whitelist in Auth mode","state":"PUBLIC","updated":"2024-04-22T14:08:39.984Z","owner":"hugegraph"},{"_id":"65db4a0925aaa903bd96ca64","ID":"CVE-2024-27438","title":"Downloading arbitrary remote jar files resulting in remote command execution","state":"PUBLIC","updated":"2024-03-21T09:39:20.599Z","owner":"doris"},{"_id":"65db9fec25aaa903bd96ca84","ID":"CVE-2024-27439","title":"Possible bypass of CSRF protection","state":"PUBLIC","updated":"2024-03-19T11:07:46.188Z","owner":"wicket"},{"_id":"65dd005b25aaa903bd96cb52","ID":"CVE-2024-27894","title":"Pulsar Functions Worker Allows Unauthorized File Access and Unauthorized HTTP/HTTPS Proxying","state":"PUBLIC","updated":"2024-03-12T18:19:39.887Z","owner":"pulsar"},{"_id":"65ddb19325aaa903bd96cc76","ID":"CVE-2024-27905","title":"padding oracle can allow construction an authentication cookie","state":"PUBLIC","updated":"2024-02-27T14:29:18.380Z","owner":"aurora"},{"_id":"65ddd2a225aaa903bd96ccdd","ID":"CVE-2024-27906","title":"Dag Code and Import Error Permissions Ignored","state":"PUBLIC","updated":"2025-05-06T13:12:04.279Z","owner":"airflow"},{"_id":"65e589c525aaa903bd96d2c0","ID":"CVE-2024-28098","title":"Improper Authorization For Topic-Level Policy Management","state":"PUBLIC","updated":"2024-03-12T18:15:36.513Z","owner":"pulsar"},{"_id":"65e746d825aaa903bd96d35b","ID":"CVE-2024-28148","title":"Incorrect datasource authorization on explore REST API ","state":"PUBLIC","updated":"2024-05-08T08:31:47.011Z","owner":"superset"},{"_id":"65e8215f25aaa903bd96d3c7","ID":"CVE-2024-28168","title":"XML External Entity (XXE) Processing","state":"PUBLIC","updated":"2024-10-09T12:04:02.004Z","owner":"xmlgraphics"},{"_id":"65eacc29275cc203a8674460","ID":"CVE-2024-28746","title":"Ignored Airflow Permissions","state":"PUBLIC","updated":"2024-03-14T08:40:55.534Z","owner":"airflow"},{"_id":"65eb04b4275cc203a867446a","ID":"CVE-2024-28752","title":"Apache CXF SSRF Vulnerability using the Aegis databinding","state":"PUBLIC","updated":"2024-03-15T10:28:02.596Z","owner":"cxf"},{"_id":"65f22f290b975b0f3f3cdcbe","ID":"CVE-2024-29006","title":"x-forwarded-for HTTP header parsed by default","state":"PUBLIC","updated":"2024-04-04T10:59:16.384Z","owner":"cloudstack"},{"_id":"65f22fae0b975b0f3f3cdcc4","ID":"CVE-2024-29007","title":"When downloading templates or ISOs, the management server and SSVM follow HTTP redirects with potentially dangerous consequences","state":"PUBLIC","updated":"2024-04-04T10:58:20.239Z","owner":"cloudstack"},{"_id":"65f2307b0b975b0f3f3cdcc6","ID":"CVE-2024-29008","title":"The extraconfig feature can be abused to load hypervisor resources on a VM instance","state":"PUBLIC","updated":"2024-04-04T10:58:44.745Z","owner":"cloudstack"},{"_id":"65f3bec80b975b0f3f3cde48","ID":"CVE-2024-29070","title":"session not invalidated after logout","state":"PUBLIC","updated":"2025-02-06T14:33:02.169Z","owner":"streampark"},{"_id":"65f4e1f50b975b0f3f3cde89","ID":"CVE-2024-29120","title":"Information leakage vulnerability","state":"PUBLIC","updated":"2024-07-17T14:59:02.804Z","owner":"streampark"},{"_id":"65f583980b975b0f3f3cdeae","ID":"CVE-2024-29131","title":"StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()","state":"PUBLIC","updated":"2024-03-21T09:07:12.130Z","owner":"commons"},{"_id":"65f6eda10b975b0f3f3cdede","ID":"CVE-2024-29133","title":"StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree","state":"PUBLIC","updated":"2024-03-21T09:05:45.826Z","owner":"commons"},{"_id":"65f86d260b975b0f3f3cdfba","ID":"CVE-2024-29178","title":"FreeMarker SSTI RCE Vulnerability","state":"PUBLIC","updated":"2024-07-18T11:15:55.181Z","owner":"streampark"},{"_id":"65f8ef190b975b0f3f3ce03a","ID":"CVE-2024-29217","title":"XSS vulnerability when changing personal website","state":"PUBLIC","updated":"2024-04-21T16:04:07.662Z","owner":"answer"},{"_id":"65f94ad64e8db503ac22b732","ID":"CVE-2024-29733","title":"FTP_TLS instance with unverified SSL context","state":"PUBLIC","updated":"2024-04-21T17:21:52.458Z","owner":"airflow"},{"_id":"65f971d64e8db503ac22b794","ID":"CVE-2024-29735","title":"Potentially harmful permission changing by log task handler","state":"PUBLIC","updated":"2024-03-26T16:52:39.118Z","owner":"airflow"},{"_id":"65f974d34e8db503ac22b7c5","ID":"CVE-2024-29736","title":"SSRF vulnerability via WADL stylesheet parameter","state":"PUBLIC","updated":"2024-07-19T08:50:06.520Z","owner":"cxf"},{"_id":"65f9a08f4e8db503ac22b828","ID":"CVE-2024-29737","title":"maven build params could trigger remote command execution","state":"PUBLIC","updated":"2024-07-17T08:21:09.036Z","owner":"streampark"},{"_id":"65fab1b24e8db503ac22b86f","ID":"CVE-2024-29831","title":"RCE by arbitrary js execution","state":"PUBLIC","updated":"2024-08-09T14:21:46.981Z","owner":"dolphinscheduler"},{"_id":"65fb12a74e8db503ac22b8b6","ID":"CVE-2024-29834","title":"Improper Authorization For Namespace and Topic Management Endpoints","state":"PUBLIC","updated":"2024-04-02T19:24:43.888Z","owner":"pulsar"},{"_id":"65fbeed44e8db503ac22ba0e","ID":"CVE-2024-29868","title":"Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Recovery Token Generation","state":"PUBLIC","updated":"2024-06-24T09:59:38.377Z","owner":"streampipes"},{"_id":"65fc093a4e8db503ac22bb10","ID":"CVE-2024-29869","title":"Credentials file created with non restrictive permissions","state":"PUBLIC","updated":"2025-01-28T19:57:18.085Z","owner":"hive"},{"_id":"66014ac04e8db503ac22bc1a","ID":"CVE-2024-30188","title":"Resource File Read And Write Vulnerability","state":"PUBLIC","updated":"2024-08-09T12:45:43.623Z","owner":"dolphinscheduler"},{"_id":"6603e4399a5c729b2534ea34","ID":"CVE-2024-30471","title":"Potential creation of multiple identical accounts","state":"PUBLIC","updated":"2024-07-17T09:01:50.452Z","owner":"streampipes"},{"_id":"6605a17e9a5c729b2534ebbd","ID":"CVE-2024-31141","title":"Privilege escalation to filesystem read-access via automatic ConfigProvider","state":"PUBLIC","updated":"2024-11-19T08:40:15.880Z","owner":"kafka"},{"_id":"66070ddd9a5c729b2534ecc5","ID":"CVE-2024-31309","title":"HTTP/2 CONTINUATION frames can be utilized for DoS attack","state":"PUBLIC","updated":"2024-04-10T15:16:21.844Z","owner":"trafficserver"},{"_id":"660c19c69a5c729b2534efb1","ID":"CVE-2024-31391","title":"Solr-Operator liveness and readiness probes may leak basic auth credentials","state":"PUBLIC","updated":"2024-04-12T15:00:22.627Z","owner":"solr"},{"_id":"660d33f99a5c729b2534f1c9","ID":"CVE-2024-31411","title":"Potential remote code execution (RCE) via file upload","state":"PUBLIC","updated":"2024-07-17T09:22:06.439Z","owner":"streampipes"},{"_id":"661136cc9a5c729b2534f616","ID":"CVE-2024-31860","title":"Path traversal vulnerability","state":"PUBLIC","updated":"2025-05-06T13:12:30.032Z","owner":"zeppelin"},{"_id":"661136f49a5c729b2534f61a","ID":"CVE-2024-31862","title":"Denial of service with invalid notebook name","state":"PUBLIC","updated":"2024-04-09T09:40:37.681Z","owner":"zeppelin"},{"_id":"661137009a5c729b2534f61c","ID":"CVE-2024-31863","title":"Replacing other users notebook, bypassing any permissions","state":"PUBLIC","updated":"2024-04-09T10:25:26.871Z","owner":"zeppelin"},{"_id":"6611370d9a5c729b2534f61e","ID":"CVE-2024-31864","title":"Remote code execution by adding malicious JDBC connection string","state":"PUBLIC","updated":"2024-04-11T07:54:22.052Z","owner":"zeppelin"},{"_id":"661137179a5c729b2534f620","ID":"CVE-2024-31865","title":"Cron arbitrary user impersonation with improper privileges","state":"PUBLIC","updated":"2024-04-09T16:07:34.123Z","owner":"zeppelin"},{"_id":"661137249a5c729b2534f622","ID":"CVE-2024-31866","title":"Interpreter download command does not escape malicious code injection","state":"PUBLIC","updated":"2024-04-09T16:09:09.746Z","owner":"zeppelin"},{"_id":"6611372f9a5c729b2534f624","ID":"CVE-2024-31867","title":"LDAP search filter query Injection Vulnerability","state":"PUBLIC","updated":"2024-04-09T16:15:46.165Z","owner":"zeppelin"},{"_id":"661137399a5c729b2534f626","ID":"CVE-2024-31868","title":"XSS vulnerability in the helium module","state":"PUBLIC","updated":"2024-10-03T12:35:14.839Z","owner":"zeppelin"},{"_id":"6611a7ef9a5c729b2534f7c9","ID":"CVE-2024-31869","title":"Sensitive configuration for providers displayed when \"non-sensitive-only\" config used","state":"PUBLIC","updated":"2024-04-18T07:18:58.062Z","owner":"airflow"},{"_id":"6613df2a9a5c729b2534f94e","ID":"CVE-2024-31979","title":"Possibility of SSRF in pipeline element installation process","state":"PUBLIC","updated":"2024-07-17T09:03:15.953Z","owner":"streampipes"},{"_id":"66140e799a5c729b2534fc64","ID":"CVE-2024-32007","title":"Apache CXF Denial of Service vulnerability in JOSE","state":"PUBLIC","updated":"2024-07-19T08:50:30.464Z","owner":"cxf"},{"_id":"6616bc2878d9e903c19121fc","ID":"CVE-2024-32077","title":"XSS vulnerability in Task Instance Log/Log Details","state":"PUBLIC","updated":"2024-05-14T10:43:17.698Z","owner":"airflow"},{"_id":"6617864578d9e903c191222b","ID":"CVE-2024-32113","title":"Path traversal leading to RCE","state":"PUBLIC","updated":"2024-05-08T14:49:53.237Z","owner":"ofbiz"},{"_id":"66179b6078d9e903c1912243","ID":"CVE-2024-32114","title":"Jolokia and REST API were not secured with default configuration","state":"PUBLIC","updated":"2024-05-01T16:07:22.140Z","owner":"activemq"},{"_id":"661e675478d9e903c191241f","ID":"CVE-2024-32638","title":"Forward-Auth Request Smuggling","state":"PUBLIC","updated":"2025-10-15T03:54:43.662Z","owner":"apisix"},{"_id":"66215e3078d9e903c1912576","ID":"CVE-2024-32838","title":"SQL injection vulnerabilities in offices API endpoint","state":"PUBLIC","updated":"2025-02-12T09:44:14.259Z","owner":"fineract"},{"_id":"6633731095e9e903b6a54620","ID":"CVE-2024-34365","title":"Cave SSRF and arbitrary file access","state":"PUBLIC","updated":"2024-05-09T06:49:03.305Z","owner":"karaf"},{"_id":"6635929c95e9e903b6a546b4","ID":"CVE-2024-34457","title":"Apache StreamPark IDOR Vulnerability","state":"PUBLIC","updated":"2024-09-11T11:03:06.370Z","owner":"streampark"},{"_id":"6639e32695e9e903b6a54798","ID":"CVE-2024-34693","title":"Server arbitrary file read","state":"PUBLIC","updated":"2024-06-20T08:51:53.358Z","owner":"superset"},{"_id":"663b2864098a0703a97dfd7d","ID":"CVE-2024-34750","title":"HTTP/2 excess header handling DoS","state":"PUBLIC","updated":"2025-10-29T11:55:37.796Z","owner":"tomcat"},{"_id":"663d2c5f098a0703a97dfedd","ID":"CVE-2024-35161","title":"Incomplete check for chunked trailer section allows request smuggling","state":"PUBLIC","updated":"2024-08-13T08:48:31.440Z","owner":"trafficserver"},{"_id":"663dd0cf098a0703a97dff70","ID":"CVE-2024-35164","title":"Improper input validation of console codes","state":"PUBLIC","updated":"2025-07-02T11:23:12.067Z","owner":"guacamole"},{"_id":"66452c1028b58203b9e2bc1d","ID":"CVE-2024-35296","title":"Invalid Accept-Encoding can force forwarding requests","state":"PUBLIC","updated":"2024-07-26T09:11:09.740Z","owner":"trafficserver"},{"_id":"664af74c28b58203b9e2bc3f","ID":"CVE-2024-36104","title":"Path traversal leading to a RCE","state":"PUBLIC","updated":"2024-06-03T06:55:24.928Z","owner":"ofbiz"},{"_id":"664dc4a3f6506e6944261eb0","ID":"CVE-2024-36263","title":"SQL injection","state":"PUBLIC","updated":"2024-06-12T14:05:08.215Z","owner":"submarine"},{"_id":"664dc4b6f6506e6944261eb2","ID":"CVE-2024-36264","title":"default secret","state":"PUBLIC","updated":"2024-10-14T08:55:23.574Z","owner":"submarine"},{"_id":"664dc4c6f6506e6944261eb4","ID":"CVE-2024-36265","title":"authorization bypass","state":"PUBLIC","updated":"2026-07-14T09:56:45.149Z","owner":"submarine"},{"_id":"664ef365f6506e6944261f14","ID":"CVE-2024-36268","title":"Remote Code Execution vulnerability","state":"PUBLIC","updated":"2024-08-02T09:44:23.542Z","owner":"inlong"},{"_id":"66546adc0ed3761128ffd832","ID":"CVE-2024-36387","title":"DoS by Null pointer in websocket over HTTP/2","state":"PUBLIC","updated":"2024-07-02T10:05:08.772Z","owner":"httpd"},{"_id":"66554d620ed3761128ffd89c","ID":"CVE-2024-36448","title":"SSRF Vulnerability (EOL)","state":"PUBLIC","updated":"2024-08-05T09:53:35.819Z","owner":"iotdb"},{"_id":"6655fec30ed3761128ffd918","ID":"CVE-2024-36471","title":"sensitive information exposure via DNS rebinding","state":"PUBLIC","updated":"2024-06-10T21:55:03.113Z","owner":"allura"},{"_id":"66586ac50ed3761128ffd962","ID":"CVE-2024-36522","title":"Remote code execution via XSLT injection","state":"PUBLIC","updated":"2024-07-12T12:13:50.122Z","owner":"wicket"},{"_id":"666160340ed3761128ffdb70","ID":"CVE-2024-37358","title":"Apache James: denial of service through the use of IMAP literals","state":"PUBLIC","updated":"2025-09-01T09:40:16.733Z","owner":"james"},{"_id":"6663770b0ed3761128ffdbcc","ID":"CVE-2024-37389","title":"Improper Neutralization of Input in Parameter Context Description","state":"PUBLIC","updated":"2024-07-08T07:28:58.478Z","owner":"nifi"},{"_id":"6669cc6b0ed3761128ffdd15","ID":"CVE-2024-38286","title":"Denial of Service","state":"PUBLIC","updated":"2025-10-29T11:54:52.747Z","owner":"tomcat"},{"_id":"666b160c1aeb5803bc33549f","ID":"CVE-2024-38311","title":"Request smuggling via pipelining after a chunked message body","state":"PUBLIC","updated":"2025-03-06T11:34:14.593Z","owner":"trafficserver"},{"_id":"666bf6931aeb5803bc3354f9","ID":"CVE-2024-38346","title":"Unauthenticated cluster service port leads to remote execution","state":"PUBLIC","updated":"2024-07-05T13:39:11.185Z","owner":"cloudstack"},{"_id":"666c569a1aeb5803bc3355a6","ID":"CVE-2024-38379","title":"Stored authenticated XSS","state":"PUBLIC","updated":"2025-02-06T14:32:32.361Z","owner":"allura"},{"_id":"667017da1aeb5803bc335741","ID":"CVE-2024-38472","title":"Apache HTTP Server on WIndows UNC SSRF","state":"PUBLIC","updated":"2024-11-18T08:50:42.606Z","owner":"httpd"},{"_id":"6670185d1aeb5803bc335743","ID":"CVE-2024-38473","title":"Apache HTTP Server proxy encoding problem","state":"PUBLIC","updated":"2024-07-03T12:05:25.367Z","owner":"httpd"},{"_id":"6670194e1aeb5803bc335745","ID":"CVE-2024-38474","title":"Apache HTTP Server weakness with encoded question marks in backreferences","state":"PUBLIC","updated":"2024-07-01T18:14:45.297Z","owner":"httpd"},{"_id":"667019841aeb5803bc335747","ID":"CVE-2024-38475","title":"Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.","state":"PUBLIC","updated":"2024-07-01T18:15:10.846Z","owner":"httpd"},{"_id":"667019c01aeb5803bc335749","ID":"CVE-2024-38476","title":"Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect","state":"PUBLIC","updated":"2024-07-01T19:20:41.405Z","owner":"httpd"},{"_id":"667019e21aeb5803bc33574b","ID":"CVE-2024-38477","title":"Crash resulting in Denial of Service in mod_proxy via a malicious request","state":"PUBLIC","updated":"2024-07-01T18:16:10.377Z","owner":"httpd"},{"_id":"6670860a1aeb5803bc33580d","ID":"CVE-2024-38479","title":"Cache key plugin is vulnerable to cache poisoning attack","state":"PUBLIC","updated":"2024-12-19T08:48:33.164Z","owner":"trafficserver"},{"_id":"66714a4a1aeb5803bc33588f","ID":"CVE-2024-38503","title":"HTML tags can be injected into Console or Enduser text fields","state":"PUBLIC","updated":"2024-09-11T11:11:10.160Z","owner":"syncope"},{"_id":"6673da241aeb5803bc335b2d","ID":"CVE-2024-38856","title":"Unauthenticated endpoint could allow execution of screen rendering code","state":"PUBLIC","updated":"2024-08-05T08:20:16.193Z","owner":"ofbiz"},{"_id":"667afaca1aeb5803bc335efb","ID":"CVE-2024-39573","title":"mod_rewrite proxy handler substitution","state":"PUBLIC","updated":"2024-07-01T18:16:42.254Z","owner":"httpd"},{"_id":"667db0b520aa0f041f1e2a2b","ID":"CVE-2024-39676","title":"Unauthorized endpoint exposed sensitive information","state":"PUBLIC","updated":"2024-07-24T07:41:07.886Z","owner":"pinot"},{"_id":"66823a7520aa0f041f1e2af2","ID":"CVE-2024-39863","title":"Potential XSS Vulnerability","state":"PUBLIC","updated":"2024-07-22T08:50:05.686Z","owner":"airflow"},{"_id":"66828c1120aa0f041f1e2b1a","ID":"CVE-2024-39864","title":"Integration API service uses dynamic port when disabled","state":"PUBLIC","updated":"2024-07-05T13:39:23.006Z","owner":"cloudstack"},{"_id":"6682d6e220aa0f041f1e2e07","ID":"CVE-2024-39877","title":"DAG Author Code Execution possibility in airflow-scheduler","state":"PUBLIC","updated":"2024-07-17T07:54:23.158Z","owner":"airflow"},{"_id":"6683033220aa0f041f1e2f08","ID":"CVE-2024-39884","title":"source code disclosure with handlers configured via AddType","state":"PUBLIC","updated":"2024-07-04T08:41:17.573Z","owner":"httpd"},{"_id":"6683ffef20aa0f041f1e2f6b","ID":"CVE-2024-39887","title":"Improper SQL authorisation, parse not checking for specific engine functions","state":"PUBLIC","updated":"2024-07-16T09:20:08.872Z","owner":"superset"},{"_id":"6686799e20aa0f041f1e3131","ID":"CVE-2024-39928","title":"Commons Lang's RandomStringUtils Random string security vulnerability","state":"PUBLIC","updated":"2024-09-24T01:38:41.101Z","owner":"linkis"},{"_id":"668768af20aa0f041f1e316b","ID":"CVE-2024-39954","title":"SSRF","state":"PUBLIC","updated":"2025-08-20T08:56:38.252Z","owner":"eventmesh"},{"_id":"668d3e0b20aa0f041f1e33c1","ID":"CVE-2024-40725","title":"source code disclosure with handlers configured via AddType","state":"PUBLIC","updated":"2024-07-18T09:32:42.028Z","owner":"httpd"},{"_id":"668e3d0120aa0f041f1e3473","ID":"CVE-2024-40761","title":"Avatar URL leaked user email addresses","state":"PUBLIC","updated":"2024-09-25T07:31:07.119Z","owner":"answer"},{"_id":"66911786306b780409ef95d8","ID":"CVE-2024-40898","title":"SSRF with mod_rewrite in server/vhost context on Windows","state":"PUBLIC","updated":"2024-07-18T09:55:11.215Z","owner":"httpd"},{"_id":"6691b191306b780409ef9772","ID":"CVE-2024-41107","title":"SAML Signature Exclusion","state":"PUBLIC","updated":"2024-07-19T10:11:15.224Z","owner":"cloudstack"},{"_id":"66963489306b780409ef9c69","ID":"CVE-2024-41151","title":"RCE by notice template injection vulnerability","state":"PUBLIC","updated":"2025-04-16T11:19:50.180Z","owner":"hertzbeat"},{"_id":"669783ed306b780409efa06a","ID":"CVE-2024-41169","title":"raft directory listing and file read","state":"PUBLIC","updated":"2025-07-12T16:22:30.823Z","owner":"zeppelin"},{"_id":"6697c95a306b780409efa129","ID":"CVE-2024-41172","title":"Unrestricted memory consumption in CXF HTTP clients","state":"PUBLIC","updated":"2024-07-19T08:50:42.522Z","owner":"cxf"},{"_id":"6697da79306b780409efa250","ID":"CVE-2024-41177","title":"XSS in the Helium module","state":"PUBLIC","updated":"2025-08-03T10:09:33.254Z","owner":"zeppelin"},{"_id":"669802ce306b780409efa33c","ID":"CVE-2024-41178","title":"AWS WebIdentityToken exposure in log files","state":"PUBLIC","updated":"2024-07-23T17:07:57.878Z","owner":"arrow"},{"_id":"669f139a306b780409efab55","ID":"CVE-2024-41888","title":"The link for resetting user password is not Single-Use","state":"PUBLIC","updated":"2024-08-09T14:55:12.877Z","owner":"answer"},{"_id":"669f186f306b780409efaba5","ID":"CVE-2024-41890","title":"The link to reset the user's password will remain valid after sending a new link","state":"PUBLIC","updated":"2024-08-09T14:53:26.714Z","owner":"answer"},{"_id":"669fc8da306b780409efac66","ID":"CVE-2024-41909","title":"integrity check bypass","state":"PUBLIC","updated":"2024-08-12T16:00:27.622Z","owner":"mina"},{"_id":"66a0b8a1306b780409efadf3","ID":"CVE-2024-41937","title":"Stored XSS Vulnerability on provider link","state":"PUBLIC","updated":"2024-08-21T15:31:11.725Z","owner":"airflow"},{"_id":"66a7838f5ffc430408cb61cd","ID":"CVE-2024-42062","title":"User Key Exposure to Domain Admins","state":"PUBLIC","updated":"2024-08-19T13:43:36.243Z","owner":"cloudstack"},{"_id":"66a879915ffc430408cb624a","ID":"CVE-2024-42222","title":"Unauthorised Network List Access","state":"PUBLIC","updated":"2024-08-07T06:49:40.024Z","owner":"cloudstack"},{"_id":"66a8a35d5ffc430408cb62d7","ID":"CVE-2024-42323","title":"RCE by snakeYaml deser load malicious xml ","state":"PUBLIC","updated":"2024-09-21T09:30:13.062Z","owner":"hertzbeat"},{"_id":"66ac22575ffc430408cb6423","ID":"CVE-2024-42447","title":"FAB provider 1.2.1 and 1.2.0 did not let user to logout for Airflow","state":"PUBLIC","updated":"2024-08-04T20:03:30.234Z","owner":"airflow"},{"_id":"66ae78e85ffc430408cb6648","ID":"CVE-2024-42516","title":"HTTP response splitting","state":"PUBLIC","updated":"2025-07-11T10:29:33.054Z","owner":"httpd"},{"_id":"66b3108b5ffc430408cb6ad7","ID":"CVE-2024-43115","title":"Alert Script Attack","state":"PUBLIC","updated":"2025-09-03T08:38:26.012Z","owner":"dolphinscheduler"},{"_id":"66b34eda5ffc430408cb6baf","ID":"CVE-2024-43166","title":"CWE-276 Incorrect Default Permissions","state":"PUBLIC","updated":"2025-09-18T09:38:13.985Z","owner":"dolphinscheduler"},{"_id":"66b3932f5ffc430408cb6c23","ID":"CVE-2024-43202","title":"Remote Code Execution Vulnerability","state":"PUBLIC","updated":"2024-08-20T07:29:41.648Z","owner":"dolphinscheduler"},{"_id":"66b4e099e5392a52588b6ece","ID":"CVE-2024-43204","title":"SSRF with mod_headers setting Content-Type header","state":"PUBLIC","updated":"2025-07-11T10:33:09.127Z","owner":"httpd"},{"_id":"66b7978b6ba90403fa862de4","ID":"CVE-2024-43383","title":"Remote Code Execution in Lucene.Net.Replicator","state":"PUBLIC","updated":"2024-10-31T09:57:26.362Z","owner":"lucenenet"},{"_id":"66ba15fc6ba90403fa862e3f","ID":"CVE-2024-43394","title":"SSRF on Windows due to UNC paths","state":"PUBLIC","updated":"2025-07-11T10:29:24.674Z","owner":"httpd"},{"_id":"66bb0a666ba90403fa862f17","ID":"CVE-2024-43441","title":"Fixed JWT Token(Secret)","state":"PUBLIC","updated":"2024-12-24T11:59:55.141Z","owner":"hugegraph"},{"_id":"66c320a26ba90403fa86318f","ID":"CVE-2024-44088","title":"Reflected XSS","state":"PUBLIC","updated":"2025-10-14T14:36:50.748Z","owner":"geode"},{"_id":"66c59c026ba90403fa8633a9","ID":"CVE-2024-45031","title":"Stored XSS in Console and Enduser","state":"PUBLIC","updated":"2025-09-01T09:41:27.665Z","owner":"syncope"},{"_id":"66c5ddad6ba90403fa8633f4","ID":"CVE-2024-45033","title":"Application does not invalidate session after password change via Airflow cli","state":"PUBLIC","updated":"2025-01-08T08:41:37.392Z","owner":"airflow"},{"_id":"66c5e06e6ba90403fa863403","ID":"CVE-2024-45034","title":"Authenticated DAG authors could execute code on scheduler nodes","state":"PUBLIC","updated":"2024-09-07T07:45:26.032Z","owner":"airflow"},{"_id":"66c661636ba90403fa8634ea","ID":"CVE-2024-45106","title":"Improper authentication when generating S3 secrets","state":"PUBLIC","updated":"2024-12-03T09:06:21.271Z","owner":"ozone"},{"_id":"66c757009d78460409c27725","ID":"CVE-2024-45195","title":"Confused controller-view authorization logic (forced browsing)","state":"PUBLIC","updated":"2024-09-04T08:08:57.418Z","owner":"ofbiz"},{"_id":"66c8c3a49d78460409c2784b","ID":"CVE-2024-45216","title":"Authentication bypass possible using a fake URL Path ending","state":"PUBLIC","updated":"2024-12-03T17:55:26.574Z","owner":"solr"},{"_id":"66c8cbfa9d78460409c2787b","ID":"CVE-2024-45217","title":"ConfigSets created during a backup restore command are trusted implicitly","state":"PUBLIC","updated":"2024-10-16T07:51:15.128Z","owner":"solr"},{"_id":"66c8f3c19d78460409c2789f","ID":"CVE-2024-45219","title":"Uploaded and registered templates and volumes can be used to abuse KVM-based infrastructure","state":"PUBLIC","updated":"2024-10-15T18:32:48.536Z","owner":"cloudstack"},{"_id":"66ce96049d78460409c27949","ID":"CVE-2024-45384","title":"Padding oracle in druid-pac4j extension that allows an attacker to manipulate a pac4j session cookie via Padding Oracle Attack","state":"PUBLIC","updated":"2024-09-17T17:58:14.680Z","owner":"druid"},{"_id":"66cf697f8dd6167d3a3a35b4","ID":"CVE-2024-45387","title":"SQL Injection in Traffic Ops endpoint PUT deliveryservice_request_comments","state":"PUBLIC","updated":"2024-12-23T15:30:11.661Z","owner":"trafficcontrol"},{"_id":"66d037978dd6167d3a3a35fa","ID":"CVE-2024-45461","title":"Access checks not enforced in Quota","state":"PUBLIC","updated":"2025-02-12T09:30:16.539Z","owner":"cloudstack"},{"_id":"66d037fd8dd6167d3a3a3600","ID":"CVE-2024-45462","title":"Incomplete session invalidation on web interface logout","state":"PUBLIC","updated":"2024-10-16T10:39:03.528Z","owner":"cloudstack"},{"_id":"66d076068dd6167d3a3a361a","ID":"CVE-2024-45477","title":"Improper Neutralization of Input in Parameter Description","state":"PUBLIC","updated":"2024-10-29T09:00:05.602Z","owner":"nifi"},{"_id":"66d086228dd6167d3a3a3653","ID":"CVE-2024-45478","title":"Stored XSS in Edit Service page - Add logic to validate user input","state":"PUBLIC","updated":"2025-06-10T09:05:24.595Z","owner":"ranger"},{"_id":"66d08ada8dd6167d3a3a3691","ID":"CVE-2024-45479","title":"SSRF in Edit Service page - Add logic to filter requests to localhost","state":"PUBLIC","updated":"2025-06-10T09:06:31.823Z","owner":"ranger"},{"_id":"66d1c0768dd6167d3a3a3740","ID":"CVE-2024-45498","title":"Command Injection in an example DAG","state":"PUBLIC","updated":"2024-09-07T07:43:42.216Z","owner":"airflow"},{"_id":"66d285838dd6167d3a3a374d","ID":"CVE-2024-45505","title":"Exists Native Deser RCE and file writing vulnerabilities","state":"PUBLIC","updated":"2024-11-18T08:44:44.304Z","owner":"hertzbeat"},{"_id":"66d475e18dd6167d3a3a3765","ID":"CVE-2024-45507","title":"Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCE","state":"PUBLIC","updated":"2024-09-04T08:08:31.094Z","owner":"ofbiz"},{"_id":"66d5659f8dd6167d3a3a37e1","ID":"CVE-2024-45537","title":"Users can provide MySQL JDBC properties not on allow list","state":"PUBLIC","updated":"2024-09-19T09:29:22.203Z","owner":"druid"},{"_id":"66d6cc488dd6167d3a3a391d","ID":"CVE-2024-45626","title":"Apache James: denial of service through JMAP HTML to text conversion","state":"PUBLIC","updated":"2025-02-06T11:21:05.038Z","owner":"james"},{"_id":"66d70d7e8dd6167d3a3a3951","ID":"CVE-2024-45627","title":"JDBC Datasource Module with Mysql has file read vulnerability","state":"PUBLIC","updated":"2025-01-14T16:13:18.399Z","owner":"linkis"},{"_id":"66d8f9ef8dd6167d3a3a3a25","ID":"CVE-2024-45693","title":"Request origin validation bypass makes account takeover possible","state":"PUBLIC","updated":"2024-10-16T10:39:13.974Z","owner":"cloudstack"},{"_id":"66d96bd78dd6167d3a3a3acc","ID":"CVE-2024-45719","title":"Predictable Authorization Token Using UUIDv1","state":"PUBLIC","updated":"2024-11-22T14:36:42.714Z","owner":"answer"},{"_id":"66d999328dd6167d3a3a3c09","ID":"CVE-2024-45720","title":"Command line argument injection on Windows platforms","state":"PUBLIC","updated":"2024-10-09T12:38:27.375Z","owner":"subversion"},{"_id":"66dbb83b8dd6167d3a3a3cef","ID":"CVE-2024-45772","title":"Security Vulnerability in Lucene Replicator - Deserialization Issue","state":"PUBLIC","updated":"2024-12-10T17:34:29.725Z","owner":"lucene"},{"_id":"66dd9fa38dd6167d3a3a3e3f","ID":"CVE-2024-45784","title":"Sensitive configuration values are not masked in the logs by default","state":"PUBLIC","updated":"2024-11-15T08:20:02.608Z","owner":"airflow"},{"_id":"66def96d8dd6167d3a3a3f32","ID":"CVE-2024-45791","title":"Exposure sensitive token via http GET method with query string","state":"PUBLIC","updated":"2024-11-18T08:45:21.798Z","owner":"hertzbeat"},{"_id":"66e1449c8dd6167d3a3a4090","ID":"CVE-2024-46544","title":"mod_jk: local users can view and modify configuration","state":"PUBLIC","updated":"2024-09-23T10:51:17.287Z","owner":"tomcat"},{"_id":"66e3c47a0949e604106fb704","ID":"CVE-2024-46901","title":"mod_dav_svn denial-of-service via control characters in paths","state":"PUBLIC","updated":"2024-12-09T09:36:41.289Z","owner":"subversion"},{"_id":"66e4ac060949e604106fb72b","ID":"CVE-2024-46910","title":"An authenticated user can perform XSS and potentially impersonate another user","state":"PUBLIC","updated":"2025-10-17T15:29:29.800Z","owner":"atlas"},{"_id":"66e72b130949e604106fb764","ID":"CVE-2024-46911","title":"Weakness in CSRF protection allows privilege escalation","state":"PUBLIC","updated":"2024-10-11T21:53:17.272Z","owner":"roller"},{"_id":"66edd53b014320ce1bec302a","ID":"CVE-2024-47197","title":"Maven Archetype integration-test may package local settings into the published artifact, possibly containing credentials","state":"PUBLIC","updated":"2024-09-26T08:01:19.076Z","owner":"maven"},{"_id":"66eeae2b014320ce1bec310b","ID":"CVE-2024-47208","title":"URLs allowing remote use of Groovy expressions, leading to RCE","state":"PUBLIC","updated":"2024-11-18T08:43:11.961Z","owner":"ofbiz"},{"_id":"66f124e6b1fd30fd57e0462e","ID":"CVE-2024-47248","title":"Buffer overflow in NimBLE MESH Bluetooth stack","state":"PUBLIC","updated":"2024-12-06T07:39:45.067Z","owner":"mynewt"},{"_id":"66f12d17b1fd30fd57e0468e","ID":"CVE-2024-47249","title":"Lack of input sanitization leading to out-of-bound reads in multiple advertisement handler","state":"PUBLIC","updated":"2024-12-06T07:49:57.242Z","owner":"mynewt"},{"_id":"66f13180b1fd30fd57e046a6","ID":"CVE-2024-47250","title":"Lack of input validation in HCI advertising report could lead to potential out-of-bound access","state":"PUBLIC","updated":"2024-12-06T07:50:00.629Z","owner":"mynewt"},{"_id":"66f1886db1fd30fd57e047fa","ID":"CVE-2024-47252","title":"mod_ssl error log variable escaping","state":"PUBLIC","updated":"2025-07-11T10:29:12.847Z","owner":"httpd"},{"_id":"66f55155b1fd30fd57e04ac8","ID":"CVE-2024-47552","title":"Deserialization of untrusted Data in jraft mode in Apache Seata Server","state":"PUBLIC","updated":"2026-03-30T02:08:11.034Z","owner":"seata"},{"_id":"66f587feb1fd30fd57e04b7b","ID":"CVE-2024-47554","title":"Possible denial of service attack on untrusted input to XmlStreamReader","state":"PUBLIC","updated":"2024-10-03T11:32:46.805Z","owner":"commons"},{"_id":"66f65987b1fd30fd57e04c6f","ID":"CVE-2024-47561","title":"Arbitrary Code Execution when reading Avro schema (Java SDK)","state":"PUBLIC","updated":"2024-10-21T08:50:48.382Z","owner":"avro"},{"_id":"6705254ad2ad02e7a43e7b64","ID":"CVE-2024-48019","title":"allows admin users to read arbitrary files through the REST API","state":"PUBLIC","updated":"2025-02-04T18:19:49.957Z","owner":"doris"},{"_id":"67071684d2ad02e7a43e7ce8","ID":"CVE-2024-48944","title":"SSRF vulnerability in the diagnosis api","state":"PUBLIC","updated":"2025-04-28T14:59:34.758Z","owner":"kylin"},{"_id":"6707735fd2ad02e7a43e7d46","ID":"CVE-2024-48962","title":"Bypass SameSite restrictions with target redirection using URL parameters (SSTI and CSRF leading to RCE)","state":"PUBLIC","updated":"2026-05-04T14:55:18.092Z","owner":"ofbiz"},{"_id":"670914fed2ad02e7a43e7e75","ID":"CVE-2024-48988","title":"SQL injection vulnerability","state":"PUBLIC","updated":"2025-08-22T16:18:41.486Z","owner":"streampark"},{"_id":"6716ba493146ae0413cc1872","ID":"CVE-2024-50305","title":"Valid Host field value can cause crashes","state":"PUBLIC","updated":"2024-11-14T09:54:18.691Z","owner":"trafficserver"},{"_id":"6716c1463146ae0413cc18bf","ID":"CVE-2024-50306","title":"Server process can fail to drop privilege","state":"PUBLIC","updated":"2024-11-14T09:55:41.120Z","owner":"trafficserver"},{"_id":"6718ba0a3146ae0413cc1961","ID":"CVE-2024-50378","title":"Secrets not masked in UI when sensitive variables are set via Airflow cli","state":"PUBLIC","updated":"2024-11-08T14:37:07.862Z","owner":"airflow"},{"_id":"6718fa9e3146ae0413cc1972","ID":"CVE-2024-50379","title":"RCE due to TOCTOU issue in JSP compilation","state":"PUBLIC","updated":"2025-10-29T11:51:38.009Z","owner":"tomcat"},{"_id":"671965ac3146ae0413cc197c","ID":"CVE-2024-50386","title":"Directly downloaded templates can be used to abuse KVM-based infrastructure","state":"PUBLIC","updated":"2024-11-12T13:52:37.947Z","owner":"cloudstack"},{"_id":"672005f53146ae0413cc1a7c","ID":"CVE-2024-51504","title":"Authentication bypass with IP-based authentication in Admin Server","state":"PUBLIC","updated":"2024-11-07T09:52:02.061Z","owner":"zookeeper"},{"_id":"672243f03146ae0413cc1b07","ID":"CVE-2024-51569","title":"Lack of input sanitization leading to out-of-bound reads in Number of Completed Packets HCI event handler","state":"PUBLIC","updated":"2024-12-06T07:50:42.419Z","owner":"mynewt"},{"_id":"67262b9f8266f1041249873d","ID":"CVE-2024-51775","title":"Command Injection via CSWSH","state":"PUBLIC","updated":"2025-08-03T10:14:50.764Z","owner":"zeppelin"},{"_id":"6728b4448266f104124987f4","ID":"CVE-2024-51941","title":"Remote Code Injection in Ambari Metrics and AMS Alerts","state":"PUBLIC","updated":"2025-09-03T08:07:26.617Z","owner":"ambari"},{"_id":"67291b8da042e6b964be34c9","ID":"CVE-2024-52012","title":"Configset upload on Windows allows arbitrary path write-access","state":"PUBLIC","updated":"2025-01-27T08:54:39.844Z","owner":"solr"},{"_id":"672a19e3a042e6b964be34f8","ID":"CVE-2024-52046","title":"MINA applications using unbounded deserialization may allow RCE","state":"PUBLIC","updated":"2025-02-12T09:33:34.969Z","owner":"mina"},{"_id":"672a7672a042e6b964be35a7","ID":"CVE-2024-52067","title":"Potential Insertion of Sensitive Parameter Values in Debug Log","state":"PUBLIC","updated":"2024-11-21T09:28:41.996Z","owner":"nifi"},{"_id":"672b34bba042e6b964be35ff","ID":"CVE-2024-52279","title":"Arbitrary file read by adding malicious JDBC connection string","state":"PUBLIC","updated":"2025-08-03T10:01:35.245Z","owner":"zeppelin"},{"_id":"672c6f44a042e6b964be3664","ID":"CVE-2024-52316","title":"Authentication bypass when using Jakarta Authentication API","state":"PUBLIC","updated":"2025-10-29T11:51:21.348Z","owner":"tomcat"},{"_id":"672c6fffa042e6b964be366d","ID":"CVE-2024-52317","title":"Request/response mix-up with HTTP/2","state":"PUBLIC","updated":"2024-11-18T11:37:01.194Z","owner":"tomcat"},{"_id":"672c70c2a042e6b964be3676","ID":"CVE-2024-52318","title":"Incorrect JSP tag recycling leads to XSS","state":"PUBLIC","updated":"2024-11-18T12:21:44.105Z","owner":"tomcat"},{"_id":"672e44cca042e6b964be37ae","ID":"CVE-2024-52338","title":"Arbitrary code execution when loading a malicious data file","state":"PUBLIC","updated":"2024-11-28T16:31:53.209Z","owner":"arrow"},{"_id":"6736054fa042e6b964be3b27","ID":"CVE-2024-52577","title":"Possible RCE when deserializing incoming messages by the server node","state":"PUBLIC","updated":"2025-02-14T09:55:31.279Z","owner":"ignite"},{"_id":"673de90ca042e6b964be3f8d","ID":"CVE-2024-53299","title":"An attacker can intentionally trigger a memory leak","state":"PUBLIC","updated":"2025-01-23T08:37:04.162Z","owner":"wicket"},{"_id":"673f678aa042e6b964be4086","ID":"CVE-2024-53677","title":"Mixing setters for uploaded files and normal fields can allow bypass file upload checks","state":"PUBLIC","updated":"2024-12-20T15:44:02.694Z","owner":"struts"},{"_id":"673fad42a042e6b964be40a8","ID":"CVE-2024-53678","title":"SQL injection vulnerability in New Block Allocation form","state":"PUBLIC","updated":"2025-03-25T09:33:34.457Z","owner":"vcl"},{"_id":"673fadf0a042e6b964be40b6","ID":"CVE-2024-53679","title":"XSS vulnerability in User Lookup impacting user privileges","state":"PUBLIC","updated":"2025-03-25T09:33:43.087Z","owner":"vcl"},{"_id":"6740d5095db96fdf62cd0495","ID":"CVE-2024-53868","title":"Malformed chunked message body allows request smuggling","state":"PUBLIC","updated":"2025-04-03T08:58:55.409Z","owner":"trafficserver"},{"_id":"674450215db96fdf62cd05a0","ID":"CVE-2024-53947","title":"Improper SQL authorisation, parse not checking for specific postgres functions","state":"PUBLIC","updated":"2024-12-09T13:35:08.136Z","owner":"superset"},{"_id":"67445b6d5db96fdf62cd05cd","ID":"CVE-2024-53948","title":"Error verbosity exposes metadata in analytics databases","state":"PUBLIC","updated":"2024-12-09T13:35:29.219Z","owner":"superset"},{"_id":"6744610f5db96fdf62cd05ed","ID":"CVE-2024-53949","title":"Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled","state":"PUBLIC","updated":"2025-02-12T09:34:35.897Z","owner":"superset"},{"_id":"6746e9f95db96fdf62cd08a7","ID":"CVE-2024-54016","title":"compression bomb attack in Apache Seata Server","state":"PUBLIC","updated":"2025-03-20T08:59:24.157Z","owner":"seata"},{"_id":"67512f7d5db96fdf62cd0b50","ID":"CVE-2024-54676","title":"Deserialisation of untrusted data in cluster mode","state":"PUBLIC","updated":"2025-01-08T08:40:01.385Z","owner":"openmeetings"},{"_id":"675156d65db96fdf62cd0b66","ID":"CVE-2024-54677","title":"DoS in examples web application","state":"PUBLIC","updated":"2025-10-29T11:50:12.395Z","owner":"tomcat"},{"_id":"67530cc85db96fdf62cd0caa","ID":"CVE-2024-55532","title":"Improper Neutralization of Formula Elements in a CSV File","state":"PUBLIC","updated":"2025-03-03T16:17:53.766Z","owner":"ranger"},{"_id":"6757659c5db96fdf62cd0ebd","ID":"CVE-2024-55633","title":"SQLLab Improper readonly query validation allows unauthorized write access","state":"PUBLIC","updated":"2025-02-12T09:35:41.246Z","owner":"superset"},{"_id":"67603ec013b7fc03f0736b26","ID":"CVE-2024-56128","title":"SCRAM authentication vulnerable to replay attacks when used without encryption","state":"PUBLIC","updated":"2024-12-18T13:38:00.297Z","owner":"kafka"},{"_id":"67627de3e583db0414724bab","ID":"CVE-2024-56180","title":"raft Hessian Deserialization Vulnerability allowing remote code execution","state":"PUBLIC","updated":"2025-02-14T15:26:18.633Z","owner":"eventmesh"},{"_id":"67630cbde583db0414724d61","ID":"CVE-2024-56195","title":"Intercept plugins are not access controlled","state":"PUBLIC","updated":"2025-03-06T11:23:34.892Z","owner":"trafficserver"},{"_id":"6763105be583db0414724d93","ID":"CVE-2024-56196","title":"ACL is not fully compatible with older versions","state":"PUBLIC","updated":"2025-03-06T11:21:46.767Z","owner":"trafficserver"},{"_id":"6763153fe583db0414724de2","ID":"CVE-2024-56202","title":"Expect header field can unreasonably retain resource","state":"PUBLIC","updated":"2025-03-06T11:09:09.771Z","owner":"trafficserver"},{"_id":"67642d95e583db0414724e32","ID":"CVE-2024-56325","title":"Authentication bypass issue. If the path does not contain / and contain . authentication is not required","state":"PUBLIC","updated":"2026-02-20T16:45:37.070Z","owner":"pinot"},{"_id":"6765520ee583db0414724efe","ID":"CVE-2024-56337","title":"RCE due to TOCTOU issue in JSP compilation - CVE-2024-50379 mitigation was incomplete","state":"PUBLIC","updated":"2025-10-29T11:52:34.749Z","owner":"tomcat"},{"_id":"676800b5e583db0414725074","ID":"CVE-2024-56373","title":"SSTI to Code Execution in Airflow through Shared DB Information","state":"PUBLIC","updated":"2026-02-24T10:06:39.270Z","owner":"airflow"},{"_id":"676dafbce583db04147251b7","ID":"CVE-2024-56512","title":"Missing Complete Authorization for Parameter and Service References","state":"PUBLIC","updated":"2024-12-29T11:14:49.689Z","owner":"nifi"},{"_id":"676f7bf2e583db04147252a3","ID":"CVE-2024-56736","title":"Server-Side Request Forgery (SSRF) in Api Config Oss","state":"PUBLIC","updated":"2025-04-16T15:38:09.273Z","owner":"hertzbeat"},{"_id":"677da725e583db0414725435","ID":"CVE-2025-22828","title":"Unauthorised access to annotations","state":"PUBLIC","updated":"2025-01-13T12:40:18.771Z","owner":"cloudstack"},{"_id":"677db765e583db0414725491","ID":"CVE-2025-22829","title":"Unauthorised access to dedicated resources in Quota plugin","state":"PUBLIC","updated":"2025-06-11T04:00:28.410Z","owner":"cloudstack"},{"_id":"6780951ae583db041472567e","ID":"CVE-2025-23015","title":"User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions","state":"PUBLIC","updated":"2025-02-11T15:47:20.883Z","owner":"cassandra"},{"_id":"678138b1e583db04147256dd","ID":"CVE-2025-23048","title":"mod_ssl access control bypass with session resumption","state":"PUBLIC","updated":"2025-07-11T10:30:23.007Z","owner":"httpd"},{"_id":"6784f0dbe583db04147256fb","ID":"CVE-2025-23184","title":"Denial of Service vulnerability with temporary files","state":"PUBLIC","updated":"2025-01-21T09:35:35.654Z","owner":"cxf"},{"_id":"6785245fe583db0414725756","ID":"CVE-2025-23195","title":"XML External Entity (XXE) Vulnerability in Ambari/Oozie","state":"PUBLIC","updated":"2025-01-21T21:22:31.147Z","owner":"ambari"},{"_id":"678526aae583db0414725766","ID":"CVE-2025-23196","title":"Code Injection Vulnerability in Ambari Alert Definition","state":"PUBLIC","updated":"2025-02-03T08:22:23.980Z","owner":"ambari"},{"_id":"67884af1e583db04147258e0","ID":"CVE-2025-23408","title":"weak password policy","state":"PUBLIC","updated":"2025-12-12T09:18:57.063Z","owner":"fineract"},{"_id":"678fb216e583db0414725bb8","ID":"CVE-2025-24404","title":"RCE by parse http sitemap xml response","state":"PUBLIC","updated":"2025-09-09T09:30:57.298Z","owner":"hertzbeat"},{"_id":"67926c0bb366b84f5120236a","ID":"CVE-2025-24783","title":"continuations may not be private","state":"PUBLIC","updated":"2025-01-27T14:47:41.250Z","owner":"cocoon"},{"_id":"679354a6b366b84f5120240a","ID":"CVE-2025-24813","title":"Potential RCE and/or information disclosure and/or information corruption with partial PUT","state":"PUBLIC","updated":"2025-10-29T11:49:42.250Z","owner":"tomcat"},{"_id":"67938c28b366b84f51202448","ID":"CVE-2025-24814","title":"Core-creation with \"trusted\" configset can use arbitrary untrusted files","state":"PUBLIC","updated":"2025-01-27T08:58:06.761Z","owner":"solr"},{"_id":"67954383b366b84f5120257e","ID":"CVE-2025-24853","title":"Cross-Site Scripting (XSS) in JSPWiki Header Link processing","state":"PUBLIC","updated":"2025-07-31T08:42:03.970Z","owner":"jspwiki"},{"_id":"679543e6b366b84f51202592","ID":"CVE-2025-24854","title":"Cross-Site Scripting (XSS) in JSPWiki Image plugin","state":"PUBLIC","updated":"2025-07-31T08:43:17.113Z","owner":"jspwiki"},{"_id":"6796b46ab366b84f51202686","ID":"CVE-2025-24859","title":"Insufficient Session Expiration on Password Change","state":"PUBLIC","updated":"2025-04-18T15:26:03.795Z","owner":"roller"},{"_id":"6797167fb366b84f5120270e","ID":"CVE-2025-24860","title":"CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regions","state":"PUBLIC","updated":"2025-02-04T10:17:53.494Z","owner":"cassandra"},{"_id":"67a0c5ab1dc9d6041cd48ee8","ID":"CVE-2025-25069","title":"Cross-Protocol Scripting Vulnerability","state":"PUBLIC","updated":"2025-02-07T12:46:01.975Z","owner":"kvrocks"},{"_id":"67a304c01dc9d6041cd490f1","ID":"CVE-2025-25247","title":"XSS in services console","state":"PUBLIC","updated":"2025-02-10T11:16:58.175Z","owner":"felix"},{"_id":"67a9f1361dc9d6041cd493cf","ID":"CVE-2025-26413","title":"The server was crashed by the negative offset","state":"PUBLIC","updated":"2025-04-22T10:35:30.358Z","owner":"kvrocks"},{"_id":"67aa89881dc9d6041cd494f0","ID":"CVE-2025-26467","title":"User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only)","state":"PUBLIC","updated":"2025-08-25T13:14:47.609Z","owner":"cassandra"},{"_id":"67ac66171dc9d6041cd4967e","ID":"CVE-2025-26521","title":"CKS cluster in project exposes user API keys","state":"PUBLIC","updated":"2025-06-11T04:00:17.648Z","owner":"cloudstack"},{"_id":"67af1bd31dc9d6041cd49816","ID":"CVE-2025-26795","title":"Exposure of Sensitive Information in IoTDB JDBC driver","state":"PUBLIC","updated":"2025-05-14T10:43:01.849Z","owner":"iotdb"},{"_id":"67af68c11dc9d6041cd498be","ID":"CVE-2025-26796","title":"XSS in Oozie Web Console","state":"PUBLIC","updated":"2025-03-22T12:23:17.532Z","owner":"oozie"},{"_id":"67b306da1dc9d6041cd49908","ID":"CVE-2025-26864","title":"Exposure of Sensitive Information in IoTDB OpenID Authentication","state":"PUBLIC","updated":"2025-05-14T10:44:11.661Z","owner":"iotdb"},{"_id":"67b307091dc9d6041cd49912","ID":"CVE-2025-26865","title":"Server-Side Template Injection affecting the ecommerce plugin leading to possible RCE","state":"PUBLIC","updated":"2025-03-10T14:00:48.257Z","owner":"ofbiz"},{"_id":"67b310221dc9d6041cd49956","ID":"CVE-2025-26866","title":"RAFT and deserialization vulnerability","state":"PUBLIC","updated":"2025-12-12T09:23:05.196Z","owner":"hugegraph"},{"_id":"67b38d981dc9d6041cd499fa","ID":"CVE-2025-27017","title":"Potential Insertion of MongoDB Password in Provenance Record","state":"PUBLIC","updated":"2025-03-12T16:19:42.969Z","owner":"nifi"},{"_id":"67b38e081dc9d6041cd49a1c","ID":"CVE-2025-27018","title":"SQL injection in MySQL provider core function","state":"PUBLIC","updated":"2025-03-19T09:06:05.242Z","owner":"airflow"},{"_id":"67bc3e1a1dc9d6041cd49bb3","ID":"CVE-2025-27391","title":"Passwords leaking from broker properties in the debug log","state":"PUBLIC","updated":"2025-04-09T14:42:30.509Z","owner":"activemq"},{"_id":"67bce00d1dc9d6041cd49c1b","ID":"CVE-2025-27427","title":"Address routing-type can be updated by user without the createAddress permission","state":"PUBLIC","updated":"2025-04-01T07:26:53.803Z","owner":"activemq"},{"_id":"67bea40c1dc9d6041cd49c75","ID":"CVE-2025-27446","title":"Local listening file permissions in APISIX plugin runner allow a local attacker to elevate privileges","state":"PUBLIC","updated":"2025-07-06T03:41:43.412Z","owner":"apisix"},{"_id":"67c00169619c73046b8bf2c6","ID":"CVE-2025-27522","title":"JDBC Vulnerability during verification processing","state":"PUBLIC","updated":"2025-05-28T08:06:02.351Z","owner":"inlong"},{"_id":"67c00fc4619c73046b8bf2fe","ID":"CVE-2025-27526","title":"JDBC Vulnerability For URLEncode and backspace bypass","state":"PUBLIC","updated":"2025-05-28T08:07:33.686Z","owner":"inlong"},{"_id":"67c01518619c73046b8bf332","ID":"CVE-2025-27528","title":"JDBC Vulnerability for Invisible Character Bypass Leading to Arbitrary File Read","state":"PUBLIC","updated":"2025-05-28T08:12:25.901Z","owner":"inlong"},{"_id":"67c12cf4619c73046b8bf38f","ID":"CVE-2025-27531","title":"An arbitrary file read vulnerability for JDBC","state":"PUBLIC","updated":"2025-02-28T12:24:23.760Z","owner":"inlong"},{"_id":"67c1b2ac619c73046b8bf475","ID":"CVE-2025-27533","title":"Unchecked buffer length can cause excessive memory allocation","state":"PUBLIC","updated":"2025-05-07T08:58:58.430Z","owner":"activemq"},{"_id":"67c27caa619c73046b8bf517","ID":"CVE-2025-27553","title":"Possible path traversal issue when using NameScope.DESCENDENT","state":"PUBLIC","updated":"2025-03-23T14:16:17.945Z","owner":"commons"},{"_id":"67c33ad2619c73046b8bf5a8","ID":"CVE-2025-27555","title":"Connection Secrets not masked in UI when Connection are added via Airflow cli","state":"PUBLIC","updated":"2026-03-11T15:10:00.713Z","owner":"airflow"},{"_id":"67c6ea6d619c73046b8bf7fa","ID":"CVE-2025-27636","title":"Camel Message Header Injection via Improper Filtering","state":"PUBLIC","updated":"2025-03-17T14:20:17.925Z","owner":"camel"},{"_id":"67c811ea619c73046b8bf874","ID":"CVE-2025-27696","title":"Incorrect authorization leading to resource ownership takeover","state":"PUBLIC","updated":"2025-09-01T09:52:51.812Z","owner":"superset"},{"_id":"67caaa62619c73046b8bf9aa","ID":"CVE-2025-27817","title":"Arbitrary file read and SSRF vulnerability","state":"PUBLIC","updated":"2025-06-10T07:55:12.969Z","owner":"kafka"},{"_id":"67cabdaf619c73046b8bfa48","ID":"CVE-2025-27818","title":"Possible RCE attack via SASL JAAS LdapLoginModule configuration","state":"PUBLIC","updated":"2025-06-10T07:53:14.155Z","owner":"kafka"},{"_id":"67cac42c619c73046b8bfadb","ID":"CVE-2025-27819","title":"Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration","state":"PUBLIC","updated":"2025-06-10T07:54:40.206Z","owner":"kafka"},{"_id":"67caeaf2619c73046b8bfb39","ID":"CVE-2025-27820","title":"PSL (Public Suffix List) validation bypass","state":"PUBLIC","updated":"2025-06-04T11:19:13.066Z","owner":"httpcomponents"},{"_id":"67cb3354619c73046b8bfc1c","ID":"CVE-2025-27821","title":"Out of bounds write in URI parser of native HDFS client","state":"PUBLIC","updated":"2026-01-26T09:44:12.099Z","owner":"hadoop"},{"_id":"67cd6698619c73046b8bfc5d","ID":"CVE-2025-27867","title":"XSS in HTTP Webconsole Plugin","state":"PUBLIC","updated":"2025-03-12T15:51:23.297Z","owner":"felix"},{"_id":"67cea543619c73046b8bfd66","ID":"CVE-2025-27888","title":"Server-Side Request Forgery and Cross-Site Scripting","state":"PUBLIC","updated":"2025-03-24T07:41:49.543Z","owner":"druid"},{"_id":"67d0ff46619c73046b8bffe1","ID":"CVE-2025-29847","title":"Arbitrary File Read via Double URL Encoding Bypass","state":"PUBLIC","updated":"2026-01-19T08:36:04.753Z","owner":"linkis"},{"_id":"67d13217619c73046b8c001d","ID":"CVE-2025-29868","title":"Using externally referenced images can leak user privacy.","state":"PUBLIC","updated":"2025-04-01T07:56:26.883Z","owner":"answer"},{"_id":"67d14a76619c73046b8c006c","ID":"CVE-2025-29891","title":"Camel Message Header Injection through request parameters","state":"PUBLIC","updated":"2025-03-13T08:19:35.754Z","owner":"camel"},{"_id":"67d1bd57619c73046b8c0280","ID":"CVE-2025-29953","title":"deserialization allowlist bypass","state":"PUBLIC","updated":"2025-04-18T15:23:28.244Z","owner":"activemq"},{"_id":"67d2f7e3619c73046b8c02e9","ID":"CVE-2025-30001","title":"Authenticated users can trigger remote command execution","state":"PUBLIC","updated":"2025-10-10T09:52:24.458Z","owner":"streampark"},{"_id":"67d4f6d3619c73046b8c0393","ID":"CVE-2025-30065","title":"Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata","state":"PUBLIC","updated":"2025-07-11T10:32:31.431Z","owner":"parquet"},{"_id":"67d594d0619c73046b8c03d5","ID":"CVE-2025-30067","title":"The remote code execution via jdbc url","state":"PUBLIC","updated":"2025-03-27T15:06:34.995Z","owner":"kylin"},{"_id":"67d82fcd619c73046b8c043b","ID":"CVE-2025-30177","title":"Camel-Undertow Message Header Injection via Improper Filtering","state":"PUBLIC","updated":"2025-04-01T16:32:28.939Z","owner":"camel"},{"_id":"67deaa60619c73046b8c07aa","ID":"CVE-2025-30473","title":"Remote Code Execution via Sql Injection","state":"PUBLIC","updated":"2025-04-07T08:31:55.441Z","owner":"airflow"},{"_id":"67deca84619c73046b8c07d3","ID":"CVE-2025-30474","title":"Failing to find an FTP file can reveal the URI's password in an error message","state":"PUBLIC","updated":"2025-03-23T14:15:49.617Z","owner":"commons"},{"_id":"67e25801edbf895d4fb2e2a0","ID":"CVE-2025-30675","title":"Unauthorised template/ISO list access to the domain/resource admins","state":"PUBLIC","updated":"2025-06-11T04:00:06.854Z","owner":"cloudstack"},{"_id":"67e25eebedbf895d4fb2e2b6","ID":"CVE-2025-30676","title":"Stored XSS Vulnerability","state":"PUBLIC","updated":"2025-04-01T14:43:47.266Z","owner":"ofbiz"},{"_id":"67e2a830edbf895d4fb2e356","ID":"CVE-2025-30677","title":"Sensitive information logged in Pulsar's Apache Kafka Connectors","state":"PUBLIC","updated":"2025-04-09T11:16:21.827Z","owner":"pulsar"},{"_id":"67ea87059c42ce05202eb30b","ID":"CVE-2025-31650","title":"DoS via malformed HTTP/2 PRIORITY_UPDATE frame","state":"PUBLIC","updated":"2025-08-08T11:42:59.031Z","owner":"tomcat"},{"_id":"67ea89b59c42ce05202eb312","ID":"CVE-2025-31651","title":"Bypass of rules in Rewrite Valve","state":"PUBLIC","updated":"2025-10-29T11:46:25.018Z","owner":"tomcat"},{"_id":"67eb061e9c42ce05202eb366","ID":"CVE-2025-31672","title":"parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names","state":"PUBLIC","updated":"2025-04-09T11:59:31.807Z","owner":"poi"},{"_id":"67eb29149c42ce05202eb3b1","ID":"CVE-2025-31698","title":"Client IP address from PROXY protocol is not used for ACL","state":"PUBLIC","updated":"2025-06-19T10:07:45.344Z","owner":"trafficserver"},{"_id":"67f9d7ad167e02054250fdb5","ID":"CVE-2025-32896","title":"Unauthenticated insecure access","state":"PUBLIC","updated":"2025-06-19T08:34:42.552Z","owner":"seatunnel"},{"_id":"67fa6bff167e02054250fef7","ID":"CVE-2025-32897","title":"Deserialization of untrusted Data in Apache Seata Server","state":"PUBLIC","updated":"2026-03-30T02:05:32.515Z","owner":"seata"},{"_id":"67fe81d5167e0205425100f3","ID":"CVE-2025-33042","title":"Code injection on Java generated code","state":"PUBLIC","updated":"2026-02-13T11:47:01.866Z","owner":"avro"},{"_id":"67febd3a167e02054251011d","ID":"CVE-2025-35003","title":"NuttX Bluetooth Stack HCI and UART DoS/RCE Vulnerabilities.","state":"PUBLIC","updated":"2026-05-08T13:32:43.156Z","owner":"nuttx"},{"_id":"68090005eddee1056a3637b8","ID":"CVE-2025-46392","title":"Uncontrolled Resource Consumption when loading untrusted configurations in 1.x","state":"PUBLIC","updated":"2025-05-09T09:34:18.561Z","owner":"commons"},{"_id":"680a9a1eeddee1056a36386a","ID":"CVE-2025-46548","title":"management API basic authentication is not effective","state":"PUBLIC","updated":"2025-06-11T17:44:21.510Z","owner":"pekko"},{"_id":"680cf57feddee1056a36387f","ID":"CVE-2025-46647","title":"improper validation of issuer from introspection discovery url in plugin openid-connect","state":"PUBLIC","updated":"2025-07-02T01:08:54.683Z","owner":"apisix"},{"_id":"680f7457eddee1056a363922","ID":"CVE-2025-46701","title":"Security constraint bypass for CGI scripts","state":"PUBLIC","updated":"2025-10-29T11:46:00.351Z","owner":"tomcat"},{"_id":"68103e20eddee1056a3639f4","ID":"CVE-2025-46762","title":"Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadata","state":"PUBLIC","updated":"2025-05-06T09:08:12.043Z","owner":"parquet"},{"_id":"681a0ba3fdb3690532dc5c4b","ID":"CVE-2025-47410","title":"CSRF attacks through GET requests to the Management and Monitoring REST API that can execute gfsh commands on the target system","state":"PUBLIC","updated":"2025-10-18T15:15:07.664Z","owner":"geode"},{"_id":"681a1baefdb3690532dc5c60","ID":"CVE-2025-47411","title":"Leverage of User ID for Privilege Escalation","state":"PUBLIC","updated":"2026-01-01T16:41:48.353Z","owner":"streampipes"},{"_id":"681ae9f8fdb3690532dc5d01","ID":"CVE-2025-47436","title":"Potential Heap Buffer Overflow during C++ LZO Decompression","state":"PUBLIC","updated":"2025-05-14T13:11:33.684Z","owner":"orc"},{"_id":"681be1a5fdb3690532dc5db8","ID":"CVE-2025-47713","title":"Domain Admin can reset Admin password in Root Domain","state":"PUBLIC","updated":"2025-06-11T03:59:55.628Z","owner":"cloudstack"},{"_id":"6821b539fdb3690532dc5f84","ID":"CVE-2025-47849","title":"Insecure access of user's API/Secret Keys in the same domain","state":"PUBLIC","updated":"2025-06-11T03:59:42.176Z","owner":"cloudstack"},{"_id":"68224c9cfdb3690532dc5fe2","ID":"CVE-2025-47868","title":"tools/bdf-converter: Fix loop termination condition.","state":"PUBLIC","updated":"2026-05-08T13:34:11.805Z","owner":"nuttx"},{"_id":"68224ca7fdb3690532dc5fe4","ID":"CVE-2025-47869","title":"examples/xmlrpc: Fix calls buffers size.","state":"PUBLIC","updated":"2026-05-08T13:35:33.530Z","owner":"nuttx"},{"_id":"682930c1dfb565053eaab703","ID":"CVE-2025-48208","title":"Jmx JNDI injection vulnerability","state":"PUBLIC","updated":"2025-09-09T09:31:33.928Z","owner":"hertzbeat"},{"_id":"682be046dfb565053eaab784","ID":"CVE-2025-48392","title":"DoS Vulnerability","state":"PUBLIC","updated":"2025-09-24T07:59:48.976Z","owner":"iotdb"},{"_id":"682ce595dfb565053eaab8fd","ID":"CVE-2025-48431","title":"Specially crafted input can crash a c_glib Thrift server with invalid pointer error.","state":"PUBLIC","updated":"2026-04-28T09:11:42.895Z","owner":"thrift"},{"_id":"682ec34c64ad2f9ccb51be6d","ID":"CVE-2025-48459","title":"Deserialization of untrusted Data","state":"PUBLIC","updated":"2025-09-24T07:57:20.978Z","owner":"iotdb"},{"_id":"68306a6864ad2f9ccb51bee3","ID":"CVE-2025-48734","title":"Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default","state":"PUBLIC","updated":"2025-05-28T13:32:13.606Z","owner":"commons"},{"_id":"6833b8be64ad2f9ccb51bfe0","ID":"CVE-2025-48768","title":"fs/inode: fs_inoderemove root inode removal","state":"PUBLIC","updated":"2026-01-01T16:13:58.511Z","owner":"nuttx"},{"_id":"6833c63864ad2f9ccb51c05e","ID":"CVE-2025-48769","title":"fs/vfs/fs_rename: use after free","state":"PUBLIC","updated":"2026-01-01T16:14:32.107Z","owner":"nuttx"},{"_id":"68342b0d64ad2f9ccb51c096","ID":"CVE-2025-48795","title":"Denial of Service and sensitive data exposure in logs","state":"PUBLIC","updated":"2025-07-15T14:26:43.340Z","owner":"cxf"},{"_id":"6836d74364ad2f9ccb51c2f8","ID":"CVE-2025-48912","title":"Improper authorization bypass on row level security via SQL Injection","state":"PUBLIC","updated":"2025-05-30T08:26:07.560Z","owner":"superset"},{"_id":"6836dfca64ad2f9ccb51c332","ID":"CVE-2025-48913","title":"Untrusted JMS configuration can lead to RCE","state":"PUBLIC","updated":"2025-08-08T09:21:18.803Z","owner":"cxf"},{"_id":"6837268b64ad2f9ccb51c45a","ID":"CVE-2025-48924","title":"ClassUtils.getClass(...) can throw a StackOverflowError on very long inputs","state":"PUBLIC","updated":"2025-07-11T14:56:54.861Z","owner":"commons"},{"_id":"68380a7264ad2f9ccb51c4d8","ID":"CVE-2025-48976","title":"FileUpload DoS via part headers","state":"PUBLIC","updated":"2025-06-16T15:00:47.037Z","owner":"commons"},{"_id":"68380f3b64ad2f9ccb51c4ec","ID":"CVE-2025-48977","title":"REST HTTP arbitrary file read vulnerability","state":"PUBLIC","updated":"2026-05-28T08:58:05.304Z","owner":"ignite"},{"_id":"68387c3064ad2f9ccb51c575","ID":"CVE-2025-48988","title":"FileUpload large number of parts with headers DoS","state":"PUBLIC","updated":"2025-10-29T11:45:34.776Z","owner":"tomcat"},{"_id":"68387c7164ad2f9ccb51c577","ID":"CVE-2025-48989","title":"h2 DoS - Made You Reset","state":"PUBLIC","updated":"2025-10-29T11:45:00.142Z","owner":"tomcat"},{"_id":"683d622664ad2f9ccb51c70b","ID":"CVE-2025-49124","title":"exe side-loading via icalcs.exe in Tomcat installer for Windows","state":"PUBLIC","updated":"2025-10-29T11:44:21.737Z","owner":"tomcat"},{"_id":"683d6a1664ad2f9ccb51c717","ID":"CVE-2025-49125","title":"Security constraint bypass for pre/post-resources","state":"PUBLIC","updated":"2025-10-29T11:43:27.486Z","owner":"tomcat"},{"_id":"6842b3908526dd2663c37742","ID":"CVE-2025-49506","title":"apr_password_validate() vulnerable to timing attack","state":"PUBLIC","updated":"2026-08-06T14:33:11.589Z","owner":"apr"},{"_id":"6845e8338526dd2663c378f1","ID":"CVE-2025-49630","title":"mod_proxy_http2 denial of service","state":"PUBLIC","updated":"2025-08-13T15:38:59.198Z","owner":"httpd"},{"_id":"684710098526dd2663c37ad8","ID":"CVE-2025-49656","title":"Administrative users can create files outside the server directory space via the admin UI","state":"PUBLIC","updated":"2025-07-21T09:30:16.936Z","owner":"jena"},{"_id":"684769e48526dd2663c37b32","ID":"CVE-2025-49763","title":"Remote DoS via memory exhaustion in ESI Plugin","state":"PUBLIC","updated":"2025-06-19T10:07:13.563Z","owner":"trafficserver"},{"_id":"68494e368526dd2663c37e10","ID":"CVE-2025-49812","title":"mod_ssl TLS upgrade attack","state":"PUBLIC","updated":"2025-07-11T10:29:53.093Z","owner":"httpd"},{"_id":"684c4e278526dd2663c37f5a","ID":"CVE-2025-50151","title":"Configuration files uploaded by administrative users are not check properly","state":"PUBLIC","updated":"2025-07-21T09:32:27.896Z","owner":"jena"},{"_id":"684d97488526dd2663c37fd2","ID":"CVE-2025-50213","title":"Potential SQL injection in CopyFromExternalStageToSnowflakeOperator","state":"PUBLIC","updated":"2025-06-24T07:06:50.934Z","owner":"airflow"},{"_id":"684fc11f8526dd2663c380a3","ID":"CVE-2025-52434","title":"APR/Native Connector crash leading to DoS","state":"PUBLIC","updated":"2025-10-29T11:42:49.909Z","owner":"tomcat"},{"_id":"685023ce8526dd2663c38213","ID":"CVE-2025-52435","title":"Invalid error handling in pause encryption procedure in NimBLE controller","state":"PUBLIC","updated":"2026-01-10T09:47:08.833Z","owner":"mynewt"},{"_id":"685119d48526dd2663c3830e","ID":"CVE-2025-52520","title":"DoS via integer overflow in multipart file upload","state":"PUBLIC","updated":"2025-10-29T11:41:28.130Z","owner":"tomcat"},{"_id":"685a500f8526dd2663c385c1","ID":"CVE-2025-53020","title":"HTTP/2 DoS by Memory Increase","state":"PUBLIC","updated":"2025-07-11T10:30:11.990Z","owner":"httpd"},{"_id":"685e6cf08526dd2663c38711","ID":"CVE-2025-53192","title":"Expression Injection leading to RCE","state":"PUBLIC","updated":"2025-08-18T20:09:29.375Z","owner":"commons"},{"_id":"6862947b8526dd2663c38826","ID":"CVE-2025-53470","title":"Out-of-Bounds Write Vulnerability in NimBLE HCI H4 driver","state":"PUBLIC","updated":"2026-01-10T09:46:32.072Z","owner":"mynewt"},{"_id":"6862a5148526dd2663c3885a","ID":"CVE-2025-53477","title":"NULL Pointer Dereference in NimBLE host HCI layer","state":"PUBLIC","updated":"2026-01-10T09:45:08.352Z","owner":"mynewt"},{"_id":"6863ef0c8526dd2663c388a7","ID":"CVE-2025-53506","title":"DoS via excessive h2 streams at connection start","state":"PUBLIC","updated":"2025-10-29T11:40:57.934Z","owner":"tomcat"},{"_id":"68693f238526dd2663c38a76","ID":"CVE-2025-53606","title":"Deserialization of untrusted Data in Apache Seata Server","state":"PUBLIC","updated":"2025-08-08T09:22:52.076Z","owner":"seata"},{"_id":"686ca9f98526dd2663c38b42","ID":"CVE-2025-53648","title":"SQL misconfiguration can access or truncate files","state":"PUBLIC","updated":"2026-06-30T13:35:54.650Z","owner":"gravitino"},{"_id":"686cf11d8526dd2663c38b6c","ID":"CVE-2025-53689","title":"XXE vulnerability in jackrabbit-spi-commons","state":"PUBLIC","updated":"2025-07-14T09:15:35.583Z","owner":"jackrabbit"},{"_id":"68766f6a8526dd2663c392c1","ID":"CVE-2025-53960","title":"Uses the user’s password as the secret key","state":"PUBLIC","updated":"2025-12-16T10:08:35.119Z","owner":"streampark"},{"_id":"687788838526dd2663c392f6","ID":"CVE-2025-54057","title":"Stored XSS vulnerability","state":"PUBLIC","updated":"2026-04-13T12:24:00.847Z","owner":"skywalking"},{"_id":"6877e3448526dd2663c3932e","ID":"CVE-2025-54090","title":"'RewriteCond expr' always evaluates to true in 2.4.64","state":"PUBLIC","updated":"2025-07-23T13:19:23.112Z","owner":"httpd"},{"_id":"688098743d7d61c841967f5e","ID":"CVE-2025-54466","title":"RCE Vulnerability in scrum plugin","state":"PUBLIC","updated":"2025-08-15T14:13:40.046Z","owner":"ofbiz"},{"_id":"6880a92f3d7d61c841967fb8","ID":"CVE-2025-54472","title":"Redis Parser Remote Denial of Service","state":"PUBLIC","updated":"2025-08-12T02:14:20.765Z","owner":"brpc"},{"_id":"688226cc3d7d61c8419680e7","ID":"CVE-2025-54539","title":"Deserialization of Untrusted Data","state":"PUBLIC","updated":"2025-10-16T08:26:04.874Z","owner":"activemq"},{"_id":"6882a1383d7d61c841968107","ID":"CVE-2025-54550","title":"RCE by race condition in example_xcom dag","state":"PUBLIC","updated":"2026-04-19T23:47:06.426Z","owner":"airflow"},{"_id":"68873cd13d7d61c8419681b5","ID":"CVE-2025-54656","title":"Improper Output Neutralization for Logs","state":"PUBLIC","updated":"2025-07-30T15:58:00.516Z","owner":"struts"},{"_id":"6889707b3d7d61c8419682be","ID":"CVE-2025-54812","title":"Improper HTML escaping in HTMLLayout","state":"PUBLIC","updated":"2025-08-22T18:46:44.374Z","owner":"logging"},{"_id":"688973623d7d61c8419682eb","ID":"CVE-2025-54813","title":"Improper escaping with JSONLayout","state":"PUBLIC","updated":"2025-08-22T18:45:40.110Z","owner":"logging"},{"_id":"688a137d3d7d61c84196838e","ID":"CVE-2025-54831","title":"Connection sensitive details exposed to users with READ permissions","state":"PUBLIC","updated":"2025-09-26T07:28:57.402Z","owner":"airflow"},{"_id":"688c13d93d7d61c841968526","ID":"CVE-2025-54920","title":"Spark History Server Code Execution Vulnerability","state":"PUBLIC","updated":"2026-03-14T09:01:48.596Z","owner":"spark"},{"_id":"688c64c83d7d61c84196856c","ID":"CVE-2025-54941","title":"Command injection in \"example_dag_decorator\"","state":"PUBLIC","updated":"2025-10-30T09:45:25.170Z","owner":"airflow"},{"_id":"688c86d83d7d61c8419685a2","ID":"CVE-2025-54947","title":"Use hard-coded key vulnerability","state":"PUBLIC","updated":"2025-12-12T15:11:36.470Z","owner":"streampark"},{"_id":"689087ae3d7d61c84196867c","ID":"CVE-2025-54981","title":"Weak Encryption Algorithm in StreamPark","state":"PUBLIC","updated":"2025-12-12T15:10:32.960Z","owner":"streampark"},{"_id":"6890da0a3d7d61c8419686ac","ID":"CVE-2025-54988","title":"XXE vulnerability in PDFParser's handling of XFA","state":"PUBLIC","updated":"2025-08-28T17:43:30.753Z","owner":"tika"},{"_id":"68916a053d7d61c841968704","ID":"CVE-2025-55017","title":"Path Traversal Vulnerability","state":"PUBLIC","updated":"2026-06-26T12:15:51.835Z","owner":"iotdb"},{"_id":"6892a17a3d7d61c8419687c9","ID":"CVE-2025-55039","title":"RPC encryption defaults to unauthenticated AES-CTR mode, enabling man-in-the-middle ciphertext modification attacks","state":"PUBLIC","updated":"2025-10-14T20:48:57.896Z","owner":"spark"},{"_id":"689c82243d7d61c841968ed1","ID":"CVE-2025-55668","title":"session fixation via rewrite valve","state":"PUBLIC","updated":"2025-10-29T11:39:27.849Z","owner":"tomcat"},{"_id":"689c87473d7d61c841968eef","ID":"CVE-2025-55672","title":"Stored XSS on charts metadata","state":"PUBLIC","updated":"2025-08-14T13:17:31.272Z","owner":"superset"},{"_id":"689c8b683d7d61c841968f34","ID":"CVE-2025-55673","title":"Metadata exposure in embedded charts","state":"PUBLIC","updated":"2025-08-14T13:16:25.157Z","owner":"superset"},{"_id":"689c8ce13d7d61c841968f58","ID":"CVE-2025-55674","title":"Improper SQL authorisation, parse not checking for specific engine functions","state":"PUBLIC","updated":"2025-08-14T13:18:08.885Z","owner":"superset"},{"_id":"689c9bcc3d7d61c841968fa9","ID":"CVE-2025-55675","title":"Incorrect datasource authorization on REST API","state":"PUBLIC","updated":"2025-08-14T13:18:52.601Z","owner":"superset"},{"_id":"689eec5b3d7d61c8419691dd","ID":"CVE-2025-55752","title":"Directory traversal via rewrite with possible RCE if PUT is enabled","state":"PUBLIC","updated":"2025-10-29T11:38:53.688Z","owner":"tomcat"},{"_id":"689ef20d3d7d61c8419691eb","ID":"CVE-2025-55753","title":"mod_md (ACME), unintended retry intervals","state":"PUBLIC","updated":"2025-12-05T10:17:13.634Z","owner":"httpd"},{"_id":"689f19703d7d61c84196927b","ID":"CVE-2025-55754","title":"console manipulation via escape sequences in log messages","state":"PUBLIC","updated":"2025-10-29T11:38:22.595Z","owner":"tomcat"},{"_id":"68a394643d7d61c8419694b8","ID":"CVE-2025-57735","title":"Airflow Logout Not Invalidating JWT","state":"PUBLIC","updated":"2026-04-09T11:12:40.266Z","owner":"airflow"},{"_id":"68a41a643d7d61c8419694d3","ID":"CVE-2025-57738","title":"Remote Code Execution by delegated administrators","state":"PUBLIC","updated":"2025-10-20T14:43:38.022Z","owner":"syncope"},{"_id":"68a8b93b3d7d61c841969953","ID":"CVE-2025-58098","title":"Server Side Includes adds query string to #exec cmd=...","state":"PUBLIC","updated":"2025-12-05T13:40:37.496Z","owner":"httpd"},{"_id":"68ac9bd13d7d61c841969ad2","ID":"CVE-2025-58130","title":"Server Key not masked","state":"PUBLIC","updated":"2025-12-12T09:20:05.211Z","owner":"fineract"},{"_id":"68acd76e3d7d61c841969bc1","ID":"CVE-2025-58136","title":"A simple legitimate POST request causes a crash","state":"PUBLIC","updated":"2026-04-10T15:53:47.491Z","owner":"trafficserver"},{"_id":"68acf9f33d7d61c841969c0c","ID":"CVE-2025-58137","title":"IDOR via self-service API","state":"PUBLIC","updated":"2025-12-12T09:20:50.539Z","owner":"fineract"},{"_id":"68b1074e3d7d61c841969e36","ID":"CVE-2025-58337","title":"Improper Access Control results in bypassing a \"read-only\" mode for doris-mcp-server MCP Server","state":"PUBLIC","updated":"2025-11-05T09:26:34.887Z","owner":"doris"},{"_id":"68b6d4813d7d61c841969ea4","ID":"CVE-2025-58457","title":"Insufficient Permission Check in AdminServer Snapshot/Restore Commands","state":"PUBLIC","updated":"2025-09-24T09:29:42.132Z","owner":"zookeeper"},{"_id":"68babfbd3d7d61c84196a104","ID":"CVE-2025-58782","title":"JNDI injection risk with JndiRepositoryFactory","state":"PUBLIC","updated":"2026-04-10T15:55:02.565Z","owner":"jackrabbit"},{"_id":"68bf223b3d7d61c84196a28a","ID":"CVE-2025-59059","title":"Remote Code Execution Vulnerability in NashornScriptEngineCreator","state":"PUBLIC","updated":"2026-03-03T10:46:03.383Z","owner":"ranger"},{"_id":"68bf26a23d7d61c84196a2c0","ID":"CVE-2025-59060","title":"Hostname verification bypass in NiFiRegistryClient","state":"PUBLIC","updated":"2026-08-21T20:11:10.266Z","owner":"ranger"},{"_id":"68bffa0b3d7d61c84196a33a","ID":"CVE-2025-59118","title":"Critical Remote Command Execution via Unrestricted File Upload","state":"PUBLIC","updated":"2025-11-12T09:15:52.459Z","owner":"ofbiz"},{"_id":"68c386c13d7d61c84196a4d0","ID":"CVE-2025-59302","title":"Potential remote code execution on Javascript engine defined rules","state":"PUBLIC","updated":"2025-11-27T11:46:23.798Z","owner":"cloudstack"},{"_id":"68c3bb653d7d61c84196a536","ID":"CVE-2025-59328","title":"Denial of Service (DoS) due to Deserialization of Untrusted malicious large Data","state":"PUBLIC","updated":"2025-09-15T16:26:55.892Z","owner":"fory"},{"_id":"68c424e33d7d61c84196a5f9","ID":"CVE-2025-59355","title":"Password Exposure","state":"PUBLIC","updated":"2026-01-19T08:37:22.783Z","owner":"linkis"},{"_id":"68c7e47a3d7d61c84196a6bf","ID":"CVE-2025-59390","title":"Kerberos authenticaton chooses a cryptographically unsecure secret if not configured explicitly.","state":"PUBLIC","updated":"2025-12-11T12:56:31.790Z","owner":"druid"},{"_id":"68c8f42d3d7d61c84196a749","ID":"CVE-2025-59454","title":"Lack of user permission validation leading to data leak for few APIs","state":"PUBLIC","updated":"2025-11-27T11:40:37.834Z","owner":"cloudstack"},{"_id":"68cd48f8b2861f866543e3d0","ID":"CVE-2025-59775","title":"NTLM Leakage on Windows through UNC SSRF","state":"PUBLIC","updated":"2025-12-05T10:17:02.236Z","owner":"httpd"},{"_id":"68ce47170fb3306a98b5abcb","ID":"CVE-2025-59789","title":"Stack Exhaustion via Unbounded Recursion in JSON Parser","state":"PUBLIC","updated":"2025-12-01T02:28:22.223Z","owner":"brpc"},{"_id":"68cf6f6d0fb3306a98b5ac0e","ID":"CVE-2025-59790","title":"RESET command grants admin privileges","state":"PUBLIC","updated":"2025-11-28T14:20:28.481Z","owner":"kvrocks"},{"_id":"68cf78640fb3306a98b5ac2a","ID":"CVE-2025-59792","title":"MONITOR command reveals plaintext credentials to non-admins","state":"PUBLIC","updated":"2025-11-28T14:21:21.082Z","owner":"kvrocks"},{"_id":"68d2efff0fb3306a98b5ad78","ID":"CVE-2025-60012","title":"Restrict file access","state":"PUBLIC","updated":"2026-03-13T15:23:05.927Z","owner":"livy"},{"_id":"68d3ea3b0fb3306a98b5ae7f","ID":"CVE-2025-60021","title":"Remote command injection vulnerability in heap builtin service","state":"PUBLIC","updated":"2026-01-16T08:39:21.612Z","owner":"brpc"},{"_id":"68d69e527e2d6d052a99921a","ID":"CVE-2025-61581","title":"ReDoS issue in Traffic Router configuration","state":"PUBLIC","updated":"2025-10-16T08:40:10.117Z","owner":"trafficcontrol"},{"_id":"68da2b7b7e2d6d052a9992a0","ID":"CVE-2025-61622","title":"Python RCE via unguarded pickle fallback serializer in pyfory","state":"PUBLIC","updated":"2025-10-04T14:58:38.087Z","owner":"fory"},{"_id":"68da2f927e2d6d052a9992cd","ID":"CVE-2025-61623","title":"Reflected Cross-site Scripting","state":"PUBLIC","updated":"2025-11-12T09:16:48.899Z","owner":"ofbiz"},{"_id":"68dbf2d07e2d6d052a999431","ID":"CVE-2025-61733","title":"Authentication bypass","state":"PUBLIC","updated":"2026-02-02T07:33:38.093Z","owner":"kylin"},{"_id":"68dbf84b7e2d6d052a99948f","ID":"CVE-2025-61734","title":"improper restriction of file read","state":"PUBLIC","updated":"2026-02-02T07:35:03.252Z","owner":"kylin"},{"_id":"68dbfada7e2d6d052a9994c1","ID":"CVE-2025-61735","title":"Server-Side Request Forgery","state":"PUBLIC","updated":"2026-02-02T07:35:53.853Z","owner":"kylin"},{"_id":"68dcf2757e2d6d052a999508","ID":"CVE-2025-61795","title":"Delayed cleaning of multi-part upload temporary files may lead to DoS","state":"PUBLIC","updated":"2025-10-29T11:37:37.868Z","owner":"tomcat"},{"_id":"68e685f17e2d6d052a9995a2","ID":"CVE-2025-62188","title":"Users can access sensitive information through the actuator endpoint.","state":"PUBLIC","updated":"2026-04-08T09:09:06.393Z","owner":"dolphinscheduler"},{"_id":"68e6bf277e2d6d052a999647","ID":"CVE-2025-62198","title":"Stored XSS in Create Entity page","state":"PUBLIC","updated":"2026-06-22T07:47:10.790Z","owner":"atlas"},{"_id":"68e71bf27e2d6d052a99968f","ID":"CVE-2025-62228","title":"SQL injection via maliciously crafted identifiers","state":"PUBLIC","updated":"2025-10-09T13:15:41.457Z","owner":"flink"},{"_id":"68e768357e2d6d052a99973b","ID":"CVE-2025-62232","title":"basic-auth logs plaintext credentials at info level","state":"PUBLIC","updated":"2025-10-31T08:48:32.770Z","owner":"apisix"},{"_id":"68e7ad317e2d6d052a99980b","ID":"CVE-2025-62233","title":"Deserialization of untrusted data in RPC","state":"PUBLIC","updated":"2026-04-24T10:54:53.855Z","owner":"dolphinscheduler"},{"_id":"68e7d49c7e2d6d052a9998e7","ID":"CVE-2025-62235","title":"Incorrect handling of SMP Security Request could lead to undesirable pairing","state":"PUBLIC","updated":"2026-01-10T09:42:36.935Z","owner":"mynewt"},{"_id":"68ecf5a17e2d6d052a999a2a","ID":"CVE-2025-62402","title":"Airflow 3 API: /api/v2/dagReports executes DAG Python in API","state":"PUBLIC","updated":"2025-10-30T09:14:24.818Z","owner":"airflow"},{"_id":"68efaaed7e2d6d052a999bbb","ID":"CVE-2025-62503","title":"Privilege boundary bypass in bulk APIs (create action can upsert existing Pools/Connections/Variables)","state":"PUBLIC","updated":"2025-10-30T09:11:15.486Z","owner":"airflow"},{"_id":"68f738277e2d6d052a999ddc","ID":"CVE-2025-62728","title":"SQL injection vulnerability when processing delete column statistics requests via the HMS Thrift APIs","state":"PUBLIC","updated":"2025-11-26T10:29:43.944Z","owner":"hive"},{"_id":"69009a0d7e2d6d052a99a101","ID":"CVE-2025-64152","title":"Path Traversal Vulnerability","state":"PUBLIC","updated":"2026-06-26T12:16:26.834Z","owner":"iotdb"},{"_id":"690708197e2d6d052a99a778","ID":"CVE-2025-64401","title":"Remote documents loaded without prompt via IFrame","state":"PUBLIC","updated":"2025-11-12T13:57:23.255Z","owner":"openoffice"},{"_id":"690714ba7e2d6d052a99a7dd","ID":"CVE-2025-64402","title":"Remote documents loaded without prompt via OLE objects","state":"PUBLIC","updated":"2025-11-12T09:03:00.298Z","owner":"openoffice"},{"_id":"690718a17e2d6d052a99a801","ID":"CVE-2025-64403","title":"Remote documents loaded without prompt via \"external data sources\" in Calc","state":"PUBLIC","updated":"2025-11-12T09:04:48.789Z","owner":"openoffice"},{"_id":"690729287e2d6d052a99a826","ID":"CVE-2025-64404","title":"Remote documents loaded without prompt via background and bullet images","state":"PUBLIC","updated":"2025-11-12T09:08:28.789Z","owner":"openoffice"},{"_id":"69072ac07e2d6d052a99a84c","ID":"CVE-2025-64405","title":"Remote documents loaded without prompt via DDE function","state":"PUBLIC","updated":"2025-11-12T09:10:33.592Z","owner":"openoffice"},{"_id":"69072cdb7e2d6d052a99a860","ID":"CVE-2025-64406","title":"Possible memory corruption during CSV import","state":"PUBLIC","updated":"2025-11-12T09:11:45.438Z","owner":"openoffice"},{"_id":"69072fe87e2d6d052a99a892","ID":"CVE-2025-64407","title":"URL fetching can be used to exfiltrate arbitrary INI file values and environment variables","state":"PUBLIC","updated":"2025-11-12T09:12:41.931Z","owner":"openoffice"},{"_id":"6908e18b7e2d6d052a99a9cc","ID":"CVE-2025-64408","title":"Java deserialization vulnerability to authenticated attackers","state":"PUBLIC","updated":"2025-11-19T10:32:04.142Z","owner":"causeway"},{"_id":"691352577e2d6d052a99ac16","ID":"CVE-2025-64775","title":"File leak in multipart request processing causes disk exhaustion (DoS)","state":"PUBLIC","updated":"2025-12-07T08:27:17.883Z","owner":"struts"},{"_id":"691b2bee7e2d6d052a99b033","ID":"CVE-2025-65082","title":"CGI environment variable override","state":"PUBLIC","updated":"2025-12-05T10:46:23.466Z","owner":"httpd"},{"_id":"691bb9af7e2d6d052a99b071","ID":"CVE-2025-65114","title":"Malformed chunked message body allows request smuggling","state":"PUBLIC","updated":"2026-04-10T15:56:14.648Z","owner":"trafficserver"},{"_id":"691ce78f7e2d6d052a99b0eb","ID":"CVE-2025-65995","title":"Disclosure of secrets to UI via kwargs","state":"PUBLIC","updated":"2026-03-08T19:08:56.440Z","owner":"airflow"},{"_id":"691d7b1e7e2d6d052a99b1c2","ID":"CVE-2025-65998","title":"Default AES key used for internal password encryption","state":"PUBLIC","updated":"2025-11-24T13:46:58.386Z","owner":"syncope"},{"_id":"6920cf3a7e2d6d052a99b3b7","ID":"CVE-2025-66168","title":"MQTT control packet remaining length field is not properly validated","state":"PUBLIC","updated":"2026-04-10T10:52:26.234Z","owner":"activemq"},{"_id":"6921dc3f7e2d6d052a99b3d3","ID":"CVE-2025-66169","title":"Cypher injection vulnerability in Camel-Neo4j component","state":"PUBLIC","updated":"2026-01-14T11:45:34.042Z","owner":"camel"},{"_id":"69220e4b7e2d6d052a99b3dc","ID":"CVE-2025-66170","title":"Any user can list backups that they should not have access to","state":"PUBLIC","updated":"2026-05-08T12:06:38.994Z","owner":"cloudstack"},{"_id":"69220e747e2d6d052a99b3e2","ID":"CVE-2025-66171","title":"Any user can create a new VM from backups they should not have access to","state":"PUBLIC","updated":"2026-05-08T12:11:10.736Z","owner":"cloudstack"},{"_id":"69220e8b7e2d6d052a99b3e4","ID":"CVE-2025-66172","title":"Any user can attach a volume in their VMs from backups they should not have access to","state":"PUBLIC","updated":"2026-05-08T12:13:30.758Z","owner":"cloudstack"},{"_id":"692480927e2d6d052a99b43c","ID":"CVE-2025-66200","title":"mod_userdir+suexec bypass via AllowOverride FileInfo","state":"PUBLIC","updated":"2025-12-05T11:02:46.192Z","owner":"httpd"},{"_id":"6925d3577e2d6d052a99b4b3","ID":"CVE-2025-66236","title":"Secrets from Airflow config file logged in plain text in DAG run logs UI","state":"PUBLIC","updated":"2026-04-13T14:20:35.201Z","owner":"airflow"},{"_id":"69260bc17e2d6d052a99b4bd","ID":"CVE-2025-66249","title":"Unauthorized directory access","state":"PUBLIC","updated":"2026-04-10T15:57:26.189Z","owner":"livy"},{"_id":"6927c4227e2d6d052a99b741","ID":"CVE-2025-66335","title":"MCP SQL inject","state":"PUBLIC","updated":"2026-04-17T09:41:43.983Z","owner":"doris"},{"_id":"6927c4707e2d6d052a99b74a","ID":"CVE-2025-66336","title":"SQL injection leading the authentication bypass","state":"PUBLIC","updated":"2026-06-22T06:55:16.362Z","owner":"doris"},{"_id":"6929f8c47e2d6d052a99bb2b","ID":"CVE-2025-66388","title":"Secrets in rendered templates not redacted properly and exposed in the UI","state":"PUBLIC","updated":"2025-12-15T11:30:42.649Z","owner":"airflow"},{"_id":"692edbc57e2d6d052a99bc38","ID":"CVE-2025-66467","title":"MinIO policy remains intact on bucket deletion","state":"PUBLIC","updated":"2026-05-08T12:16:09.128Z","owner":"cloudstack"},{"_id":"6930c3957e2d6d052a99bcb4","ID":"CVE-2025-66516","title":"Update to CVE-2025-54988 to expand scope of artifacts affected","state":"PUBLIC","updated":"2025-12-30T15:07:41.528Z","owner":"tika"},{"_id":"6930e8467e2d6d052a99bcf4","ID":"CVE-2025-66518","title":"Unauthorized directory access due to missing path normalization","state":"PUBLIC","updated":"2026-01-05T08:46:25.781Z","owner":"kyuubi"},{"_id":"693106e77e2d6d052a99bdd7","ID":"CVE-2025-66524","title":"Deserialization of Untrusted Data in GetAsanaObject Processor","state":"PUBLIC","updated":"2025-12-19T09:24:44.035Z","owner":"nifi"},{"_id":"6932c7f7c9466108a64fcb07","ID":"CVE-2025-66614","title":"Client certificate verification bypass due to virtual host mapping","state":"PUBLIC","updated":"2026-03-24T09:46:30.194Z","owner":"tomcat"},{"_id":"69353a09c9466108a64fcbaa","ID":"CVE-2025-66675","title":"File leak in multipart request processing causes disk exhaustion (DoS) - version ranges fixed","state":"PUBLIC","updated":"2025-12-10T07:13:32.174Z","owner":"struts"},{"_id":"693d99cfc9466108a64fd357","ID":"CVE-2025-67895","title":"Edge3 Worker RPC RCE on Airflow 2","state":"PUBLIC","updated":"2025-12-17T11:48:30.034Z","owner":"airflow"},{"_id":"694142edc9466108a64fd454","ID":"CVE-2025-68161","title":"Missing TLS hostname verification in Socket appender","state":"PUBLIC","updated":"2026-08-24T11:29:02.055Z","owner":"logging"},{"_id":"69416f2bc9466108a64fd4c5","ID":"CVE-2025-68280","title":"XML External Entity (XXE) vulnerability","state":"PUBLIC","updated":"2026-04-10T15:58:12.739Z","owner":"sis"},{"_id":"6942dad0c9466108a64fd64e","ID":"CVE-2025-68438","title":"Secrets in rendered templates could contain parts of sensitive values when truncated","state":"PUBLIC","updated":"2026-01-16T10:06:05.336Z","owner":"airflow"},{"_id":"6944f5a0ae0cd9ae0ffbff4e","ID":"CVE-2025-68493","title":"XXE vulnerability in outdated XWork component","state":"PUBLIC","updated":"2026-03-11T15:11:35.231Z","owner":"struts"},{"_id":"694693e6ae0cd9ae0ffbffdf","ID":"CVE-2025-68637","title":"Insecure SSL Configuration in Uniffle HTTP Client","state":"PUBLIC","updated":"2026-01-07T09:39:02.164Z","owner":"uniffle"},{"_id":"694a84ecae0cd9ae0ffc0116","ID":"CVE-2025-68675","title":"proxy credentials for various providers might leak in task logs","state":"PUBLIC","updated":"2026-02-24T05:48:09.000Z","owner":"airflow"},{"_id":"6952b441ae0cd9ae0ffc01da","ID":"CVE-2025-69219","title":"Unsafe Pickle Deserialization in apache-airflow-providers-http leading to RCE via HttpOperator","state":"PUBLIC","updated":"2026-03-09T10:19:56.479Z","owner":"airflow"},{"_id":"6953097eae0cd9ae0ffc01e0","ID":"CVE-2025-69233","title":"Domain/account resources limits not honored","state":"PUBLIC","updated":"2026-05-08T12:19:36.271Z","owner":"cloudstack"},{"_id":"695c2473ae0cd9ae0ffc03b6","ID":"CVE-2026-22022","title":"Unauthorized bypass of certain \"predefined permission\" rules in the RuleBasedAuthorizationPlugin","state":"PUBLIC","updated":"2026-01-21T13:41:44.763Z","owner":"solr"},{"_id":"695c53feae0cd9ae0ffc03ff","ID":"CVE-2026-22068","title":"Regex mappings match with malicious domain names","state":"PUBLIC","updated":"2026-07-29T07:18:58.921Z","owner":"trafficserver"},{"_id":"695e5fa0ae0cd9ae0ffc050b","ID":"CVE-2026-22444","title":"Insufficient file-access checking in standalone core-creation requests","state":"PUBLIC","updated":"2026-01-21T13:40:23.406Z","owner":"solr"},{"_id":"6966539dae0cd9ae0ffc089f","ID":"CVE-2026-22922","title":"Airflow externalLogUrl Permission Bypass","state":"PUBLIC","updated":"2026-02-09T10:33:48.256Z","owner":"airflow"},{"_id":"696782c5ae0cd9ae0ffc0973","ID":"CVE-2016-15057","title":"Command injection leading to RCE","state":"PUBLIC","updated":"2026-02-06T10:50:44.556Z","owner":"continuum"},{"_id":"69678bbeae0cd9ae0ffc098d","ID":"CVE-2026-23552","title":"Camel-Keycloak: Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy","state":"PUBLIC","updated":"2026-02-22T15:55:13.482Z","owner":"camel"},{"_id":"696a06fab7c3a3054490e0d6","ID":"CVE-2026-23794","title":"Reflected XSS on Enduser Login","state":"PUBLIC","updated":"2026-02-03T15:15:22.918Z","owner":"syncope"},{"_id":"696a1de9b7c3a3054490e158","ID":"CVE-2026-23795","title":"Console XXE on Keymaster parameters","state":"PUBLIC","updated":"2026-02-03T15:14:33.685Z","owner":"syncope"},{"_id":"696bce91b7c3a3054490e1d7","ID":"CVE-2026-23901","title":"Brute force attack possible to determine valid user names","state":"PUBLIC","updated":"2026-02-10T09:25:49.952Z","owner":"shiro"},{"_id":"696c5c78b7c3a3054490e225","ID":"CVE-2026-23902","title":"Users are able to use tenants that are not defined on the platform during workflow execution.","state":"PUBLIC","updated":"2026-04-24T10:56:16.919Z","owner":"dolphinscheduler"},{"_id":"696d8580b7c3a3054490e273","ID":"CVE-2026-23903","title":"Auth bypass when accessing static files only on case-insensitive filesystems","state":"PUBLIC","updated":"2026-08-20T03:10:19.598Z","owner":"shiro"},{"_id":"696da7beb7c3a3054490e317","ID":"CVE-2026-23904","title":"Unrestricted access via Kyuubi engine-ui proxy","state":"PUBLIC","updated":"2026-07-29T04:15:21.816Z","owner":"kyuubi"},{"_id":"696df1e6b7c3a3054490e3fc","ID":"CVE-2026-23906","title":"Authentication Bypass via LDAP Anonymous Bind","state":"PUBLIC","updated":"2026-02-10T09:28:07.546Z","owner":"druid"},{"_id":"696e1ffeb7c3a3054490e430","ID":"CVE-2026-23907","title":"Path Traversal in PDFBox ExtractEmbeddedFiles Example Code","state":"PUBLIC","updated":"2026-03-10T16:53:49.159Z","owner":"pdfbox"},{"_id":"696e2ae5b7c3a3054490e486","ID":"CVE-2026-23918","title":"http2: double free and possible RCE on early reset","state":"PUBLIC","updated":"2026-05-04T14:44:27.003Z","owner":"httpd"},{"_id":"696e56dbb7c3a3054490e4ac","ID":"CVE-2026-23969","title":"Exposure of Sensitive Information via Incomplete ClickHouse Function Filtering","state":"PUBLIC","updated":"2026-02-24T13:02:53.998Z","owner":"superset"},{"_id":"696e5a4cb7c3a3054490e4f6","ID":"CVE-2026-23980","title":"Improper Neutralization of Special Elements used in a SQL Command","state":"PUBLIC","updated":"2026-02-24T12:54:08.623Z","owner":"superset"},{"_id":"696e5beeb7c3a3054490e516","ID":"CVE-2026-23981","title":"Improper Authorization in Chart Update allowing Dashboard Modification","state":"PUBLIC","updated":"2026-07-30T16:08:22.552Z","owner":"superset"},{"_id":"696e6141b7c3a3054490e540","ID":"CVE-2026-23982","title":"Improper Authorization in Dataset Creation Allows Access Control Bypass","state":"PUBLIC","updated":"2026-02-24T12:52:42.954Z","owner":"superset"},{"_id":"696e633db7c3a3054490e55a","ID":"CVE-2026-23983","title":"Sensitive Data Exposure via REST API (disabled by default)","state":"PUBLIC","updated":"2026-02-24T12:52:09.887Z","owner":"superset"},{"_id":"696e6645b7c3a3054490e587","ID":"CVE-2026-23984","title":"SQLLab Read-Only Bypass on PostgreSQL","state":"PUBLIC","updated":"2026-02-24T12:51:05.623Z","owner":"superset"},{"_id":"696e6874b7c3a3054490e5ab","ID":"CVE-2026-23985","title":"Regular Expression Denial of Service (ReDoS) in SQL Parser","state":"PUBLIC","updated":"2026-07-30T16:09:19.372Z","owner":"superset"},{"_id":"696ee8c6b7c3a3054490e5f1","ID":"CVE-2026-24012","title":"Denial of Service via Resource Exhaustion in Aggregation Query","state":"PUBLIC","updated":"2026-07-06T07:19:25.470Z","owner":"iotdb"},{"_id":"696ee928b7c3a3054490e5fb","ID":"CVE-2026-24013","title":"Authentication Bypass via Forged SessionID in Thrift RPC","state":"PUBLIC","updated":"2026-07-06T07:17:46.194Z","owner":"iotdb"},{"_id":"696ef0dbb7c3a3054490e605","ID":"CVE-2026-24014","title":"Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write","state":"PUBLIC","updated":"2026-07-06T08:34:23.903Z","owner":"iotdb"},{"_id":"696ef514b7c3a3054490e60b","ID":"CVE-2026-24015","title":"Insecure Default Configuration Vulnerability","state":"PUBLIC","updated":"2026-03-09T08:57:43.961Z","owner":"iotdb"},{"_id":"696fcbceb7c3a3054490e73c","ID":"CVE-2026-24033","title":"Request smuggling via chunked extension quoted-string parsing","state":"PUBLIC","updated":"2026-07-29T07:22:37.470Z","owner":"trafficserver"},{"_id":"6970c892b7c3a3054490e773","ID":"CVE-2026-24072","title":"mod_rewrite elevation of privileges via ap_expr","state":"PUBLIC","updated":"2026-05-04T12:37:56.221Z","owner":"httpd"},{"_id":"6970f655b7c3a3054490e7bb","ID":"CVE-2026-24098","title":"Assigning single DAG permission leaked all DAGs Import Errors","state":"PUBLIC","updated":"2026-03-10T18:13:52.941Z","owner":"airflow"},{"_id":"69712ba9b7c3a3054490e7c9","ID":"CVE-2026-24281","title":"Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager","state":"PUBLIC","updated":"2026-03-07T08:50:30.345Z","owner":"zookeeper"},{"_id":"6971472bb7c3a3054490e877","ID":"CVE-2026-24308","title":"Sensitive information disclosure in client configuration handling","state":"PUBLIC","updated":"2026-03-07T08:51:03.330Z","owner":"zookeeper"},{"_id":"6971e34bb7c3a3054490e8f2","ID":"CVE-2026-24343","title":"Uncontrolled Resource Consumption via Crafted XPath Expressions","state":"PUBLIC","updated":"2026-02-09T15:07:42.730Z","owner":"hertzbeat"},{"_id":"6973b602b7c3a3054490ea20","ID":"CVE-2026-24656","title":"Decanter log-socket collector has deserialization vulnerability","state":"PUBLIC","updated":"2026-01-26T09:41:22.803Z","owner":"karaf"},{"_id":"6976d407b7c3a3054490eabd","ID":"CVE-2026-24713","title":"JEXL Expression Injection Vulnerability","state":"PUBLIC","updated":"2026-03-09T08:59:57.653Z","owner":"iotdb"},{"_id":"69777324b7c3a3054490eb4c","ID":"CVE-2026-24733","title":"Security constraint bypass with HTTP/0.9","state":"PUBLIC","updated":"2026-02-17T18:50:40.418Z","owner":"tomcat"},{"_id":"69777849b7c3a3054490eb63","ID":"CVE-2026-24734","title":"OCSP revocation bypass","state":"PUBLIC","updated":"2026-02-17T18:53:09.659Z","owner":"tomcat"},{"_id":"69779077b7c3a3054490eb69","ID":"CVE-2026-24735","title":"Revision API Improper Access Control leads to Information Disclosure","state":"PUBLIC","updated":"2026-06-03T06:48:19.838Z","owner":"answer"},{"_id":"6978fec2b7c3a3054490ebdc","ID":"CVE-2026-24880","title":"Request smuggling via invalid chunk extension","state":"PUBLIC","updated":"2026-04-09T19:46:23.955Z","owner":"tomcat"},{"_id":"697a87a5b7c3a3054490ec8c","ID":"CVE-2026-25077","title":"Unauthenticated Command Injection in Direct Download Templates","state":"PUBLIC","updated":"2026-05-08T12:21:33.362Z","owner":"cloudstack"},{"_id":"697b25cfb7c3a3054490ecd7","ID":"CVE-2026-25087","title":"Potential use-after-free when reading IPC file with pre-buffering","state":"PUBLIC","updated":"2026-02-20T09:56:40.992Z","owner":"arrow"},{"_id":"697c374fb7c3a3054490ed33","ID":"CVE-2026-25199","title":"Proxmox Extension Allows Unauthorized Cross-Tenant Instance Access","state":"PUBLIC","updated":"2026-05-08T12:23:04.078Z","owner":"cloudstack"},{"_id":"697c7657b7c3a3054490ed74","ID":"CVE-2026-25219","title":"Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access","state":"PUBLIC","updated":"2026-04-15T13:14:51.470Z","owner":"airflow"},{"_id":"6981c703b7c3a3054490eeb3","ID":"CVE-2026-25604","title":"Apache Airflow AWS Auth Manager - Host Header Injection Leading to SAML Authentication Bypass","state":"PUBLIC","updated":"2026-03-09T10:39:37.628Z","owner":"airflow"},{"_id":"698458d6b7c3a3054490efbe","ID":"CVE-2026-25688","title":"XSS in AI Answer Rendering","state":"PUBLIC","updated":"2026-06-09T07:32:22.140Z","owner":"answer"},{"_id":"69845d2db7c3a3054490efee","ID":"CVE-2026-25699","title":"Authorization Bypass in Timeline API","state":"PUBLIC","updated":"2026-06-09T07:33:11.641Z","owner":"answer"},{"_id":"6984903fb7c3a3054490f068","ID":"CVE-2026-25700","title":"AdminToken not invalidated after admin deactivation","state":"PUBLIC","updated":"2026-06-10T14:56:58.543Z","owner":"answer"},{"_id":"6984d76cb7c3a3054490f0ca","ID":"CVE-2026-25747","title":"Deserialization of Untrusted Data in Camel LevelDB","state":"PUBLIC","updated":"2026-04-03T14:58:52.459Z","owner":"camel"},{"_id":"698615e7b7c3a3054490f13e","ID":"CVE-2026-25854","title":"Occasionally open redirect","state":"PUBLIC","updated":"2026-04-09T19:47:07.298Z","owner":"tomcat"},{"_id":"6987fe2cb7c3a3054490f144","ID":"CVE-2026-25903","title":"Missing Authorization of Restricted Permissions for Component Updates","state":"PUBLIC","updated":"2026-02-17T09:54:42.673Z","owner":"nifi"},{"_id":"6989c861b7c3a3054490f2fc","ID":"CVE-2026-25917","title":"API extra-links triggers XCom deserialization/class instantiation (Airflow 3.1.5)","state":"PUBLIC","updated":"2026-04-17T20:19:53.511Z","owner":"airflow"},{"_id":"698a65dbb7c3a3054490f3c2","ID":"CVE-2026-26032","title":"PackagerResolver path traversal vulnerability","state":"PUBLIC","updated":"2026-07-15T18:49:39.291Z","owner":"ant"},{"_id":"6993148ab7c3a3054490f5ca","ID":"CVE-2026-26929","title":"Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata","state":"PUBLIC","updated":"2026-03-17T10:54:03.388Z","owner":"airflow"},{"_id":"6995ca225913bc1be1e85a07","ID":"CVE-2026-27172","title":"Unsafe Java deserialization in camel-consul ConsulRegistry allows arbitrary code execution via malicious values read from the Consul KV store","state":"PUBLIC","updated":"2026-04-27T09:59:44.109Z","owner":"camel"},{"_id":"6995ca435913bc1be1e85a11","ID":"CVE-2026-27173","title":"JWT Token Exposure in KubernetesExecutor Command-Line Arguments","state":"PUBLIC","updated":"2026-05-22T18:42:19.144Z","owner":"airflow"},{"_id":"6996536d5913bc1be1e85a27","ID":"CVE-2026-27314","title":"Privilege escalation via ADD IDENTITY authorization bypass","state":"PUBLIC","updated":"2026-04-07T16:33:42.799Z","owner":"cassandra"},{"_id":"69969dcf5913bc1be1e85a34","ID":"CVE-2026-27315","title":"cqlsh history sensitive information leak","state":"PUBLIC","updated":"2026-04-07T16:40:48.899Z","owner":"cassandra"},{"_id":"6997360e5913bc1be1e85a7f","ID":"CVE-2026-27446","title":"Auth bypass for Core downstream federation","state":"PUBLIC","updated":"2026-03-17T15:30:04.446Z","owner":"artemis"},{"_id":"69a436ae5913bc1be1e861f0","ID":"CVE-2026-28563","title":"DAG authorization bypass","state":"PUBLIC","updated":"2026-03-17T10:54:55.864Z","owner":"airflow"},{"_id":"69a4f5805913bc1be1e861fd","ID":"CVE-2026-28564","title":"REST Basic Authentication Accepts Stale Cached Credentials","state":"PUBLIC","updated":"2026-07-10T07:08:01.156Z","owner":"iotdb"},{"_id":"69a5fdbf5913bc1be1e8637e","ID":"CVE-2026-28672","title":"OS Command Injection via Username in UnixUserGroupBuilder","state":"PUBLIC","updated":"2026-08-10T10:26:31.190Z","owner":"ranger"},{"_id":"69a6b4085913bc1be1e8643a","ID":"CVE-2026-28779","title":"Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications","state":"PUBLIC","updated":"2026-03-17T10:43:18.236Z","owner":"airflow"},{"_id":"69a6d49c5913bc1be1e8649a","ID":"CVE-2026-28780","title":"buffer overflow in mod_proxy_ajp via  ajp_msg_check_header()","state":"PUBLIC","updated":"2026-05-05T21:29:39.951Z","owner":"httpd"},{"_id":"69a6f7935913bc1be1e8653b","ID":"CVE-2026-28811","title":"Error Handling - Reveals Error Details","state":"PUBLIC","updated":"2026-07-30T12:17:16.969Z","owner":"jspwiki"},{"_id":"69a6f7b85913bc1be1e86545","ID":"CVE-2026-28812","title":"UserManager does not sanity-check user database at startup","state":"PUBLIC","updated":"2026-07-30T12:17:53.394Z","owner":"jspwiki"},{"_id":"69a6f7d65913bc1be1e8655b","ID":"CVE-2026-28813","title":"JSPWiki vulnerable to JSON hijacking","state":"PUBLIC","updated":"2026-07-30T12:18:27.400Z","owner":"jspwiki"},{"_id":"69a6f7f25913bc1be1e86561","ID":"CVE-2026-28814","title":"Pre-Authentication Arbitrary Wiki Markup Rendering","state":"PUBLIC","updated":"2026-07-30T12:19:01.429Z","owner":"jspwiki"},{"_id":"69a7ea785913bc1be1e867a2","ID":"CVE-2026-29129","title":"TLS cipher order is not preserved","state":"PUBLIC","updated":"2026-04-09T19:47:40.805Z","owner":"tomcat"},{"_id":"69a800ed5913bc1be1e867f2","ID":"CVE-2026-29145","title":"OCSP checks sometimes soft-fail even when soft-fail is disabled","state":"PUBLIC","updated":"2026-04-09T19:48:12.636Z","owner":"tomcat"},{"_id":"69a80b0b5913bc1be1e867f7","ID":"CVE-2026-29146","title":"EncryptInterceptor vulnerable to padding oracle attack by default","state":"PUBLIC","updated":"2026-04-09T19:48:55.475Z","owner":"tomcat"},{"_id":"69a81bd25913bc1be1e86819","ID":"CVE-2026-29167","title":"mod_ldap per-dir use-after-free","state":"PUBLIC","updated":"2026-06-08T15:08:08.305Z","owner":"httpd"},{"_id":"69a81c125913bc1be1e86823","ID":"CVE-2026-29168","title":"mod_md unrestricted OCSP response","state":"PUBLIC","updated":"2026-05-08T18:04:07.527Z","owner":"httpd"},{"_id":"69a81c885913bc1be1e86825","ID":"CVE-2026-29169","title":"mod_dav_lock indirect lock crash","state":"PUBLIC","updated":"2026-05-05T16:53:52.408Z","owner":"httpd"},{"_id":"69a822955913bc1be1e86827","ID":"CVE-2026-29170","title":"mod_proxy_ftp XSS","state":"PUBLIC","updated":"2026-06-08T15:10:13.886Z","owner":"httpd"},{"_id":"69a84cf75913bc1be1e868da","ID":"CVE-2026-29207","title":"Low-Privilege SSTI Leading to RCE in the Content Component","state":"PUBLIC","updated":"2026-05-19T09:18:23.188Z","owner":"ofbiz"},{"_id":"69a84dab5913bc1be1e868f8","ID":"CVE-2026-29220","title":"Low-Privilege LFI in Content Component","state":"PUBLIC","updated":"2026-05-19T09:17:05.818Z","owner":"ofbiz"},{"_id":"69a84dd65913bc1be1e868fe","ID":"CVE-2026-29226","title":"Low-Privilege SSRF in Content Component","state":"PUBLIC","updated":"2026-05-19T09:19:35.072Z","owner":"ofbiz"},{"_id":"69a8d7055913bc1be1e86a5e","ID":"CVE-2026-30778","title":"The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.","state":"PUBLIC","updated":"2026-04-15T10:54:23.696Z","owner":"skywalking"},{"_id":"69ab07d05913bc1be1e86b4f","ID":"CVE-2026-30898","title":"Bad example of BashOperator shell injection via dag_run.conf","state":"PUBLIC","updated":"2026-04-18T02:40:37.049Z","owner":"airflow"},{"_id":"69ac28cc5913bc1be1e86cff","ID":"CVE-2026-30911","title":"Execution API HITL Endpoints Missing Per-Task Authorization","state":"PUBLIC","updated":"2026-03-17T10:53:00.535Z","owner":"airflow"},{"_id":"69ac2cd15913bc1be1e86d01","ID":"CVE-2026-30912","title":"Exposing stack trace in case of constraint error","state":"PUBLIC","updated":"2026-04-18T02:41:53.492Z","owner":"airflow"},{"_id":"69ae81e95913bc1be1e87031","ID":"CVE-2026-31378","title":"JSON Attribute Override and URL Allowlist Bypass Leads to Remote Code Execution","state":"PUBLIC","updated":"2026-05-19T09:21:23.935Z","owner":"ofbiz"},{"_id":"69ae877a5913bc1be1e8703b","ID":"CVE-2026-31379","title":"Path Traversal and File Upload Validation Bypass Leading to Arbitrary File Write, Stored XSS and RCE in Catalog Manager","state":"PUBLIC","updated":"2026-05-19T09:22:53.895Z","owner":"ofbiz"},{"_id":"69ae8bfd5913bc1be1e8705e","ID":"CVE-2026-31380","title":"FreeMarker SSTI via Duplicate Parameter Sanitization Bypass","state":"PUBLIC","updated":"2026-05-19T09:24:43.138Z","owner":"ofbiz"},{"_id":"69ae94b75913bc1be1e8709a","ID":"CVE-2026-31387","title":"Cookie Manipulation Allows Authenticated JWT Forgery and Account Impersonation","state":"PUBLIC","updated":"2026-05-19T09:27:10.241Z","owner":"ofbiz"},{"_id":"69ae9ae75913bc1be1e870a8","ID":"CVE-2026-31388","title":"Cross-Tenant Data Exposure via Program Export Feature","state":"PUBLIC","updated":"2026-05-19T09:28:35.638Z","owner":"ofbiz"},{"_id":"69afc78b5913bc1be1e8725e","ID":"CVE-2026-31906","title":"Reflected XSS via Improper HTML Attribute Escaping in Layered-Modal Dialog Parameters","state":"PUBLIC","updated":"2026-05-19T09:30:23.994Z","owner":"ofbiz"},{"_id":"69afd4645913bc1be1e87271","ID":"CVE-2026-31908","title":"forward auth plugin allows header injection","state":"PUBLIC","updated":"2026-04-14T08:06:15.933Z","owner":"apisix"},{"_id":"69afe0925913bc1be1e872f9","ID":"CVE-2026-31909","title":"Unauthenticated Shipment Label Image Disclosure","state":"PUBLIC","updated":"2026-05-19T09:32:51.623Z","owner":"ofbiz"},{"_id":"69afe2075913bc1be1e87311","ID":"CVE-2026-31910","title":"Improper Input Validation in UI Factory Classes Leads to SSRF and Blind File Access","state":"PUBLIC","updated":"2026-05-19T09:33:43.399Z","owner":"ofbiz"},{"_id":"69b005a95913bc1be1e8745e","ID":"CVE-2026-31923","title":"Openid-connect `tls_verify` field is disabled by default","state":"PUBLIC","updated":"2026-04-14T08:38:57.640Z","owner":"apisix"},{"_id":"69b00b0d5913bc1be1e87524","ID":"CVE-2026-31924","title":"Plugin tencent-cloud-cls log export uses plaintext HTTP","state":"PUBLIC","updated":"2026-04-14T08:08:04.772Z","owner":"apisix"},{"_id":"69b045075913bc1be1e875b8","ID":"CVE-2026-31986","title":"Unauthenticated RCE via Default JWT Signing Key and Widget Template Injection","state":"PUBLIC","updated":"2026-05-19T09:34:42.293Z","owner":"ofbiz"},{"_id":"69b0636d5913bc1be1e8762b","ID":"CVE-2026-31987","title":"JWT token appearing in logs","state":"PUBLIC","updated":"2026-04-16T17:49:35.608Z","owner":"airflow"},{"_id":"69b0de785913bc1be1e87635","ID":"CVE-2026-32227","title":"SQL Injection vulnerability in lookup functionality","state":"PUBLIC","updated":"2026-08-10T10:26:05.115Z","owner":"ranger"},{"_id":"69b1530c5913bc1be1e8768d","ID":"CVE-2026-32228","title":"Users with asset materialization permisssions could trigger Dags they had no access to","state":"PUBLIC","updated":"2026-04-18T02:42:30.328Z","owner":"airflow"},{"_id":"69b280105913bc1be1e8778a","ID":"CVE-2026-32327","title":"apr-util XML stack recursion crash","state":"PUBLIC","updated":"2026-08-06T14:32:41.688Z","owner":"apr"},{"_id":"69b2c1435913bc1be1e877fa","ID":"CVE-2026-32588","title":"Authenticated DoS via ALTER ROLE Password Hashing","state":"PUBLIC","updated":"2026-04-08T14:57:32.286Z","owner":"cassandra"},{"_id":"69b2e47c5913bc1be1e87852","ID":"CVE-2026-32642","title":"Temporary address auto-created for OpenWire consumer without createAddress permission","state":"PUBLIC","updated":"2026-03-24T07:54:40.342Z","owner":"artemis"},{"_id":"69b3eca85913bc1be1e879a0","ID":"CVE-2026-32690","title":"3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1","state":"PUBLIC","updated":"2026-04-18T02:36:09.517Z","owner":"airflow"},{"_id":"69b7d8bf5913bc1be1e87b11","ID":"CVE-2026-32794","title":"TLS Certificate Verification Disabled in Databricks Provider K8s Token Exchange","state":"PUBLIC","updated":"2026-03-30T21:43:36.022Z","owner":"airflow"},{"_id":"69b8b3675913bc1be1e87b78","ID":"CVE-2026-32966","title":"DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure","state":"PUBLIC","updated":"2026-06-17T08:48:15.528Z","owner":"dolphinscheduler"},{"_id":"69b8b3be5913bc1be1e87b7a","ID":"CVE-2026-32967","title":"The `/v2` experimental interface lacks permission checks","state":"PUBLIC","updated":"2026-08-21T08:22:51.583Z","owner":"dolphinscheduler"},{"_id":"69b95d645913bc1be1e87c7c","ID":"CVE-2026-32990","title":"Fix for CVE-2025-66614 is incomplete","state":"PUBLIC","updated":"2026-04-09T19:49:26.655Z","owner":"tomcat"},{"_id":"69b97abf5913bc1be1e87cb3","ID":"CVE-2026-33005","title":"Insufficient checks in FileWebService","state":"PUBLIC","updated":"2026-04-09T15:52:49.573Z","owner":"openmeetings"},{"_id":"69b984895913bc1be1e87cd9","ID":"CVE-2026-33006","title":"mod_auth_digest timing attack","state":"PUBLIC","updated":"2026-05-04T14:41:59.911Z","owner":"httpd"},{"_id":"69b9854d5913bc1be1e87d05","ID":"CVE-2026-33007","title":"mod_authn_socache crash","state":"PUBLIC","updated":"2026-05-05T14:54:49.081Z","owner":"httpd"},{"_id":"69b9ece95913bc1be1e87d13","ID":"CVE-2026-33227","title":"Improper Limitation of a Pathname to a Restricted Classpath Directory","state":"PUBLIC","updated":"2026-04-08T15:44:44.530Z","owner":"activemq"},{"_id":"69ba84325913bc1be1e87d6c","ID":"CVE-2026-33264","title":"DAG author RCE on webserver via unrestricted import_string() in BaseSerialization.deserialize()","state":"PUBLIC","updated":"2026-07-07T12:25:55.676Z","owner":"airflow"},{"_id":"69bab3cb5913bc1be1e87d75","ID":"CVE-2026-33266","title":"Hardcoded Remember-Me Cookie Encryption Key and Salt","state":"PUBLIC","updated":"2026-04-09T15:52:32.475Z","owner":"openmeetings"},{"_id":"69bac67a5913bc1be1e87db7","ID":"CVE-2026-33267","title":"Untrusted @ headers can spoof ATS internal metadata","state":"PUBLIC","updated":"2026-07-29T07:21:47.559Z","owner":"trafficserver"},{"_id":"69bd0d985913bc1be1e87ebd","ID":"CVE-2026-33453","title":"CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution","state":"PUBLIC","updated":"2026-04-27T09:58:44.714Z","owner":"camel"},{"_id":"69bd17815913bc1be1e87ec7","ID":"CVE-2026-33454","title":"Inbound Header Filter Missing in MailHeaderFilterStrategy Allows Remote Code Execution via MIME Header Injection (CVE-2025-30177 Variant)","state":"PUBLIC","updated":"2026-04-27T09:42:29.897Z","owner":"camel"},{"_id":"69bd84035913bc1be1e87f5d","ID":"CVE-2026-33523","title":"multiple modules: HTTP response splitting forwarding malicious status line","state":"PUBLIC","updated":"2026-05-04T14:40:39.823Z","owner":"httpd"},{"_id":"69c0b02d5913bc1be1e87ff9","ID":"CVE-2026-33557","title":"Missing JWT token validation in OAUTHBEARER authentication","state":"PUBLIC","updated":"2026-04-18T14:14:44.004Z","owner":"kafka"},{"_id":"69c0b7915913bc1be1e8802d","ID":"CVE-2026-33558","title":"Information Exposure Through Network Client Log Output","state":"PUBLIC","updated":"2026-04-18T14:13:55.292Z","owner":"kafka"},{"_id":"69c132c45913bc1be1e88102","ID":"CVE-2026-33582","title":"Uploading specially crafted TIFF files causes an Out-of-Memory error","state":"PUBLIC","updated":"2026-06-09T07:34:00.786Z","owner":"answer"},{"_id":"69c2574b5913bc1be1e881f1","ID":"CVE-2026-33857","title":"Off-by-one OOB reads in AJP getter functions","state":"PUBLIC","updated":"2026-05-04T13:07:29.296Z","owner":"httpd"},{"_id":"69c259b75913bc1be1e88243","ID":"CVE-2026-33858","title":"Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API","state":"PUBLIC","updated":"2026-04-13T14:36:29.251Z","owner":"airflow"},{"_id":"69c2c49b5913bc1be1e8838b","ID":"CVE-2026-33929","title":"Path Traversal in PDFBox ExtractEmbeddedFiles Example Code","state":"PUBLIC","updated":"2026-04-14T08:09:38.140Z","owner":"pdfbox"},{"_id":"69c2d8625913bc1be1e883b8","ID":"CVE-2026-33930","title":"Buffer overflow via Host field that has a long string value","state":"PUBLIC","updated":"2026-07-29T07:23:50.719Z","owner":"trafficserver"},{"_id":"69c3abb35913bc1be1e884a1","ID":"CVE-2026-34020","title":"Login Credentials Passed via GET Query Parameters","state":"PUBLIC","updated":"2026-04-09T15:52:02.110Z","owner":"openmeetings"},{"_id":"69c3e4a95913bc1be1e8851d","ID":"CVE-2026-34031","title":"The custom avatar was not properly validated","state":"PUBLIC","updated":"2026-06-09T07:34:37.370Z","owner":"answer"},{"_id":"69c3e58f5913bc1be1e88527","ID":"CVE-2026-34032","title":"mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string)","state":"PUBLIC","updated":"2026-06-04T16:35:28.706Z","owner":"httpd"},{"_id":"69c3e6035913bc1be1e88545","ID":"CVE-2026-34033","title":"HTML Content Injection in Email","state":"PUBLIC","updated":"2026-06-09T07:35:14.622Z","owner":"answer"},{"_id":"69c40abb5913bc1be1e88580","ID":"CVE-2026-34059","title":"mod_proxy_ajp: Heap Over-Read and memory disclosure in  ajp_parse_data()","state":"PUBLIC","updated":"2026-05-04T12:39:41.105Z","owner":"httpd"},{"_id":"69c522135913bc1be1e88721","ID":"CVE-2026-34191","title":"SQL Injection in apr_dbd_oracle","state":"PUBLIC","updated":"2026-08-06T14:32:23.055Z","owner":"apr"},{"_id":"69c547e95913bc1be1e88922","ID":"CVE-2026-34197","title":"Authenticated users could perform RCE via Jolokia MBeans","state":"PUBLIC","updated":"2026-04-08T15:39:05.835Z","owner":"activemq"},{"_id":"69c66abc5913bc1be1e88a86","ID":"CVE-2026-34355","title":"mod_proxy_html buffer overflow","state":"PUBLIC","updated":"2026-06-08T15:20:36.831Z","owner":"httpd"},{"_id":"69c66e385913bc1be1e88a8c","ID":"CVE-2026-34356","title":"ProxyPassReverseCookieMap buffer overflow","state":"PUBLIC","updated":"2026-06-08T15:12:26.477Z","owner":"httpd"},{"_id":"69c73f425913bc1be1e88ca6","ID":"CVE-2026-34476","title":"Server-Side Request Forgery via SW-URL Header in MCP Server","state":"PUBLIC","updated":"2026-04-13T13:00:58.883Z","owner":"skywalking"},{"_id":"69c7bacc5913bc1be1e88cd7","ID":"CVE-2026-34477","title":"verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass","state":"PUBLIC","updated":"2026-04-10T15:36:10.071Z","owner":"logging"},{"_id":"69c7d4ef5913bc1be1e88d4b","ID":"CVE-2026-34478","title":"Log injection in Rfc5424Layout due to silent configuration incompatibility","state":"PUBLIC","updated":"2026-04-10T15:40:07.991Z","owner":"logging"},{"_id":"69c7e0685913bc1be1e88dd1","ID":"CVE-2026-34479","title":"Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters","state":"PUBLIC","updated":"2026-04-10T15:41:04.182Z","owner":"logging"},{"_id":"69c7f3d75913bc1be1e88e52","ID":"CVE-2026-34480","title":"Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters","state":"PUBLIC","updated":"2026-04-10T15:41:58.452Z","owner":"logging"},{"_id":"69c82ab95913bc1be1e88edf","ID":"CVE-2026-34481","title":"Improper serialization of non-finite floating-point values in JsonTemplateLayout","state":"PUBLIC","updated":"2026-07-11T04:55:35.716Z","owner":"logging"},{"_id":"69ca28fc5913bc1be1e8903c","ID":"CVE-2026-34483","title":"Incomplete escaping of JSON access logs","state":"PUBLIC","updated":"2026-04-09T19:49:51.643Z","owner":"tomcat"},{"_id":"69ca2cfd5913bc1be1e8909f","ID":"CVE-2026-34486","title":"Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor","state":"PUBLIC","updated":"2026-04-09T19:50:23.342Z","owner":"tomcat"},{"_id":"69ca30085913bc1be1e890a4","ID":"CVE-2026-34487","title":"Cloud membership for clustering component exposed the Kubernetes bearer token","state":"PUBLIC","updated":"2026-04-09T19:50:53.750Z","owner":"tomcat"},{"_id":"69ca35b05913bc1be1e890ac","ID":"CVE-2026-34500","title":"OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled","state":"PUBLIC","updated":"2026-04-09T19:51:26.249Z","owner":"tomcat"},{"_id":"69ca794a5913bc1be1e89147","ID":"CVE-2026-34501","title":"Heap buffer overflow in APR redis client","state":"PUBLIC","updated":"2026-08-06T14:31:46.904Z","owner":"apr"},{"_id":"69ca79965913bc1be1e89159","ID":"CVE-2026-34502","title":"Heap buffer overflow in APR memcached client","state":"PUBLIC","updated":"2026-08-06T14:31:06.399Z","owner":"apr"},{"_id":"69ca9fa75913bc1be1e89201","ID":"CVE-2026-34538","title":"Authorization bypass in DagRun wait endpoint (XCom exposure)","state":"PUBLIC","updated":"2026-04-09T09:09:19.260Z","owner":"airflow"},{"_id":"69cb78e05913bc1be1e892d6","ID":"CVE-2026-34884","title":"SSRF via set_skywalking_url Tool and GraphQL Expression Injection in MCP Server","state":"PUBLIC","updated":"2026-08-18T03:21:11.514Z","owner":"skywalking"},{"_id":"69cbbc585913bc1be1e89303","ID":"CVE-2026-34905","title":"Unlisted Questions Accessible via Direct API Access","state":"PUBLIC","updated":"2026-06-09T07:35:55.677Z","owner":"answer"},{"_id":"69ccef6d5913bc1be1e8946f","ID":"CVE-2026-35086","title":"Authenticated Remote Code Execution via Unsafe Template Expansion in email services","state":"PUBLIC","updated":"2026-05-19T09:36:05.258Z","owner":"ofbiz"},{"_id":"69cd4c3b5913bc1be1e89522","ID":"CVE-2026-35152","title":"SQL injection in runreports endpoint","state":"PUBLIC","updated":"2026-08-05T12:05:58.976Z","owner":"fineract"},{"_id":"69cd664d5913bc1be1e895b7","ID":"CVE-2026-35194","title":"Remote code execution via SQL injection in code generation","state":"PUBLIC","updated":"2026-05-15T15:27:25.824Z","owner":"flink"},{"_id":"69ce35205913bc1be1e89607","ID":"CVE-2026-35337","title":"RCE through Unsafe Deserialization via Kerberos TGT Credential Handling","state":"PUBLIC","updated":"2026-04-13T09:11:04.526Z","owner":"storm"},{"_id":"69cf9fae5913bc1be1e8977b","ID":"CVE-2026-35554","title":"Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition","state":"PUBLIC","updated":"2026-04-07T13:07:01.788Z","owner":"kafka"},{"_id":"69cfc4a45913bc1be1e898c4","ID":"CVE-2026-35563","title":"LDAP client implementation does not verify if the server certificate matches the intended LDAP hostname","state":"PUBLIC","updated":"2026-06-01T07:38:34.650Z","owner":"directory"},{"_id":"69cfd9445913bc1be1e8990d","ID":"CVE-2026-35565","title":"Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Storm UI","state":"PUBLIC","updated":"2026-04-13T09:10:15.976Z","owner":"storm"},{"_id":"69d382115913bc1be1e899aa","ID":"CVE-2026-38743","title":"Dags endpoint might provide access to otherwise inaccessible entities","state":"PUBLIC","updated":"2026-04-24T12:36:37.917Z","owner":"airflow"},{"_id":"69d3ac6d5913bc1be1e899d4","ID":"CVE-2026-39304","title":"Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOM","state":"PUBLIC","updated":"2026-04-10T10:54:02.870Z","owner":"activemq"},{"_id":"69d52f015913bc1be1e89d7b","ID":"CVE-2026-39816","title":"Missing Execute Code Required Permission on TinkerpopClientService","state":"PUBLIC","updated":"2026-05-08T13:38:11.640Z","owner":"nifi"},{"_id":"69d5bead5913bc1be1e89eee","ID":"CVE-2026-39998","title":"Identity Injection via forward-auth Plugin Missing Header Cleanup","state":"PUBLIC","updated":"2026-06-19T13:05:07.084Z","owner":"apisix"},{"_id":"69d5c3ec5913bc1be1e89f1a","ID":"CVE-2026-39999","title":"JWT Algorithm Confusion allows authentication bypass","state":"PUBLIC","updated":"2026-06-19T13:07:45.459Z","owner":"apisix"},{"_id":"69d614915913bc1be1e8a032","ID":"CVE-2026-40005","title":"Path Traversal in Pipe File Transfer Receiver","state":"PUBLIC","updated":"2026-07-10T07:09:44.506Z","owner":"iotdb"},{"_id":"69d614d75913bc1be1e8a03c","ID":"CVE-2026-40006","title":"Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver","state":"PUBLIC","updated":"2026-07-10T07:10:51.432Z","owner":"iotdb"},{"_id":"69d614f85913bc1be1e8a042","ID":"CVE-2026-40007","title":"Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError","state":"PUBLIC","updated":"2026-07-10T07:12:27.092Z","owner":"iotdb"},{"_id":"69d615105913bc1be1e8a048","ID":"CVE-2026-40008","title":"Arbitrary Class Instantiation via Pipe Transfer RPC","state":"PUBLIC","updated":"2026-07-10T07:13:24.628Z","owner":"iotdb"},{"_id":"69d61a7e5913bc1be1e8a09e","ID":"CVE-2026-40009","title":"Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor","state":"PUBLIC","updated":"2026-07-10T07:15:02.989Z","owner":"iotdb"},{"_id":"69d626745913bc1be1e8a0f2","ID":"CVE-2026-40010","title":"possible session fixation using AuthenticatedWebSession","state":"PUBLIC","updated":"2026-05-06T08:34:37.475Z","owner":"wicket"},{"_id":"69d627ff5913bc1be1e8a13c","ID":"CVE-2026-40021","title":"Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters","state":"PUBLIC","updated":"2026-04-10T15:44:08.554Z","owner":"logging"},{"_id":"69d628ac5913bc1be1e8a142","ID":"CVE-2026-40022","title":"Authentication Bypass on Non-Root Context Paths in camel main runtime","state":"PUBLIC","updated":"2026-04-27T09:40:26.613Z","owner":"camel"},{"_id":"69d632cf5913bc1be1e8a205","ID":"CVE-2026-40023","title":"Silent log event loss in XMLLayout due to unescaped XML 1.0 forbidden characters","state":"PUBLIC","updated":"2026-04-10T15:45:43.003Z","owner":"logging"},{"_id":"69d672915913bc1be1e8a496","ID":"CVE-2026-40046","title":"Missing fix for CVE-2025-66168: MQTT control packet remaining length field is not properly validated","state":"PUBLIC","updated":"2026-04-09T15:58:31.486Z","owner":"activemq"},{"_id":"69d680225913bc1be1e8a5d8","ID":"CVE-2026-40047","title":"Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer","state":"PUBLIC","updated":"2026-07-05T12:07:12.860Z","owner":"camel"},{"_id":"69d684fd5913bc1be1e8a5df","ID":"CVE-2026-40048","title":"Unsafe Deserialization from FileBasedKeyLifecycleManager","state":"PUBLIC","updated":"2026-04-27T07:53:48.505Z","owner":"camel"},{"_id":"69dc9c2e5913bc1be1e8b375","ID":"CVE-2026-40452","title":"Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users","state":"PUBLIC","updated":"2026-07-10T07:16:03.259Z","owner":"iotdb"},{"_id":"69dca9065913bc1be1e8b403","ID":"CVE-2026-40453","title":"Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, camel-coap, camel-google-pubsub) allows case-variant header injection","state":"PUBLIC","updated":"2026-04-27T08:23:18.588Z","owner":"camel"},{"_id":"69dcb1195913bc1be1e8b41b","ID":"CVE-2026-40454","title":"Out-of-bounds reads in C++ client TsBlock deserializer crash client process on malformed server data","state":"PUBLIC","updated":"2026-07-10T07:18:58.462Z","owner":"iotdb"},{"_id":"69dcf1e25913bc1be1e8b60a","ID":"CVE-2026-40466","title":"Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URI","state":"PUBLIC","updated":"2026-04-24T10:15:42.912Z","owner":"activemq"},{"_id":"69dd13845913bc1be1e8b744","ID":"CVE-2026-40473","title":"Unsafe Deserialization in MinaConverter.toObjectInput() via TCP/UDP","state":"PUBLIC","updated":"2026-04-27T07:51:56.460Z","owner":"camel"},{"_id":"69de04b25913bc1be1e8b843","ID":"CVE-2026-40542","title":"SCRAM-SHA-256 mutual authentication bypass may cause the client to accept authentication without proper mutual authentication verification","state":"PUBLIC","updated":"2026-04-22T07:07:19.055Z","owner":"httpcomponents"},{"_id":"69de23135913bc1be1e8b8b5","ID":"CVE-2026-40557","title":"Disabling TLS verification for Prometheus Reporter also disables it for all other connections","state":"PUBLIC","updated":"2026-04-27T13:12:09.640Z","owner":"storm"},{"_id":"69de2d835913bc1be1e8b939","ID":"CVE-2026-40563","title":"Script injection allows access to unintended data","state":"PUBLIC","updated":"2026-05-04T15:17:30.858Z","owner":"atlas"},{"_id":"69de3a205913bc1be1e8b9ef","ID":"CVE-2026-40564","title":"Server-Side Request Forgery and local file access in Kubernetes Operator","state":"PUBLIC","updated":"2026-05-26T14:43:13.154Z","owner":"flink"},{"_id":"69de77855913bc1be1e8c522","ID":"CVE-2026-40682","title":"XXE via Dictionary Parsing in DictionaryEntryPersistor","state":"PUBLIC","updated":"2026-06-30T04:40:05.111Z","owner":"opennlp"},{"_id":"69dee54a5913bc1be1e8c69e","ID":"CVE-2026-40690","title":"Assets graph view bypasses DAG level access control displaying unrelated topologies and all DAGs names to unauthorized users","state":"PUBLIC","updated":"2026-04-24T12:35:28.702Z","owner":"airflow"},{"_id":"69df81a95913bc1be1e8c771","ID":"CVE-2026-40858","title":"Camel-Infinispan: Unsafe Deserialization in Remote Aggregation Repository","state":"PUBLIC","updated":"2026-04-27T09:38:53.977Z","owner":"camel"},{"_id":"69df82885913bc1be1e8c777","ID":"CVE-2026-40859","title":"Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled","state":"PUBLIC","updated":"2026-07-05T12:06:34.457Z","owner":"camel"},{"_id":"69df88375913bc1be1e8c7cd","ID":"CVE-2026-40860","title":"Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, camel-sjms2 and camel-amqp","state":"PUBLIC","updated":"2026-04-27T08:03:17.126Z","owner":"camel"},{"_id":"69df99805913bc1be1e8c807","ID":"CVE-2026-40861","title":"Arbitrary File Read via Log Symlink following in FileTaskHandler","state":"PUBLIC","updated":"2026-06-01T07:55:36.142Z","owner":"airflow"},{"_id":"69dfc84b5913bc1be1e8c836","ID":"CVE-2026-40914","title":"Address routing-type can be updated by STOMP protocol user without the createAddress permission","state":"PUBLIC","updated":"2026-05-28T12:28:55.897Z","owner":"artemis"},{"_id":"69dfdb8d5913bc1be1e8c8da","ID":"CVE-2026-40920","title":"Privilege Escalation via URL Parameter","state":"PUBLIC","updated":"2026-08-10T10:25:48.184Z","owner":"ranger"},{"_id":"69e0299a00502a9953e05208","ID":"CVE-2026-40948","title":"OAuth Login CSRF — Missing State Parameter in Keycloak Auth Manager","state":"PUBLIC","updated":"2026-04-19T23:44:07.936Z","owner":"airflow"},{"_id":"69e035a700502a9953e05223","ID":"CVE-2026-40961","title":"Open Redirect Bypass Vulnerability","state":"PUBLIC","updated":"2026-06-01T07:55:03.222Z","owner":"airflow"},{"_id":"69e041ea00502a9953e05225","ID":"CVE-2026-40963","title":"DAG authorization bypass on /ui/structure/structure_data","state":"PUBLIC","updated":"2026-06-01T07:54:32.443Z","owner":"airflow"},{"_id":"69e0478000502a9953e0523c","ID":"CVE-2026-41014","title":"per-DAG RBAC bypass on /ui/partitioned_dag_runs endpoints","state":"PUBLIC","updated":"2026-06-01T07:53:50.879Z","owner":"airflow"},{"_id":"69e04bc200502a9953e052d6","ID":"CVE-2026-41016","title":"No certificate validation on SMTP STARTTLS connections (SMTP provider — split from #265)","state":"PUBLIC","updated":"2026-05-29T08:45:19.890Z","owner":"airflow"},{"_id":"69e04ff600502a9953e052e0","ID":"CVE-2026-41017","title":"JWT cookie missing Secure flag in JWTRefreshMiddleware behind HTTPS-terminating proxy","state":"PUBLIC","updated":"2026-06-01T07:52:32.340Z","owner":"airflow"},{"_id":"69e052e500502a9953e052ee","ID":"CVE-2026-41018","title":"Elasticsearch task-log handler leaks credentials embedded in the host URL","state":"PUBLIC","updated":"2026-05-10T20:38:57.776Z","owner":"airflow"},{"_id":"69e0a13900502a9953e0537e","ID":"CVE-2026-41041","title":"URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended API endpoints.","state":"PUBLIC","updated":"2026-07-13T09:08:49.763Z","owner":"gravitino"},{"_id":"69e0c5d600502a9953e05411","ID":"CVE-2026-41042","title":"Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter","state":"PUBLIC","updated":"2026-07-08T11:38:53.337Z","owner":"gravitino"},{"_id":"69e0dab3389333d5037dab4c","ID":"CVE-2026-41043","title":"ActiveMQ Web Console -  XSS vulnerability when browsing queues","state":"PUBLIC","updated":"2026-06-26T22:01:21.682Z","owner":"activemq"},{"_id":"69e0ddf9389333d5037dab6b","ID":"CVE-2026-41044","title":"Authenticated user can perform RCE via DestinationView MBean exposed by Jolokia","state":"PUBLIC","updated":"2026-04-24T10:16:51.999Z","owner":"activemq"},{"_id":"69e11ae3389333d5037dad11","ID":"CVE-2026-41081","title":"Anonymous principal assigned on TLS client certificate verification failure","state":"PUBLIC","updated":"2026-04-27T13:10:44.288Z","owner":"storm"},{"_id":"69e1266d389333d5037dade6","ID":"CVE-2026-41084","title":"API authorization bypass: bulk TaskInstances allows cross-DAG mutation","state":"PUBLIC","updated":"2026-06-01T07:51:55.264Z","owner":"airflow"},{"_id":"69e1a44e389333d5037daf14","ID":"CVE-2026-41115","title":"Improper Authorization in CONSUMER_GROUP_DESCRIBE API","state":"PUBLIC","updated":"2026-06-02T08:56:41.838Z","owner":"kafka"},{"_id":"69e465842b5ce8e146762d6d","ID":"CVE-2026-41280","title":"Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects","state":"PUBLIC","updated":"2026-06-17T06:32:49.794Z","owner":"dolphinscheduler"},{"_id":"69e5d5708b587a02e158e123","ID":"CVE-2026-41284","title":"Unbounded read in WebDAV LOCK and PROPFIND handling","state":"PUBLIC","updated":"2026-05-12T15:15:06.069Z","owner":"tomcat"},{"_id":"69e5ff548b587a02e158e14c","ID":"CVE-2026-41293","title":"HTTP/2 request headers not validated","state":"PUBLIC","updated":"2026-05-12T15:19:39.777Z","owner":"tomcat"},{"_id":"69e640968b587a02e158e2f5","ID":"CVE-2026-41409","title":"CWE-502 Deserialization of Untrusted Data","state":"PUBLIC","updated":"2026-04-27T09:20:11.275Z","owner":"mina"},{"_id":"69e77cf88b587a02e158e3ef","ID":"CVE-2026-41566","title":"Improper permission for the APPLYBATCH command","state":"PUBLIC","updated":"2026-06-25T08:04:24.570Z","owner":"kvrocks"},{"_id":"69e7ebfe8b587a02e158e455","ID":"CVE-2026-41602","title":"Go TFramedTransport uint32 overflow","state":"PUBLIC","updated":"2026-04-28T09:19:05.731Z","owner":"thrift"},{"_id":"69e7eccc8b587a02e158e45d","ID":"CVE-2026-41604","title":"Swift Range crash in skip()","state":"PUBLIC","updated":"2026-04-28T09:20:12.306Z","owner":"thrift"},{"_id":"69e7ecdc8b587a02e158e45f","ID":"CVE-2026-41605","title":"Swift Compact Protocol integer overflow","state":"PUBLIC","updated":"2026-04-28T09:20:43.166Z","owner":"thrift"},{"_id":"69e7ecfe8b587a02e158e461","ID":"CVE-2026-41606","title":"c_glib dispatch stack overflow","state":"PUBLIC","updated":"2026-04-28T09:21:09.783Z","owner":"thrift"},{"_id":"69e7f5c78b587a02e158e463","ID":"CVE-2026-41607","title":"C++ JSON OOB read","state":"PUBLIC","updated":"2026-04-28T09:21:46.727Z","owner":"thrift"},{"_id":"69e7f6a88b587a02e158e465","ID":"CVE-2026-41608","title":"Unbounded Zlib Decompression in Python THeaderTransport","state":"PUBLIC","updated":"2026-08-01T15:15:08.921Z","owner":"thrift"},{"_id":"69e7f7ae8b587a02e158e46b","ID":"CVE-2026-41635","title":"AbstractIoBuffer.resolveClass() null-clazz Branch Skips acceptMatchers Filter — Full Object Deserialization RCE","state":"PUBLIC","updated":"2026-04-27T09:15:40.308Z","owner":"mina"},{"_id":"69e7f8e68b587a02e158e471","ID":"CVE-2026-41636","title":"Node.js skip() recursion","state":"PUBLIC","updated":"2026-07-15T20:56:45.279Z","owner":"thrift"},{"_id":"69e8909d8b587a02e158e539","ID":"CVE-2026-41873","title":"Admin account takeover via request smuggling","state":"PUBLIC","updated":"2026-04-28T15:18:49.753Z","owner":"ponymail"},{"_id":"69e8f66a8b587a02e158e6ca","ID":"CVE-2026-41919","title":"Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Construction","state":"PUBLIC","updated":"2026-05-19T09:37:00.903Z","owner":"ofbiz"},{"_id":"69e913a08b587a02e158e730","ID":"CVE-2026-41920","title":"SNI to Host header matching policy is not properly enforced","state":"PUBLIC","updated":"2026-07-29T07:17:57.749Z","owner":"trafficserver"},{"_id":"69ea2ae58b587a02e158e8c6","ID":"CVE-2026-42027","title":"Arbitrary Class Instantiation via Model Manifest in ExtensionLoader","state":"PUBLIC","updated":"2026-06-30T07:17:51.901Z","owner":"opennlp"},{"_id":"69ed0cca8b587a02e158ee61","ID":"CVE-2026-42252","title":"BashOperator Jinja2 injection via dag_run.conf — low-privilege user pattern","state":"PUBLIC","updated":"2026-06-01T07:51:17.651Z","owner":"airflow"},{"_id":"69ed1a748b587a02e158ee73","ID":"CVE-2026-42253","title":"HTTP Response Header Injection via JMS Message Properties","state":"PUBLIC","updated":"2026-06-03T09:26:01.816Z","owner":"activemq"},{"_id":"69ee24e18b587a02e158efb6","ID":"CVE-2026-42357","title":"Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.","state":"PUBLIC","updated":"2026-06-17T06:31:34.851Z","owner":"dolphinscheduler"},{"_id":"69ee47c98b587a02e158efba","ID":"CVE-2026-42358","title":"Variable masker depth-limit bypass returns cleartext nested secrets","state":"PUBLIC","updated":"2026-06-01T07:49:56.426Z","owner":"airflow"},{"_id":"69ee69948b587a02e158f0d7","ID":"CVE-2026-42359","title":"Authenticated RCE via XCom PATCH endpoint — XComUpdateBody missing FORBIDDEN_XCOM_KEYS validator","state":"PUBLIC","updated":"2026-06-01T15:13:25.919Z","owner":"airflow"},{"_id":"69ee6c0f8b587a02e158f0d9","ID":"CVE-2026-42360","title":"Rendered template truncation bypasses nested sensitive-key masking","state":"PUBLIC","updated":"2026-06-01T07:50:36.896Z","owner":"airflow"},{"_id":"69ef3a018b587a02e158f258","ID":"CVE-2026-42402","title":"Policy Normalization Unbounded Resource Allocation DoS","state":"PUBLIC","updated":"2026-05-01T09:35:22.670Z","owner":"ws"},{"_id":"69ef3b658b587a02e158f290","ID":"CVE-2026-42403","title":"Circular Policy Reference Infinite Loop","state":"PUBLIC","updated":"2026-05-01T09:36:06.796Z","owner":"ws"},{"_id":"69ef3bd38b587a02e158f2aa","ID":"CVE-2026-42404","title":"Unrestricted HTTP Redirect Following in Policy References","state":"PUBLIC","updated":"2026-05-01T09:46:48.474Z","owner":"ws"},{"_id":"69ef59e28b587a02e158f312","ID":"CVE-2026-42440","title":"OOM DoS via Unbounded Array Allocation in AbstractModelReader","state":"PUBLIC","updated":"2026-06-30T04:39:58.456Z","owner":"opennlp"},{"_id":"69efdf71db3191058d4eaf13","ID":"CVE-2026-42498","title":"WebSocket authentication header exposure","state":"PUBLIC","updated":"2026-05-12T15:18:02.449Z","owner":"tomcat"},{"_id":"69f01901db3191058d4eb1b1","ID":"CVE-2026-42509","title":"crafted strings can break out of the JavaScript sequence","state":"PUBLIC","updated":"2026-05-06T08:34:07.745Z","owner":"wicket"},{"_id":"69f08bbadb3191058d4eb261","ID":"CVE-2026-42526","title":"Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends","state":"PUBLIC","updated":"2026-05-20T01:48:06.454Z","owner":"airflow"},{"_id":"69f09f0adb3191058d4eb267","ID":"CVE-2026-42527","title":"Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure","state":"PUBLIC","updated":"2026-07-05T12:05:31.946Z","owner":"camel"},{"_id":"69f0d7fadb3191058d4eb2a2","ID":"CVE-2026-42535","title":"mod_dav_fs protected directory access","state":"PUBLIC","updated":"2026-06-08T15:14:54.481Z","owner":"httpd"},{"_id":"69f0db01db3191058d4eb2ae","ID":"CVE-2026-42536","title":"mod_xml2enc heap overflow","state":"PUBLIC","updated":"2026-06-08T15:23:49.951Z","owner":"httpd"},{"_id":"69f0dd12db3191058d4eb2b8","ID":"CVE-2026-42537","title":"Remote Code Execution via JDBC URL Injection","state":"PUBLIC","updated":"2026-08-10T10:24:33.165Z","owner":"ranger"},{"_id":"69f11fbcdb3191058d4eb321","ID":"CVE-2026-42588","title":"Remote Code Execution via Jolokia addNetworkConnector","state":"PUBLIC","updated":"2026-06-01T07:23:15.963Z","owner":"activemq"},{"_id":"69f20845db3191058d4eb3eb","ID":"CVE-2026-42778","title":"CWE-502 Deserialization of Untrusted Data (take 2)","state":"PUBLIC","updated":"2026-05-01T10:01:08.442Z","owner":"mina"},{"_id":"69f20889db3191058d4eb3f8","ID":"CVE-2026-42779","title":"AbstractIoBuffer.resolveClass() null-clazz Branch Skips acceptMatchers Filter — Full Object Deserialization RCE (take 2)","state":"PUBLIC","updated":"2026-05-01T10:00:40.665Z","owner":"mina"},{"_id":"69f21177db3191058d4eb44e","ID":"CVE-2026-42782","title":"Post-auth RCE via Groovy static","state":"PUBLIC","updated":"2026-05-25T14:59:04.113Z","owner":"syncope"},{"_id":"69f2f25adb3191058d4eb54b","ID":"CVE-2026-42797","title":"JexlContextBuilder Information Disclosure","state":"PUBLIC","updated":"2026-05-25T15:01:00.581Z","owner":"syncope"},{"_id":"69f35f58db3191058d4eb5fc","ID":"CVE-2026-42809","title":"staged table creation could vend storage credentials for unvalidated locations","state":"PUBLIC","updated":"2026-05-04T16:36:14.167Z","owner":"polaris"},{"_id":"69f365acdb3191058d4eb634","ID":"CVE-2026-42810","title":"could broaden vended S3 credentials through wildcard-bearing namespace or table names","state":"PUBLIC","updated":"2026-05-04T16:48:47.000Z","owner":"polaris"},{"_id":"69f36777db3191058d4eb659","ID":"CVE-2026-42811","title":"could broaden vended GCS credentials through unescaped identifier content in access-boundary CEL conditions","state":"PUBLIC","updated":"2026-05-04T16:26:53.369Z","owner":"polaris"},{"_id":"69f36907db3191058d4eb675","ID":"CVE-2026-42812","title":"write.metadata.path changes could bypass location validation and broaden delegated storage access","state":"PUBLIC","updated":"2026-05-04T16:28:09.922Z","owner":"polaris"},{"_id":"69f4d28adb3191058d4eb8e9","ID":"CVE-2026-43512","title":"Digest authenticator will authenticate any unknown user","state":"PUBLIC","updated":"2026-05-12T15:24:13.584Z","owner":"tomcat"},{"_id":"69f4d2f0db3191058d4eb8ee","ID":"CVE-2026-43513","title":"LockOutRealm treats user names as case-sensitive","state":"PUBLIC","updated":"2026-05-12T15:26:30.429Z","owner":"tomcat"},{"_id":"69f4d329db3191058d4eb8f7","ID":"CVE-2026-43514","title":"AJP secret compared in non-constant time","state":"PUBLIC","updated":"2026-05-12T15:32:17.251Z","owner":"tomcat"},{"_id":"69f4d3a1db3191058d4eb8fc","ID":"CVE-2026-43515","title":"Security constraints not correctly applied","state":"PUBLIC","updated":"2026-06-04T09:57:52.473Z","owner":"tomcat"},{"_id":"69f4f343db3191058d4eb990","ID":"CVE-2026-43646","title":"crafted URLs can bypass PackageResourceGuard","state":"PUBLIC","updated":"2026-05-06T08:31:55.175Z","owner":"wicket"},{"_id":"69f5bc71db3191058d4eba40","ID":"CVE-2026-43825","title":"Unsafe Java Deserialization in SvmDoccatModel","state":"PUBLIC","updated":"2026-07-06T15:41:58.595Z","owner":"opennlp"},{"_id":"69f606f3db3191058d4ebaa7","ID":"CVE-2026-43826","title":"OpenSearch task-log handler leaks credentials embedded in the host URL","state":"PUBLIC","updated":"2026-05-10T20:27:25.758Z","owner":"airflow"},{"_id":"69f67a0bdb3191058d4ebbb7","ID":"CVE-2026-43827","title":"Session fixation: new session is not created after login by default","state":"PUBLIC","updated":"2026-05-25T20:19:09.384Z","owner":"shiro"},{"_id":"69f7a147db3191058d4ebeb1","ID":"CVE-2026-43828","title":"Shiro's native session and rememberMe cookies do not have secure flag set by default","state":"PUBLIC","updated":"2026-05-25T20:19:30.172Z","owner":"shiro"},{"_id":"69f8854cdb3191058d4ec071","ID":"CVE-2026-43865","title":"Camel-Hazelcast: Unsafe Java deserialization in default-configured managed Hazelcast instances enables remote code execution","state":"PUBLIC","updated":"2026-07-05T12:04:39.086Z","owner":"camel"},{"_id":"69f88686db3191058d4ec073","ID":"CVE-2026-43866","title":"Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder","state":"PUBLIC","updated":"2026-07-06T07:24:17.611Z","owner":"camel"},{"_id":"69f8871cdb3191058d4ec0a3","ID":"CVE-2026-43867","title":"Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter","state":"PUBLIC","updated":"2026-07-06T08:15:07.227Z","owner":"camel"},{"_id":"69f8a8ce58f8e272fea72ffe","ID":"CVE-2026-43868","title":"Rust implementation vulnerable to CVE-2020-13949 pattern","state":"PUBLIC","updated":"2026-05-05T07:49:46.378Z","owner":"thrift"},{"_id":"69f8abb458f8e272fea730b8","ID":"CVE-2026-43869","title":"TSSLTransportFactory.java hostname verification","state":"PUBLIC","updated":"2026-08-01T15:15:50.815Z","owner":"thrift"},{"_id":"69f8ac2d58f8e272fea730ba","ID":"CVE-2026-43870","title":"Node.js web_server.js multi-vulnerability","state":"PUBLIC","updated":"2026-08-01T15:14:33.689Z","owner":"thrift"},{"_id":"69f8ace758f8e272fea730bc","ID":"CVE-2026-43871","title":"TCompactProtocol varint byte-count limit","state":"PUBLIC","updated":"2026-07-27T10:56:06.868Z","owner":"thrift"},{"_id":"69f8d44058f8e272fea732fd","ID":"CVE-2026-43951","title":"OOB Read in `merge_response_headers` can cause crash","state":"PUBLIC","updated":"2026-06-08T15:16:17.975Z","owner":"httpd"},{"_id":"69f8f9b358f8e272fea733fe","ID":"CVE-2026-43975","title":"Possible malicious path traversal in FolderUploadsFileManager","state":"PUBLIC","updated":"2026-05-06T08:28:37.545Z","owner":"wicket"},{"_id":"69f9854358f8e272fea735b6","ID":"CVE-2026-44046","title":"wolf-rbac plugin Identity Spoofing","state":"PUBLIC","updated":"2026-06-19T13:08:47.282Z","owner":"apisix"},{"_id":"69f9a32f58f8e272fea73602","ID":"CVE-2026-44087","title":"Openid-connect plugin Identity Header Spoofing","state":"PUBLIC","updated":"2026-06-19T13:11:08.855Z","owner":"apisix"},{"_id":"69f9d5dd58f8e272fea736a5","ID":"CVE-2026-44119","title":"escalation of privilege through expressions in .htaccess in multiple modules","state":"PUBLIC","updated":"2026-06-08T15:17:34.711Z","owner":"httpd"},{"_id":"69fa01c258f8e272fea737b5","ID":"CVE-2026-44185","title":"Stack Buffer Over-Read in mod_ssl OCSP `send_request`","state":"PUBLIC","updated":"2026-06-08T15:22:16.097Z","owner":"httpd"},{"_id":"69fa061058f8e272fea737ee","ID":"CVE-2026-44186","title":"Loop in `proxy_ftp_handler` in mod_proxy_ftp","state":"PUBLIC","updated":"2026-06-08T15:11:17.549Z","owner":"httpd"},{"_id":"69fb4f7058f8e272fea73b93","ID":"CVE-2026-44416","title":"Remote Code Execution via Arbitrary Class Instantiation","state":"PUBLIC","updated":"2026-08-10T10:23:49.093Z","owner":"ranger"},{"_id":"69fb504858f8e272fea73ba5","ID":"CVE-2026-44417","title":"Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE)","state":"PUBLIC","updated":"2026-05-22T12:17:23.985Z","owner":"cxf"},{"_id":"69fbf17158f8e272fea73c59","ID":"CVE-2026-44598","title":"Open redirect and SSRF (requires valid credentials)","state":"PUBLIC","updated":"2026-05-25T20:19:50.656Z","owner":"shiro"},{"_id":"69fc42d758f8e272fea73cc2","ID":"CVE-2026-44613","title":"Cross-site request forgery in REST and WebSocket request handling","state":"PUBLIC","updated":"2026-07-30T15:19:35.612Z","owner":"zeppelin"},{"_id":"69fc437058f8e272fea73cc6","ID":"CVE-2026-44615","title":"Path traversal in NotebookRepo note and folder path composition","state":"PUBLIC","updated":"2026-07-30T15:35:21.810Z","owner":"zeppelin"},{"_id":"69fc440058f8e272fea73cc8","ID":"CVE-2026-44616","title":"LDAP injection in ActiveDirectoryGroupRealm filter construction","state":"PUBLIC","updated":"2026-08-06T10:08:34.789Z","owner":"zeppelin"},{"_id":"69fc443c58f8e272fea73cca","ID":"CVE-2026-44617","title":"LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867","state":"PUBLIC","updated":"2026-07-30T15:22:27.856Z","owner":"zeppelin"},{"_id":"69fc590f58f8e272fea73ce8","ID":"CVE-2026-44618","title":"XXE vulnerability in WS-Transfer functionality","state":"PUBLIC","updated":"2026-05-22T12:17:12.799Z","owner":"cxf"},{"_id":"69fc657b58f8e272fea73d28","ID":"CVE-2026-44630","title":"RPC service denial of service via unchecked Thrift string length","state":"PUBLIC","updated":"2026-08-10T09:25:10.202Z","owner":"iotdb"},{"_id":"69fc87e658f8e272fea73e3b","ID":"CVE-2026-44631","title":"Heap Underflow in `ap_regname` via Signed Char Overflow","state":"PUBLIC","updated":"2026-06-08T15:19:26.351Z","owner":"httpd"},{"_id":"69fcf60f58f8e272fea73f19","ID":"CVE-2026-44825","title":"Enabling BasicAuth using bin/solr CLI configures additional insecure users","state":"PUBLIC","updated":"2026-06-01T08:02:13.681Z","owner":"solr"},{"_id":"69fd5bc258f8e272fea73fa2","ID":"CVE-2026-44911","title":"Incorrect Authorization for Configuration Verification Requests","state":"PUBLIC","updated":"2026-06-22T07:37:09.411Z","owner":"nifi"},{"_id":"69fd636758f8e272fea73fca","ID":"CVE-2026-44913","title":"Improper Escaping of Table Names in CaptureChangeMySQL","state":"PUBLIC","updated":"2026-06-22T07:36:39.632Z","owner":"nifi"},{"_id":"69fd66c858f8e272fea73fde","ID":"CVE-2026-44914","title":"Missing Authorization of Restricted Permissions when Replacing Flow Contents","state":"PUBLIC","updated":"2026-06-22T07:38:00.013Z","owner":"nifi"},{"_id":"69fd778858f8e272fea73ff6","ID":"CVE-2026-44915","title":"Cas-auth plugin open redirect via unsanitized cookie value","state":"PUBLIC","updated":"2026-06-19T13:12:20.566Z","owner":"apisix"},{"_id":"69fdbd7458f8e272fea7411c","ID":"CVE-2026-44930","title":"LDAP Injection vulnerability in XKMS LDAP Repository","state":"PUBLIC","updated":"2026-05-22T12:16:45.335Z","owner":"cxf"},{"_id":"69fe41d358f8e272fea745b4","ID":"CVE-2026-45112","title":"Unbounded Read Leading to Denial of Service","state":"PUBLIC","updated":"2026-07-27T10:57:25.527Z","owner":"thrift"},{"_id":"6a0046c658f8e272fea74630","ID":"CVE-2026-45187","title":"Improper Authorization in Scheduled Job Creation Allows Low-Privileged Users to Submit System Jobs","state":"PUBLIC","updated":"2026-05-19T09:39:30.906Z","owner":"ofbiz"},{"_id":"6a007b9d58f8e272fea74656","ID":"CVE-2026-45188","title":"Replication Fullsync Path Traversal via Unvalidated Filename Handling","state":"PUBLIC","updated":"2026-06-25T08:01:48.602Z","owner":"kvrocks"},{"_id":"6a00fc0058f8e272fea746f7","ID":"CVE-2026-45192","title":"Incomplete Redaction of Sensitive Fields in Connection Extra API Response","state":"PUBLIC","updated":"2026-06-01T06:51:50.457Z","owner":"airflow"},{"_id":"6a01d6a758f8e272fea7476d","ID":"CVE-2026-45205","title":"StackOverflowError for YAML input with cycles","state":"PUBLIC","updated":"2026-05-14T11:22:48.661Z","owner":"commons"},{"_id":"6a01ef7358f8e272fea747e2","ID":"CVE-2026-45249","title":"XSS in Lines series tooltip rendering","state":"PUBLIC","updated":"2026-05-25T17:40:58.037Z","owner":"echarts"},{"_id":"6a025ac458f8e272fea748e7","ID":"CVE-2026-45360","title":"Arbitrary import in custom deadline-reference deserialization","state":"PUBLIC","updated":"2026-06-01T07:48:10.959Z","owner":"airflow"},{"_id":"6a026d4358f8e272fea748e9","ID":"CVE-2026-45361","title":"SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)","state":"PUBLIC","updated":"2026-06-01T15:48:33.023Z","owner":"airflow"},{"_id":"6a02992158f8e272fea74929","ID":"CVE-2026-45426","title":"Log server JWT authorization bypass via Python lstrip() character stripping allows cross-Dag log access","state":"PUBLIC","updated":"2026-06-01T07:47:13.162Z","owner":"airflow"},{"_id":"6a0324a258f8e272fea749d3","ID":"CVE-2026-45434","title":"Authentication Bypass via Password-Change Logic Flaw Leading to RCE","state":"PUBLIC","updated":"2026-05-19T09:40:31.930Z","owner":"ofbiz"},{"_id":"6a0352da58f8e272fea74c12","ID":"CVE-2026-45505","title":"Jolokia `addNetworkConnector` Discovery Wrapper Bypass","state":"PUBLIC","updated":"2026-06-01T07:22:30.266Z","owner":"activemq"},{"_id":"6a042a5c58f8e272fea74c53","ID":"CVE-2026-45760","title":"Camel K Cross-Namespace Build Deputy Attack","state":"PUBLIC","updated":"2026-05-21T11:43:39.236Z","owner":"camel"},{"_id":"6a043aee58f8e272fea74c73","ID":"CVE-2026-45811","title":"Buffer overflow in socket HCI transport","state":"PUBLIC","updated":"2026-07-24T12:09:09.262Z","owner":"mynewt"},{"_id":"6a043cd758f8e272fea74c81","ID":"CVE-2026-45812","title":"OOB Read via sizeof(pointer) in Legacy Advertising Report Handler","state":"PUBLIC","updated":"2026-07-24T12:09:37.486Z","owner":"mynewt"},{"_id":"6a043e1358f8e272fea74c8b","ID":"CVE-2026-45813","title":"Incorrect data validation in BASS add/modify source operation","state":"PUBLIC","updated":"2026-07-24T12:10:10.910Z","owner":"mynewt"},{"_id":"6a0444ed58f8e272fea74cb7","ID":"CVE-2026-45815","title":"Remote reachable assertion in ATT Read Multiple Variable Response handler","state":"PUBLIC","updated":"2026-07-24T12:10:37.291Z","owner":"mynewt"},{"_id":"6a04475458f8e272fea74cc1","ID":"CVE-2026-45816","title":"NULL pointer dereference vulnerability in SMP LTK request","state":"PUBLIC","updated":"2026-07-24T12:11:08.240Z","owner":"mynewt"},{"_id":"6a05763658f8e272fea74dc4","ID":"CVE-2026-46452","title":"Mesh Proxy SAR reassembly unbounded append and unchecked failure","state":"PUBLIC","updated":"2026-07-24T12:11:41.257Z","owner":"mynewt"},{"_id":"6a05853358f8e272fea74e16","ID":"CVE-2026-46453","title":"Camel-Elasticsearch-Rest-Client: Exchange header constants without the Camel prefix bypass inbound HTTP header filtering, allowing untrusted clients to override the Elasticsearch query and operation","state":"PUBLIC","updated":"2026-07-05T12:03:20.579Z","owner":"camel"},{"_id":"6a058ba358f8e272fea74e50","ID":"CVE-2026-46454","title":"Camel-Cometd: Inbound Bayeux message headers are mapped into the Exchange without a HeaderFilterStrategy, allowing unauthenticated clients to inject Camel control headers","state":"PUBLIC","updated":"2026-07-05T12:02:45.108Z","owner":"camel"},{"_id":"6a058e0e58f8e272fea74e52","ID":"CVE-2026-46455","title":"Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be accepted","state":"PUBLIC","updated":"2026-07-05T12:02:14.819Z","owner":"camel"},{"_id":"6a058edf58f8e272fea74e54","ID":"CVE-2026-46456","title":"Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers","state":"PUBLIC","updated":"2026-07-05T12:01:36.500Z","owner":"camel"},{"_id":"6a05b5ea58f8e272fea74f18","ID":"CVE-2026-46457","title":"Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers","state":"PUBLIC","updated":"2026-07-05T12:00:52.558Z","owner":"camel"},{"_id":"6a06d0ce58f8e272fea75025","ID":"CVE-2026-46584","title":"The mail producer applied attacker-supplied message headers as JavaMail session properties, allowing an attacker to influence SMTP parameters","state":"PUBLIC","updated":"2026-07-06T08:02:36.402Z","owner":"camel"},{"_id":"6a06d14858f8e272fea75027","ID":"CVE-2026-46585","title":"The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search query","state":"PUBLIC","updated":"2026-07-06T08:03:14.855Z","owner":"camel"},{"_id":"6a06dd1858f8e272fea75037","ID":"CVE-2026-46586","title":"Improper Validation in traverseContent Service Enables Authenticated Groovy Code Execution","state":"PUBLIC","updated":"2026-05-19T09:41:46.590Z","owner":"ofbiz"},{"_id":"6a06dfd258f8e272fea75055","ID":"CVE-2026-46587","title":"Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input","state":"PUBLIC","updated":"2026-07-06T09:25:19.132Z","owner":"camel"},{"_id":"6a06e00a58f8e272fea7505f","ID":"CVE-2026-46588","title":"CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input","state":"PUBLIC","updated":"2026-07-06T09:25:34.812Z","owner":"camel"},{"_id":"6a071e4a58f8e272fea750bd","ID":"CVE-2026-46590","title":"Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation of CVE-2026-40048)","state":"PUBLIC","updated":"2026-07-05T11:58:05.374Z","owner":"camel"},{"_id":"6a071f4658f8e272fea750bf","ID":"CVE-2026-46591","title":"Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169)","state":"PUBLIC","updated":"2026-07-05T11:57:19.664Z","owner":"camel"},{"_id":"6a07205d58f8e272fea750c1","ID":"CVE-2026-46592","title":"Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation","state":"PUBLIC","updated":"2026-07-05T11:56:44.036Z","owner":"camel"},{"_id":"6a0763da58f8e272fea751ed","ID":"CVE-2026-46605","title":"Incomplete authorization during destination removal","state":"PUBLIC","updated":"2026-06-01T07:21:11.500Z","owner":"activemq"},{"_id":"6a07b25c58f8e272fea75288","ID":"CVE-2026-46718","title":"A user-controled model can load arbitrary classes, leading to code execution","state":"PUBLIC","updated":"2026-06-02T09:17:49.528Z","owner":"calcite"},{"_id":"6a089f5e58f8e272fea752d4","ID":"CVE-2026-46726","title":"The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers","state":"PUBLIC","updated":"2026-07-06T08:05:38.812Z","owner":"camel"},{"_id":"6a0adb2d58f8e272fea755d4","ID":"CVE-2026-46745","title":"LDAP Filter Injection in FAB Auth Manager _search_ldap reachable via /auth/token","state":"PUBLIC","updated":"2026-05-25T11:30:22.680Z","owner":"airflow"},{"_id":"6a0afcaa58f8e272fea755f0","ID":"CVE-2026-46751","title":"Does not remove the unsafe loadstring function from its Lua sandbox, allowing a user who can run EVAL scripts to load crafted, unvalidated bytecode that crashes the server process, resulting in a remote denial of service.","state":"PUBLIC","updated":"2026-06-25T08:00:59.029Z","owner":"kvrocks"},{"_id":"6a0b025358f8e272fea7561a","ID":"CVE-2026-46752","title":"Stack buffer overflow in Lua bit.tohex()","state":"PUBLIC","updated":"2026-06-25T08:00:16.837Z","owner":"kvrocks"},{"_id":"6a0b336558f8e272fea756ee","ID":"CVE-2026-46764","title":"Event Log detail endpoint bypasses DAG-scoped event log permission filter","state":"PUBLIC","updated":"2026-06-01T07:45:46.820Z","owner":"airflow"},{"_id":"6a0b441358f8e272fea7570e","ID":"CVE-2026-47065","title":"Critical Deserialization Allow-list Bypass via resolveProxyClass - ZDRES-232","state":"PUBLIC","updated":"2026-06-03T22:29:54.026Z","owner":"mina"},{"_id":"6a0c24eb58f8e272fea75b4c","ID":"CVE-2026-47323","title":"Camel-CXF Message Header Injection via Missing Inbound Filtering","state":"PUBLIC","updated":"2026-05-19T12:25:47.873Z","owner":"camel"},{"_id":"6a0c49fa58f8e272fea75f81","ID":"CVE-2026-47339","title":"authz-casdoor incorrect session sharing","state":"PUBLIC","updated":"2026-06-19T13:10:09.663Z","owner":"apisix"},{"_id":"6a0c4acd58f8e272fea75f8b","ID":"CVE-2026-47340","title":"An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.","state":"PUBLIC","updated":"2026-06-17T01:44:26.990Z","owner":"dolphinscheduler"},{"_id":"6a0c4e1758f8e272fea75fa9","ID":"CVE-2026-47341","title":"Session replay issue in hmac-auth","state":"PUBLIC","updated":"2026-06-19T13:17:16.260Z","owner":"apisix"},{"_id":"6a0c549758f8e272fea76033","ID":"CVE-2026-47342","title":"Privilege Escalation via updateOrRemove Authorization Bypass","state":"PUBLIC","updated":"2026-06-10T22:29:05.548Z","owner":"ofbiz"},{"_id":"6a0c6f1658f8e272fea76113","ID":"CVE-2026-47359","title":"OS Command Injection due to unsanitized mount command","state":"PUBLIC","updated":"2026-08-21T08:30:06.507Z","owner":"cloudstack"},{"_id":"6a0cbe9758f8e272fea7621d","ID":"CVE-2026-47430","title":"iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews","state":"PUBLIC","updated":"2026-06-08T11:27:13.460Z","owner":"cordova"},{"_id":"6a0dc36558f8e272fea762d2","ID":"CVE-2026-47896","title":"Unauthenticated arbitrary file read on the Lucene.Net.Replicator replication server","state":"PUBLIC","updated":"2026-07-03T07:48:34.009Z","owner":"lucenenet"},{"_id":"6a0dc40058f8e272fea762dc","ID":"CVE-2026-47897","title":"Arbitrary file write from malicious server to Lucene.Net.Replicator client","state":"PUBLIC","updated":"2026-07-03T07:48:10.017Z","owner":"lucenenet"},{"_id":"6a0dc59b58f8e272fea762e0","ID":"CVE-2026-47898","title":"XXE vulnerability in Lucene.Net.Analysis.Common PatternParser","state":"PUBLIC","updated":"2026-07-03T07:47:36.852Z","owner":"lucenenet"},{"_id":"6a0e363058f8e272fea7637d","ID":"CVE-2026-48144","title":"c_glib TLS Client Missing Hostname Verification","state":"PUBLIC","updated":"2026-07-27T10:58:24.417Z","owner":"thrift"},{"_id":"6a0e398658f8e272fea76391","ID":"CVE-2026-48145","title":"C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass","state":"PUBLIC","updated":"2026-07-27T10:59:40.690Z","owner":"thrift"},{"_id":"6a0ec93d58f8e272fea7640d","ID":"CVE-2026-48203","title":"Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields","state":"PUBLIC","updated":"2026-07-05T11:55:11.904Z","owner":"camel"},{"_id":"6a0ec99958f8e272fea76410","ID":"CVE-2026-48204","title":"Camel-MongoDB-GridFS: The gridfs.* control headers used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to switch the GridFS operation - including destructive file deletion - in the default configuration","state":"PUBLIC","updated":"2026-07-05T11:54:33.844Z","owner":"camel"},{"_id":"6a0ec9cf58f8e272fea76412","ID":"CVE-2026-48205","title":"The dns.* and term Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to influence internal behaviour","state":"PUBLIC","updated":"2026-07-06T08:08:18.509Z","owner":"camel"},{"_id":"6a0eca1258f8e272fea76414","ID":"CVE-2026-48206","title":"A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to drive arbitrary JIRA issue operations using the endpoint's configured credentials","state":"PUBLIC","updated":"2026-07-06T08:09:07.730Z","owner":"camel"},{"_id":"6a0ef53858f8e272fea764c6","ID":"CVE-2026-48207","title":"PyFory ReduceSerializer Incomplete Policy Enforcement","state":"PUBLIC","updated":"2026-05-21T12:44:21.497Z","owner":"fory"},{"_id":"6a0f6d2f58f8e272fea7657b","ID":"CVE-2026-48586","title":"TZlibTransport Decompression Size Limit","state":"PUBLIC","updated":"2026-07-27T11:02:50.181Z","owner":"thrift"},{"_id":"6a0fa3f958f8e272fea765ab","ID":"CVE-2026-48589","title":"Jakarta EE open redirect via untrusted Referer in post-login redirect flow","state":"PUBLIC","updated":"2026-05-25T20:20:09.531Z","owner":"shiro"},{"_id":"6a10a79658f8e272fea76744","ID":"CVE-2026-48726","title":"revoke_token() unreachable in FabAuthManager / KeycloakAuthManager logout path","state":"PUBLIC","updated":"2026-06-01T07:35:18.096Z","owner":"airflow"},{"_id":"6a116e0058f8e272fea767b7","ID":"CVE-2026-48827","title":"Path traversal in org.apache.sshd:sshd-git","state":"PUBLIC","updated":"2026-06-01T08:37:39.905Z","owner":"mina"},{"_id":"6a11b02f58f8e272fea767ed","ID":"CVE-2026-48828","title":"Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the key","state":"PUBLIC","updated":"2026-07-07T12:25:57.319Z","owner":"airflow"},{"_id":"6a142ec058f8e272fea76a15","ID":"CVE-2026-48834","title":"Denial of service via crafted Accept-Language header parsing","state":"PUBLIC","updated":"2026-08-05T15:07:31.168Z","owner":"answer"},{"_id":"6a14f7d758f8e272fea76c7a","ID":"CVE-2026-48891","title":"/ui/dependencies scheduling graph leaks unreadable Dag identifiers via trigger/sensor dep.source/dep.target","state":"PUBLIC","updated":"2026-07-07T12:26:00.634Z","owner":"airflow"},{"_id":"6a14f9ca58f8e272fea76c7c","ID":"CVE-2026-48892","title":"Config API leaks per-key secrets backend kwargs - masker bypass on synthetic options","state":"PUBLIC","updated":"2026-07-07T12:25:58.879Z","owner":"airflow"},{"_id":"6a15628858f8e272fea76d04","ID":"CVE-2026-48895","title":"Cas-auth Host header influence on CAS service URL","state":"PUBLIC","updated":"2026-06-19T13:16:18.311Z","owner":"apisix"},{"_id":"6a1578c358f8e272fea76d98","ID":"CVE-2026-48910","title":"Markdown parser allows XSS injection in Markdown error processing","state":"PUBLIC","updated":"2026-07-30T12:19:35.157Z","owner":"jspwiki"},{"_id":"6a157fad58f8e272fea76ddc","ID":"CVE-2026-48911","title":"Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow","state":"PUBLIC","updated":"2026-08-05T15:09:10.774Z","owner":"answer"},{"_id":"6a15882a58f8e272fea76df4","ID":"CVE-2026-48912","title":"Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URL","state":"PUBLIC","updated":"2026-08-05T15:10:03.446Z","owner":"answer"},{"_id":"6a15960d58f8e272fea76e18","ID":"CVE-2026-48913","title":"mod_http2 memory corruption when file handles exhausted","state":"PUBLIC","updated":"2026-06-08T15:24:55.228Z","owner":"httpd"},{"_id":"6a16a09f58f8e272fea76f83","ID":"CVE-2026-49042","title":"langchain4j-tools: filter tool argument headers against declared parameters","state":"PUBLIC","updated":"2026-07-06T09:25:44.186Z","owner":"camel"},{"_id":"6a16be2a58f8e272fea77021","ID":"CVE-2026-49050","title":"General user can mint admin access tokens via /access-tokens","state":"PUBLIC","updated":"2026-08-25T06:32:16.645Z","owner":"dolphinscheduler"},{"_id":"6a16cfc358f8e272fea7702d","ID":"CVE-2026-49086","title":"Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers, allowing an actor who can publish to the subscribed topic to influence internal behaviour","state":"PUBLIC","updated":"2026-07-06T08:10:05.908Z","owner":"camel"},{"_id":"6a16d8d158f8e272fea7702f","ID":"CVE-2026-49097","title":"Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to redirect outgoing IRC messages to arbitrary channels or users","state":"PUBLIC","updated":"2026-07-05T11:51:47.659Z","owner":"camel"},{"_id":"6a16d93558f8e272fea77031","ID":"CVE-2026-49098","title":"Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter, allowing an HTTP client to redirect Kafka messages to an arbitrary topic","state":"PUBLIC","updated":"2026-07-05T11:51:10.500Z","owner":"camel"},{"_id":"6a16d99058f8e272fea77037","ID":"CVE-2026-49099","title":"Non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to influence internal behaviour","state":"PUBLIC","updated":"2026-07-06T08:11:29.239Z","owner":"camel"},{"_id":"6a1761eb58f8e272fea770be","ID":"CVE-2026-49157","title":"Authenticated low-privilege Web users retain Jolokia broker-management capability by default","state":"PUBLIC","updated":"2026-06-01T07:20:09.394Z","owner":"activemq"},{"_id":"6a17797758f8e272fea770ed","ID":"CVE-2026-49158","title":"Ruby THeaderTransport ZLIB Decompression Bomb","state":"PUBLIC","updated":"2026-07-27T11:05:01.307Z","owner":"thrift"},{"_id":"6a17da5258f8e272fea7716d","ID":"CVE-2026-49230","title":"Authentication bypass in jwe-decrypt","state":"PUBLIC","updated":"2026-06-19T13:13:32.638Z","owner":"apisix"},{"_id":"6a17e62958f8e272fea771c0","ID":"CVE-2026-49231","title":"Identity spoofing issue in APISIX opa plugin","state":"PUBLIC","updated":"2026-06-19T13:14:23.085Z","owner":"apisix"},{"_id":"6a186fb358f8e272fea77383","ID":"CVE-2026-49267","title":"No certificate validation on SMTP STARTTLS connections","state":"PUBLIC","updated":"2026-06-01T07:53:11.785Z","owner":"airflow"},{"_id":"6a18796558f8e272fea773df","ID":"CVE-2026-49268","title":"LDAP DN Injection in DefaultLdapRealm","state":"PUBLIC","updated":"2026-06-17T13:07:43.325Z","owner":"shiro"},{"_id":"6a188ec158f8e272fea7743d","ID":"CVE-2026-49270","title":"Durable Subscription Disclosure via Crafted BrokerInfo (OpenWire)","state":"PUBLIC","updated":"2026-06-01T07:19:32.927Z","owner":"activemq"},{"_id":"6a18a74558f8e272fea7747c","ID":"CVE-2026-49296","title":"Per-DAG read bypass discloses co-located DAGs' source via GET /api/v2/dagSources/{dag_id}","state":"PUBLIC","updated":"2026-07-07T12:26:02.148Z","owner":"airflow"},{"_id":"6a18a8c358f8e272fea77486","ID":"CVE-2026-49297","title":"Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator)","state":"PUBLIC","updated":"2026-07-04T05:57:06.977Z","owner":"airflow"},{"_id":"6a18b01c58f8e272fea7753e","ID":"CVE-2026-49298","title":"JWT Token Exposure in KubernetesExecutor Command-Line Arguments","state":"PUBLIC","updated":"2026-06-01T07:34:31.163Z","owner":"airflow"},{"_id":"6a19443f58f8e272fea775a1","ID":"CVE-2026-49326","title":"Missing scanner instance owner check in thrift delegation service","state":"PUBLIC","updated":"2026-07-24T14:56:20.732Z","owner":"hbase"},{"_id":"6a195f2a58f8e272fea7766f","ID":"CVE-2026-49328","title":"Improper validation of user-supplied URLs leading to SSRF","state":"PUBLIC","updated":"2026-06-01T10:10:32.924Z","owner":"fesod"},{"_id":"6a19b46558f8e272fea7781f","ID":"CVE-2026-49361","title":"Apache Fluss Netty Frame Decoder Memory Exhaustion Vulnerability","state":"PUBLIC","updated":"2026-06-01T07:57:25.667Z","owner":"fluss"},{"_id":"6a19c3c158f8e272fea778db","ID":"CVE-2026-49365","title":"Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients","state":"PUBLIC","updated":"2026-07-05T11:49:54.080Z","owner":"camel"},{"_id":"6a19f8ad58f8e272fea77a3b","ID":"CVE-2026-49432","title":"STOMP negative content-length enables denial of service","state":"PUBLIC","updated":"2026-06-30T09:54:37.498Z","owner":"activemq"},{"_id":"6a19fbb558f8e272fea77a4d","ID":"CVE-2026-49434","title":"LdapNetworkConnector instantiates denied transports and a remote-properties broker","state":"PUBLIC","updated":"2026-06-30T09:55:28.407Z","owner":"activemq"},{"_id":"6a1b918858f8e272fea77cfe","ID":"CVE-2026-49486","title":"FTP Provider does not protect FTPS data channel (missing PROT_P)","state":"PUBLIC","updated":"2026-06-26T07:20:08.333Z","owner":"airflow"},{"_id":"6a1b91af58f8e272fea77d00","ID":"CVE-2026-49487","title":"Task-instance API exposes secrets in deferred trigger kwargs","state":"PUBLIC","updated":"2026-07-07T12:26:03.726Z","owner":"airflow"},{"_id":"6a1bdaec58f8e272fea77d14","ID":"CVE-2026-49488","title":"Arbitrary File Read","state":"PUBLIC","updated":"2026-07-14T09:51:40.069Z","owner":"openmeetings"},{"_id":"6a1dc36858f8e272fea783a9","ID":"CVE-2026-49818","title":"Path traversal in GCSToSambaOperator via GCS object names","state":"PUBLIC","updated":"2026-06-10T17:37:51.189Z","owner":"airflow"},{"_id":"6a1de86f58f8e272fea783d2","ID":"CVE-2026-49844","title":"Improper serialization of non-finite floating-point values in MapMessage.asJson()","state":"PUBLIC","updated":"2026-07-10T21:14:52.822Z","owner":"logging"},{"_id":"6a1df8a058f8e272fea7841b","ID":"CVE-2026-49845","title":"SQL Injection vulnerability in HiveMetaStore partition-name direct-SQL paths","state":"PUBLIC","updated":"2026-08-24T19:33:58.098Z","owner":"hive"},{"_id":"6a1e420558f8e272fea7848f","ID":"CVE-2026-49871","title":"cas-auth login CSRF / session injection issue","state":"PUBLIC","updated":"2026-06-19T13:18:27.333Z","owner":"apisix"},{"_id":"6a1e53dc58f8e272fea784bb","ID":"CVE-2026-49872","title":"Improper authentication in cas-auth plugin","state":"PUBLIC","updated":"2026-06-19T13:19:29.418Z","owner":"apisix"},{"_id":"6a1e984158f8e272fea78593","ID":"CVE-2026-49875","title":"XML External Entity (XXE) Injection in W3CMultiSchemaFactory and EndpointReferenceUtils","state":"PUBLIC","updated":"2026-06-25T06:58:56.041Z","owner":"cxf"},{"_id":"6a1ecd6c58f8e272fea78637","ID":"CVE-2026-49876","title":"Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs","state":"PUBLIC","updated":"2026-07-13T08:45:33.423Z","owner":"gravitino"},{"_id":"6a1edcb358f8e272fea786b6","ID":"CVE-2026-49877","title":"Authenticated web users retain admin access by default in the Web Console","state":"PUBLIC","updated":"2026-06-30T09:53:41.777Z","owner":"activemq"},{"_id":"6a1f10e658f8e272fea7874e","ID":"CVE-2026-49975","title":"mod_http2 denial of service","state":"PUBLIC","updated":"2026-06-08T15:26:08.775Z","owner":"httpd"},{"_id":"6a202225d92d3d8f3aa39758","ID":"CVE-2026-50076","title":"Java ReplaceResolverSerializer deserialization checks bypass","state":"PUBLIC","updated":"2026-06-04T09:08:27.361Z","owner":"fory"},{"_id":"6a204cead92d3d8f3aa397ca","ID":"CVE-2026-50112","title":"RCE and SSRF in direct download, metalink and NFS templates","state":"PUBLIC","updated":"2026-08-21T08:29:39.850Z","owner":"cloudstack"},{"_id":"6a20c15ed92d3d8f3aa398c3","ID":"CVE-2026-50203","title":"Path traversal in SFTPHook.retrieve_directory allows local file write outside the destination directory via malicious server-supplied directory-entry names","state":"PUBLIC","updated":"2026-06-17T01:48:06.460Z","owner":"airflow"},{"_id":"6a211bc8d92d3d8f3aa398ce","ID":"CVE-2026-50222","title":"Improper access control in Userdata reference APIs","state":"PUBLIC","updated":"2026-08-21T08:29:16.822Z","owner":"cloudstack"},{"_id":"6a2142f2d92d3d8f3aa3997f","ID":"CVE-2026-50223","title":"DataResource Low-Privileged Authenticated FreeMarker Template Injection Leads to Remote Code Execution","state":"PUBLIC","updated":"2026-06-10T22:23:48.015Z","owner":"ofbiz"},{"_id":"6a2147cbd92d3d8f3aa399c0","ID":"CVE-2026-50229","title":"XSS in number guess example","state":"PUBLIC","updated":"2026-06-29T20:37:28.560Z","owner":"tomcat"},{"_id":"6a229820d92d3d8f3aa39c92","ID":"CVE-2026-50622","title":"Missing Authorization on Admin Endpoints","state":"PUBLIC","updated":"2026-07-29T09:10:07.076Z","owner":"atlas"},{"_id":"6a22a2f5d92d3d8f3aa39cbf","ID":"CVE-2026-50623","title":"Authentication Bypass in OAuth2 TokenIntrospectionService","state":"PUBLIC","updated":"2026-06-25T06:34:24.353Z","owner":"cxf"},{"_id":"6a22a6bed92d3d8f3aa39d19","ID":"CVE-2026-50627","title":"OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator","state":"PUBLIC","updated":"2026-06-25T06:36:34.767Z","owner":"cxf"},{"_id":"6a22a907d92d3d8f3aa39d83","ID":"CVE-2026-50628","title":"OAuth2: Inverted IP Binding Check Defeats Security Control","state":"PUBLIC","updated":"2026-06-25T06:38:43.915Z","owner":"cxf"},{"_id":"6a22ab12d92d3d8f3aa39de9","ID":"CVE-2026-50629","title":"OAuth2: Log Injection via Unsanitized Client Identifier","state":"PUBLIC","updated":"2026-06-25T06:43:46.623Z","owner":"cxf"},{"_id":"6a22abb4d92d3d8f3aa39e05","ID":"CVE-2026-50630","title":"OAuth2: HTTP Response Splitting via WWW-Authenticate Realm Injection","state":"PUBLIC","updated":"2026-06-25T06:42:38.758Z","owner":"cxf"},{"_id":"6a22acadd92d3d8f3aa39e33","ID":"CVE-2026-50631","title":"OAuth2: TOCTOU Race Condition in Refresh Token Processing","state":"PUBLIC","updated":"2026-06-25T06:40:52.934Z","owner":"cxf"},{"_id":"6a22ae41d92d3d8f3aa39e4e","ID":"CVE-2026-50632","title":"JNDI Injection Vulnerability in JMSConfigFactory","state":"PUBLIC","updated":"2026-06-25T06:47:58.029Z","owner":"cxf"},{"_id":"6a22b016d92d3d8f3aa39e7a","ID":"CVE-2026-50633","title":"JNDI Injection vulnerability in DispatchMDBMessageListenerImpl","state":"PUBLIC","updated":"2026-06-25T06:49:37.691Z","owner":"cxf"},{"_id":"6a22b24dd92d3d8f3aa39ea2","ID":"CVE-2026-50634","title":"WS JSON request filter trusts metadata from an unvalidated first signature entry","state":"PUBLIC","updated":"2026-06-25T06:51:16.599Z","owner":"cxf"},{"_id":"6a22d78dd92d3d8f3aa39f18","ID":"CVE-2026-50645","title":"No restriction on attachment headers per message","state":"PUBLIC","updated":"2026-08-07T11:18:25.630Z","owner":"cxf"},{"_id":"6a2300e9d92d3d8f3aa39f7a","ID":"CVE-2026-50734","title":"Pre-authentication OpenWire memory-allocation DoS during wire format negotiation","state":"PUBLIC","updated":"2026-06-30T09:53:02.137Z","owner":"activemq"},{"_id":"6a24512dd92d3d8f3aa3a067","ID":"CVE-2026-50749","title":"Missing authorization in revision audit reject allows authenticated users to reject pending revisions","state":"PUBLIC","updated":"2026-08-05T15:11:00.104Z","owner":"answer"},{"_id":"6a2472f4d92d3d8f3aa3a0a1","ID":"CVE-2026-50750","title":"Pre-authentication OpenWire DoS following fix for CVE-2026-49270","state":"PUBLIC","updated":"2026-06-30T09:51:55.636Z","owner":"activemq"},{"_id":"6a265f09d92d3d8f3aa3a18a","ID":"CVE-2026-52680","title":"REST batch multipart upload path traversal allows controlled file write","state":"PUBLIC","updated":"2026-07-30T08:27:43.964Z","owner":"kyuubi"},{"_id":"6a26e234d92d3d8f3aa3a5c8","ID":"CVE-2026-52760","title":"Stored XSS via Unescaped values in ActiveMQ Web Console","state":"PUBLIC","updated":"2026-06-30T09:50:28.410Z","owner":"activemq"},{"_id":"6a27d432d92d3d8f3aa3a859","ID":"CVE-2026-53404","title":"Bad ornext processing in RewriteValve","state":"PUBLIC","updated":"2026-06-29T20:39:47.505Z","owner":"tomcat"},{"_id":"6a27df45d92d3d8f3aa3a8b7","ID":"CVE-2026-53405","title":"Remote Code Execution via Flowable BPMN Groovy ScriptTask","state":"PUBLIC","updated":"2026-07-20T14:20:04.039Z","owner":"syncope"},{"_id":"6a27e951d92d3d8f3aa3a918","ID":"CVE-2026-53421","title":"Remote Code Execution via Scripted Connector","state":"PUBLIC","updated":"2026-07-20T14:21:06.192Z","owner":"syncope"},{"_id":"6a281e78d92d3d8f3aa3a98c","ID":"CVE-2026-53434","title":"Invalid CRL configuration doesn't trigger failure for FFM Connector","state":"PUBLIC","updated":"2026-06-29T20:41:05.689Z","owner":"tomcat"},{"_id":"6a285b36d92d3d8f3aa3aa60","ID":"CVE-2026-53561","title":"Unauthenticated authentication bypass in HiveServer2 HTTP SAML bearer-token validation allows impersonation of any Hive user","state":"PUBLIC","updated":"2026-08-24T19:34:40.993Z","owner":"hive"},{"_id":"6a2a8cd0d92d3d8f3aa3af99","ID":"CVE-2026-53913","title":"KeycloakSecurityPolicy verifies the bearer access token only inside its role and permission checks, so in the default configuration the token is never verified and any non-null bearer value is accepted","state":"PUBLIC","updated":"2026-07-06T08:12:31.281Z","owner":"camel"},{"_id":"6a2ac7d8d92d3d8f3aa3afdd","ID":"CVE-2026-53916","title":"Unbounded header buffer in STOMP NIO codec","state":"PUBLIC","updated":"2026-06-30T09:49:54.244Z","owner":"activemq"},{"_id":"6a2aca1ad92d3d8f3aa3afe7","ID":"CVE-2026-53917","title":"Unbounded memory allocation in OpenWire property unmarshalling","state":"PUBLIC","updated":"2026-06-30T09:49:16.202Z","owner":"activemq"},{"_id":"6a2b5b70d92d3d8f3aa3b199","ID":"CVE-2026-54183","title":"Airflow Variables were not masked in the UI for authenticated users","state":"PUBLIC","updated":"2026-08-12T15:34:17.762Z","owner":"airflow"},{"_id":"6a2bfeded92d3d8f3aa3b2f7","ID":"CVE-2026-54225","title":"Denial of Service attack via large attachments","state":"PUBLIC","updated":"2026-08-06T10:11:39.713Z","owner":"cxf"},{"_id":"6a2c04e8d92d3d8f3aa3b311","ID":"CVE-2026-54226","title":"RESTORE IntSet Integer Overflow Leads to Remote DoS","state":"PUBLIC","updated":"2026-06-25T07:59:22.966Z","owner":"kvrocks"},{"_id":"6a2d2b46d92d3d8f3aa3b35e","ID":"CVE-2026-54399","title":"Unbounded HTTP Header/Line Length in Default Configuration","state":"PUBLIC","updated":"2026-07-01T17:05:54.930Z","owner":"httpcomponents"},{"_id":"6a2e76d2d92d3d8f3aa3b41d","ID":"CVE-2026-54428","title":"HPackDecoder Unlimited Header List Size Before SETTINGS ACK","state":"PUBLIC","updated":"2026-07-01T17:05:28.114Z","owner":"httpcomponents"},{"_id":"6a302dd9d92d3d8f3aa3b669","ID":"CVE-2026-54475","title":"Temporary destination ownership takeover","state":"PUBLIC","updated":"2026-06-30T09:48:27.404Z","owner":"activemq"},{"_id":"6a305f23d92d3d8f3aa3b691","ID":"CVE-2026-54665","title":"Missing Validation for Proxy Host Headers","state":"PUBLIC","updated":"2026-06-22T07:34:12.067Z","owner":"nifi"},{"_id":"6a318aa3d92d3d8f3aa3b897","ID":"CVE-2026-55276","title":"Logged effective web.xml is incomplete","state":"PUBLIC","updated":"2026-06-29T20:42:28.486Z","owner":"tomcat"},{"_id":"6a32b2b64472a2da26aa7fd7","ID":"CVE-2026-55799","title":"Remote Code Execution Vulnerability in GraalScriptEngineCreator","state":"PUBLIC","updated":"2026-08-10T10:23:27.092Z","owner":"ranger"},{"_id":"6a32b6d94472a2da26aa7ff7","ID":"CVE-2026-55814","title":"Download APIs expose plugin data without authentication","state":"PUBLIC","updated":"2026-08-10T10:21:26.393Z","owner":"ranger"},{"_id":"6a32e1c14472a2da26aa8056","ID":"CVE-2026-55955","title":"EncryptInterceptor not protected against replay attacks","state":"PUBLIC","updated":"2026-06-29T20:44:43.001Z","owner":"tomcat"},{"_id":"6a32e9304472a2da26aa8090","ID":"CVE-2026-55956","title":"Security constraints for default servlet ignored method","state":"PUBLIC","updated":"2026-06-29T20:46:06.844Z","owner":"tomcat"},{"_id":"6a32f4a84472a2da26aa80fb","ID":"CVE-2026-55957","title":"Authentication bypass with JNDIRealm and GSSAPI authenticated bind","state":"PUBLIC","updated":"2026-06-29T20:47:14.140Z","owner":"tomcat"},{"_id":"6a3329214472a2da26aa812b","ID":"CVE-2026-55968","title":"Node.js quadratic-time DoS in server receive transports","state":"PUBLIC","updated":"2026-07-27T11:06:12.486Z","owner":"thrift"},{"_id":"6a332a334472a2da26aa813f","ID":"CVE-2026-55969","title":"integer overflow in TProtocol::checkReadBytesAvailable()","state":"PUBLIC","updated":"2026-07-27T11:07:43.565Z","owner":"thrift"},{"_id":"6a332d594472a2da26aa815b","ID":"CVE-2026-55970","title":"C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat()","state":"PUBLIC","updated":"2026-07-27T11:09:36.113Z","owner":"thrift"},{"_id":"6a332da24472a2da26aa8161","ID":"CVE-2026-55971","title":"C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform()","state":"PUBLIC","updated":"2026-07-27T11:11:18.790Z","owner":"thrift"},{"_id":"6a3334594472a2da26aa81ba","ID":"CVE-2026-55976","title":"SSRF vulnerability in Hive Avro Serde due to Insufficient input validation on avro.schema.url","state":"PUBLIC","updated":"2026-08-24T19:34:22.629Z","owner":"hive"},{"_id":"6a33a8714472a2da26aa8212","ID":"CVE-2026-55993","title":"The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling influencing internal behaviour","state":"PUBLIC","updated":"2026-07-06T08:13:23.425Z","owner":"camel"},{"_id":"6a33a8cb4472a2da26aa8214","ID":"CVE-2026-55994","title":"The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling control over internal behaviour","state":"PUBLIC","updated":"2026-07-06T08:13:58.182Z","owner":"camel"},{"_id":"6a3427054472a2da26aa831f","ID":"CVE-2026-56091","title":"Authentication bypass in Guice-Web integration","state":"PUBLIC","updated":"2026-06-25T08:45:18.079Z","owner":"shiro"},{"_id":"6a34a7ef4472a2da26aa8394","ID":"CVE-2026-56130","title":"Remember-me cookie isn't checked for expiry on the server","state":"PUBLIC","updated":"2026-06-25T08:44:28.652Z","owner":"shiro"},{"_id":"6a3511b34472a2da26aa88f7","ID":"CVE-2026-56139","title":"The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients","state":"PUBLIC","updated":"2026-07-06T08:15:07.275Z","owner":"camel"},{"_id":"6a35124d4472a2da26aa8909","ID":"CVE-2026-56140","title":"An inbound Camel-namespace filter was added to Sns2HeaderFilterStrategy to align it with sibling components","state":"PUBLIC","updated":"2026-07-06T08:15:59.205Z","owner":"camel"},{"_id":"6a3637154472a2da26aa8c94","ID":"CVE-2026-56287","title":"Boolean SQL Injection in Client Search API (orderBy parameter) leading to Local File Disclosure","state":"PUBLIC","updated":"2026-07-15T09:19:36.672Z","owner":"fineract"},{"_id":"6a3939254472a2da26aa913c","ID":"CVE-2026-56452","title":"Path traversal in SCP file reception","state":"PUBLIC","updated":"2026-07-20T20:26:25.352Z","owner":"mina"},{"_id":"6a394b8c4472a2da26aa91a2","ID":"CVE-2026-56623","title":"Path traversal in org.apache.sshd:sshd-git on Windows","state":"PUBLIC","updated":"2026-07-20T20:29:07.039Z","owner":"mina"},{"_id":"6a394f374472a2da26aa91c0","ID":"CVE-2026-56624","title":"SSH certificate options lack validations","state":"PUBLIC","updated":"2026-07-20T20:28:23.266Z","owner":"mina"},{"_id":"6a3b006c4472a2da26aa93f6","ID":"CVE-2026-57111","title":"Permissive CORS Configuration in REST API Allows Unrestricted Cross-Origin","state":"PUBLIC","updated":"2026-07-09T07:08:43.930Z","owner":"helix"},{"_id":"6a3baa374472a2da26aa94b3","ID":"CVE-2026-57308","title":"SQL injection vulnerability in Audit Events search","state":"PUBLIC","updated":"2026-07-20T14:21:50.872Z","owner":"syncope"},{"_id":"6a3cfe5e4472a2da26aa990a","ID":"CVE-2026-57817","title":"The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow","state":"PUBLIC","updated":"2026-08-06T10:24:04.605Z","owner":"cxf"},{"_id":"6a3d00464472a2da26aa9924","ID":"CVE-2026-57818","title":"OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider","state":"PUBLIC","updated":"2026-08-06T11:24:52.308Z","owner":"cxf"},{"_id":"6a3d08cb4472a2da26aa9968","ID":"CVE-2026-57819","title":"No default restriction on the amount of form parameters per message","state":"PUBLIC","updated":"2026-08-06T10:12:25.051Z","owner":"cxf"},{"_id":"6a3d15474472a2da26aa99e2","ID":"CVE-2026-57821","title":"Office list: SQL Injection via Subquery in orderBy","state":"PUBLIC","updated":"2026-07-15T08:40:21.140Z","owner":"fineract"},{"_id":"6a3d61e24472a2da26aa9a66","ID":"CVE-2026-57834","title":"Malformed chunked message body allows request smuggling","state":"PUBLIC","updated":"2026-07-29T07:25:43.006Z","owner":"trafficserver"},{"_id":"6a3e54bc4472a2da26aa9b18","ID":"CVE-2026-57914","title":"StackOverflow on parsing deeply nested ASN1 structures","state":"PUBLIC","updated":"2026-06-26T11:28:25.784Z","owner":"directory"},{"_id":"6a3e57e14472a2da26aa9b52","ID":"CVE-2026-57915","title":"Kerberos Pre-Authentication Bypass","state":"PUBLIC","updated":"2026-06-26T12:09:53.178Z","owner":"directory"},{"_id":"6a3fb6d84472a2da26aa9f96","ID":"CVE-2026-58023","title":"c_glib heap out-of-bounds read in transport leftover-bytes path","state":"PUBLIC","updated":"2026-07-27T11:12:35.855Z","owner":"thrift"},{"_id":"6a41323f4472a2da26aaa04c","ID":"CVE-2026-58065","title":"Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification","state":"PUBLIC","updated":"2026-07-19T16:29:11.369Z","owner":"airflow"},{"_id":"6a413ab04472a2da26aaa04e","ID":"CVE-2026-58076","title":"Unguarded import_string() of airflow_exc_ser / base_exc_ser exception nodes in BaseSerialization.deserialize enables DAG-author RCE on Scheduler / API Server","state":"PUBLIC","updated":"2026-08-12T15:40:58.403Z","owner":"airflow"},{"_id":"6a428fcd4472a2da26aaa27a","ID":"CVE-2026-58150","title":"HTTP/2 requests with Transfer-Encoding are not rejected, allowing request smuggling","state":"PUBLIC","updated":"2026-07-29T07:30:24.423Z","owner":"trafficserver"},{"_id":"6a42900d4472a2da26aaa28e","ID":"CVE-2026-58151","title":"Abusive HTTP/2 framing can exhaust resources and crash the server","state":"PUBLIC","updated":"2026-07-29T08:15:41.513Z","owner":"trafficserver"},{"_id":"6a42903b4472a2da26aaa2ac","ID":"CVE-2026-58152","title":"Integer-handling errors in HPACK/XPACK decoding corrupt memory","state":"PUBLIC","updated":"2026-07-29T08:16:17.147Z","owner":"trafficserver"},{"_id":"6a42906b4472a2da26aaa2c4","ID":"CVE-2026-58153","title":"HTTP/2 to HTTP/1 conversion forwards origin trailers to clients unsafely","state":"PUBLIC","updated":"2026-07-29T08:17:07.259Z","owner":"trafficserver"},{"_id":"6a42909f4472a2da26aaa2d8","ID":"CVE-2026-58154","title":"Memory-safety errors in MIME and header parsing","state":"PUBLIC","updated":"2026-07-29T08:23:57.475Z","owner":"trafficserver"},{"_id":"6a4293324472a2da26aaa2ec","ID":"CVE-2026-58155","title":"Header-name length truncation enables header aliasing and request smuggling","state":"PUBLIC","updated":"2026-07-29T08:24:30.308Z","owner":"trafficserver"},{"_id":"6a4293644472a2da26aaa300","ID":"CVE-2026-58156","title":"URL and port parsing errors allow access-control bypass","state":"PUBLIC","updated":"2026-07-29T08:25:07.986Z","owner":"trafficserver"},{"_id":"6a42938b4472a2da26aaa314","ID":"CVE-2026-58157","title":"Improper server-session reuse can expose data across client connections","state":"PUBLIC","updated":"2026-07-29T08:25:47.725Z","owner":"trafficserver"},{"_id":"6a4293b44472a2da26aaa328","ID":"CVE-2026-58158","title":"PROXY protocol parsing has port truncation and a stack overflow","state":"PUBLIC","updated":"2026-07-29T08:26:27.296Z","owner":"trafficserver"},{"_id":"6a4293e04472a2da26aaa33c","ID":"CVE-2026-58159","title":"Listener and ACL handling allow access-control bypass","state":"PUBLIC","updated":"2026-07-29T08:31:14.552Z","owner":"trafficserver"},{"_id":"6a42941f4472a2da26aaa354","ID":"CVE-2026-58160","title":"Out-of-bounds reads while parsing DNS responses","state":"PUBLIC","updated":"2026-07-29T08:34:31.111Z","owner":"trafficserver"},{"_id":"6a4294434472a2da26aaa368","ID":"CVE-2026-58161","title":"Memory-safety errors in TLS and SNI handling can crash the server","state":"PUBLIC","updated":"2026-07-29T08:35:35.583Z","owner":"trafficserver"},{"_id":"6a4294694472a2da26aaa37c","ID":"CVE-2026-58162","title":"Certifier plugin trusts client SNI when generating certificates","state":"PUBLIC","updated":"2026-07-29T08:36:12.596Z","owner":"trafficserver"},{"_id":"6a4294944472a2da26aaa390","ID":"CVE-2026-58163","title":"Cache deserialization and lifetime errors can corrupt state or crash the server","state":"PUBLIC","updated":"2026-07-29T08:36:53.072Z","owner":"trafficserver"},{"_id":"6a4294bb4472a2da26aaa3a8","ID":"CVE-2026-58164","title":"Remap configuration lifetime and TOCTOU errors cause use-after-free","state":"PUBLIC","updated":"2026-07-29T08:37:38.531Z","owner":"trafficserver"},{"_id":"6a429c0a4472a2da26aaa3cc","ID":"CVE-2026-58175","title":"HostDB SRV handling leaks memory","state":"PUBLIC","updated":"2026-07-29T08:41:45.146Z","owner":"trafficserver"},{"_id":"6a429c2b4472a2da26aaa3e0","ID":"CVE-2026-58177","title":"Memory-safety and path-traversal errors in the Cripts framework","state":"PUBLIC","updated":"2026-07-29T08:42:36.014Z","owner":"trafficserver"},{"_id":"6a429c514472a2da26aaa3f4","ID":"CVE-2026-58178","title":"ESI plugin allows uncontrolled recursion and server-side request forgery","state":"PUBLIC","updated":"2026-07-29T08:43:21.506Z","owner":"trafficserver"},{"_id":"6a429c744472a2da26aaa408","ID":"CVE-2026-58179","title":"regex_remap plugin overflows the stack from attacker input","state":"PUBLIC","updated":"2026-07-29T08:44:28.901Z","owner":"trafficserver"},{"_id":"6a429c9c4472a2da26aaa41c","ID":"CVE-2026-58180","title":"txn_box plugin overflows the stack from attacker input","state":"PUBLIC","updated":"2026-07-29T08:45:10.821Z","owner":"trafficserver"},{"_id":"6a429cc44472a2da26aaa430","ID":"CVE-2026-58181","title":"uri_signing and url_sig plugins can exhaust the stack or crash","state":"PUBLIC","updated":"2026-07-29T08:46:00.299Z","owner":"trafficserver"},{"_id":"6a429cec4472a2da26aaa444","ID":"CVE-2026-58182","title":"ts_lua plugin has initialization and resource-handling errors","state":"PUBLIC","updated":"2026-07-29T08:54:41.470Z","owner":"trafficserver"},{"_id":"6a429d164472a2da26aaa458","ID":"CVE-2026-58183","title":"prefetch plugin can crash on attacker-influenced input","state":"PUBLIC","updated":"2026-07-29T08:55:45.403Z","owner":"trafficserver"},{"_id":"6a429d3b4472a2da26aaa470","ID":"CVE-2026-58184","title":"header_rewrite plugin cookie handling can corrupt memory","state":"PUBLIC","updated":"2026-07-29T08:56:45.008Z","owner":"trafficserver"},{"_id":"6a429d664472a2da26aaa484","ID":"CVE-2026-58185","title":"Use-after-free in the intercept plugin","state":"PUBLIC","updated":"2026-07-29T08:57:42.562Z","owner":"trafficserver"},{"_id":"6a429ebb4472a2da26aaa49e","ID":"CVE-2026-58186","title":"webp_transform plugin decodes unsafely and mislabels degraded responses","state":"PUBLIC","updated":"2026-07-29T09:01:35.556Z","owner":"trafficserver"},{"_id":"6a429edb4472a2da26aaa4b2","ID":"CVE-2026-58187","title":"Multiplexer plugin chunk decoder enables a denial of service","state":"PUBLIC","updated":"2026-07-29T09:03:17.157Z","owner":"trafficserver"},{"_id":"6a429efc4472a2da26aaa4c6","ID":"CVE-2026-58188","title":"Memory-safety and limit-bypass errors across experimental plugins","state":"PUBLIC","updated":"2026-07-29T09:04:20.085Z","owner":"trafficserver"},{"_id":"6a429f1a4472a2da26aaa4de","ID":"CVE-2026-58189","title":"Plugins resetting the redirect counter enable SSRF amplification","state":"PUBLIC","updated":"2026-07-29T09:05:13.041Z","owner":"trafficserver"},{"_id":"6a43381c4472a2da26aaa9b6","ID":"CVE-2026-58319","title":"Improper Authentication in Frontend HTTP API","state":"PUBLIC","updated":"2026-07-14T09:36:25.369Z","owner":"doris"},{"_id":"6a43f7544472a2da26aab3a0","ID":"CVE-2026-58389","title":"Rust binary protocol non-strict path missing string size limit","state":"PUBLIC","updated":"2026-07-27T11:14:25.617Z","owner":"thrift"},{"_id":"6a4566414472a2da26aab6f0","ID":"CVE-2026-58624","title":"Remote execution of JGit commands can write files on the server","state":"PUBLIC","updated":"2026-07-20T20:27:36.709Z","owner":"mina"},{"_id":"6a4591204472a2da26aab76c","ID":"CVE-2026-58662","title":"C++ THeaderTransport::readString() info-header length bounds bypass","state":"PUBLIC","updated":"2026-07-27T11:17:20.407Z","owner":"thrift"},{"_id":"6a463fd04472a2da26aab884","ID":"CVE-2026-59083","title":"Incorrect URL decoding in RewriteValve may allow security control bypass","state":"PUBLIC","updated":"2026-07-14T08:13:32.606Z","owner":"tomcat"},{"_id":"6a4640984472a2da26aab889","ID":"CVE-2026-59084","title":"EncryptInterceptor requirements not clearly documented","state":"PUBLIC","updated":"2026-07-14T08:24:29.946Z","owner":"tomcat"},{"_id":"6a464d1d4472a2da26aab899","ID":"CVE-2026-59085","title":"Server-Side Request Forgery (SSRF) vulnerability in webhook module","state":"PUBLIC","updated":"2026-08-21T08:28:50.341Z","owner":"cloudstack"},{"_id":"6a469e6b4472a2da26aabf4b","ID":"CVE-2026-59173","title":"DoS vulnerability in HTTP/2 via stalled flow-control conditions","state":"PUBLIC","updated":"2026-07-18T12:52:08.684Z","owner":"trafficserver"},{"_id":"6a47934c4472a2da26aac154","ID":"CVE-2026-59230","title":"Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled","state":"PUBLIC","updated":"2026-08-24T16:09:32.233Z","owner":"camel"},{"_id":"6a48512a4472a2da26aac16c","ID":"CVE-2026-59242","title":"Arbitrary airflow.* class instantiation on the API server via the XCom deserialize endpoint","state":"PUBLIC","updated":"2026-08-12T15:34:59.496Z","owner":"airflow"},{"_id":"6a48513b4472a2da26aac16e","ID":"CVE-2026-59243","title":"FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)","state":"PUBLIC","updated":"2026-07-28T10:25:25.203Z","owner":"airflow"},{"_id":"6a4851ce4472a2da26aac170","ID":"CVE-2026-59244","title":"Secrets masker: `var.json` Variable values not masked in the Rendered Templates UI","state":"PUBLIC","updated":"2026-08-12T15:43:15.962Z","owner":"airflow"},{"_id":"6a4866fa4472a2da26aac188","ID":"CVE-2026-59245","title":"FAB auth manager: a DAG named \"DAGs\" hijacks the global all-DAGs permission (access_control privilege escalation via resource_name() collision)","state":"PUBLIC","updated":"2026-07-19T16:30:45.992Z","owner":"airflow"},{"_id":"6a4b600c4472a2da26aacaba","ID":"CVE-2026-59654","title":"DoS caused by database connections leak","state":"PUBLIC","updated":"2026-08-21T12:32:59.667Z","owner":"cloudstack"},{"_id":"6a4b70a94472a2da26aaccaf","ID":"CVE-2026-59655","title":"Unauthenticated OAuth provider client-secret disclosure","state":"PUBLIC","updated":"2026-08-21T08:28:13.175Z","owner":"cloudstack"},{"_id":"6a4b78eb4472a2da26aacd58","ID":"CVE-2026-59657","title":"Sensitive Information Disclosure via Cleartext Storage in AsyncJob","state":"PUBLIC","updated":"2026-08-21T08:27:52.170Z","owner":"cloudstack"},{"_id":"6a4cb2a54472a2da26aad32e","ID":"CVE-2026-59780","title":"LDAP provider configuration disclosure","state":"PUBLIC","updated":"2026-08-21T08:27:15.624Z","owner":"cloudstack"},{"_id":"6a4cebe94472a2da26aad503","ID":"CVE-2026-59799","title":"Missing Privilege Check in Two-Factor Authentication Disable Flow","state":"PUBLIC","updated":"2026-08-21T08:26:50.990Z","owner":"cloudstack"},{"_id":"6a4d26ff4472a2da26aad56b","ID":"CVE-2026-59878","title":"AMQP NIO negative frame size validation bypass leading to DoS","state":"PUBLIC","updated":"2026-07-28T13:33:50.227Z","owner":"activemq"},{"_id":"6a4dc76b4472a2da26aad63a","ID":"CVE-2026-60023","title":"Unauthorized disclosure of deleted or pending answer content","state":"PUBLIC","updated":"2026-08-05T15:12:01.731Z","owner":"answer"},{"_id":"6a4e0dd44472a2da26aad660","ID":"CVE-2026-60053","title":"Residual Administrative API Key Access After Role or Account Revocation","state":"PUBLIC","updated":"2026-08-05T15:13:06.027Z","owner":"answer"},{"_id":"6a4e2e864472a2da26aad906","ID":"CVE-2026-60080","title":"Rust MetaString heap use-after-free","state":"PUBLIC","updated":"2026-07-21T10:54:15.045Z","owner":"fory"},{"_id":"6a4e4be44472a2da26aad986","ID":"CVE-2026-60093","title":"Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir","state":"PUBLIC","updated":"2026-08-24T14:06:02.406Z","owner":"camel"},{"_id":"6a4eb3a04472a2da26aada22","ID":"CVE-2026-61372","title":"Web requests using SPARQL Update can escape file restrictions","state":"PUBLIC","updated":"2026-08-03T15:19:33.471Z","owner":"jena"},{"_id":"6a4f544b4472a2da26aadc38","ID":"CVE-2026-61397","title":"OAuth2 Token Cross-Request Leak","state":"PUBLIC","updated":"2026-08-21T08:26:22.132Z","owner":"cloudstack"},{"_id":"6a4f56a44472a2da26aadc44","ID":"CVE-2026-61398","title":"Cross-Site Scripting (XSS) Vulnerability in Instance Reset Password Function in UI","state":"PUBLIC","updated":"2026-08-21T08:25:46.538Z","owner":"cloudstack"},{"_id":"6a4f57744472a2da26aadc5a","ID":"CVE-2026-61399","title":"Cross-Site Scripting (XSS) Vulnerability in Lock User Function in UI","state":"PUBLIC","updated":"2026-08-21T08:25:22.261Z","owner":"cloudstack"},{"_id":"6a4f5a304472a2da26aadc66","ID":"CVE-2026-61400","title":"Get and Run Diagnostics Command Injection","state":"PUBLIC","updated":"2026-08-21T08:25:01.740Z","owner":"cloudstack"},{"_id":"6a4f87434472a2da26aadd3a","ID":"CVE-2026-61422","title":"Authenticated pre-validation SSRF in registerTemplate","state":"PUBLIC","updated":"2026-08-21T08:24:36.997Z","owner":"cloudstack"},{"_id":"6a4fb4624472a2da26aade4f","ID":"CVE-2026-61466","title":"OAuth2 Dynamic Client Registration Scope Self-Escalation","state":"PUBLIC","updated":"2026-08-06T11:24:26.209Z","owner":"cxf"},{"_id":"6a50ea3b4472a2da26aae25d","ID":"CVE-2026-61487","title":"Authorization bypass via temporary composite destinations","state":"PUBLIC","updated":"2026-07-28T13:32:36.487Z","owner":"activemq"},{"_id":"6a52ae824472a2da26aae4f0","ID":"CVE-2026-61899","title":"Possible classpath file download through URL manipulation","state":"PUBLIC","updated":"2026-08-10T10:36:02.028Z","owner":"tapestry"},{"_id":"6a54f6724472a2da26aae81c","ID":"CVE-2026-62183","title":"User self-service privilege escalation","state":"PUBLIC","updated":"2026-07-20T14:23:15.458Z","owner":"syncope"},{"_id":"6a555dfa4472a2da26aaea9f","ID":"CVE-2026-62354","title":"Incorrect Authorization for Parameter Context Validation Requests","state":"PUBLIC","updated":"2026-08-03T19:57:33.492Z","owner":"nifi"},{"_id":"6a55a15d4472a2da26aaeaf0","ID":"CVE-2026-62390","title":"SQL Injection Vulnerability in Catalog Cache Refresh API","state":"PUBLIC","updated":"2026-07-14T12:09:39.268Z","owner":"kylin"},{"_id":"6a55a2f94472a2da26aaeafe","ID":"CVE-2026-62391","title":"kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases","state":"PUBLIC","updated":"2026-07-31T09:20:26.636Z","owner":"kyuubi"},{"_id":"6a55a88c4472a2da26aaeb53","ID":"CVE-2026-62392","title":"OS Command Injection via Async Query API","state":"PUBLIC","updated":"2026-07-14T12:18:55.913Z","owner":"kylin"},{"_id":"6a55adfa4472a2da26aaeb94","ID":"CVE-2026-62393","title":"Improper authorization in job information retrieval","state":"PUBLIC","updated":"2026-07-14T12:19:26.389Z","owner":"kylin"},{"_id":"6a55f1c24472a2da26aaecbe","ID":"CVE-2026-62418","title":"Low-privileged authenticated SSRF in Connectors and Resources check","state":"PUBLIC","updated":"2026-07-20T14:27:00.668Z","owner":"syncope"},{"_id":"6a5649054472a2da26aaeeca","ID":"CVE-2026-62440","title":"Improper access control in Kubernetes Service (CKS) cluster manipulation","state":"PUBLIC","updated":"2026-08-21T08:23:54.134Z","owner":"cloudstack"},{"_id":"6a564b36acc2965caa347d94","ID":"CVE-2026-61483","title":"QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow DoS","state":"PUBLIC","updated":"2026-08-05T06:35:55.863Z","owner":"lucy"},{"_id":"6a564be495b8415d9039a134","ID":"CVE-2026-61484","title":"LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS","state":"PUBLIC","updated":"2026-08-05T06:42:01.626Z","owner":"lucy"},{"_id":"6a564da37c29f15fbd193beb","ID":"CVE-2026-61485","title":"Freezer/InStream deserialization bomb - unbounded allocation reading an index","state":"PUBLIC","updated":"2026-08-05T06:43:22.936Z","owner":"lucy"},{"_id":"6a564db7b389465fdfb2175b","ID":"CVE-2026-61486","title":"stack-buffer-overflow in JSON parser error reporter on malformed input","state":"PUBLIC","updated":"2026-08-05T06:44:06.722Z","owner":"lucy"},{"_id":"6a56a3d44472a2da26aaf009","ID":"CVE-2026-62764","title":"A user can trigger a graceful shutdown of services without the relevant system permissions","state":"PUBLIC","updated":"2026-07-17T08:35:41.303Z","owner":"accumulo"},{"_id":"6a56f3ab4472a2da26aaf097","ID":"CVE-2026-63015","title":"Non-template responsible persons can view template information","state":"PUBLIC","updated":"2026-08-20T15:29:24.817Z","owner":"inlong"},{"_id":"6a56f7464472a2da26aaf0c7","ID":"CVE-2026-63016","title":"Ordinary users can create new packages","state":"PUBLIC","updated":"2026-08-20T15:32:39.423Z","owner":"inlong"},{"_id":"6a56f93d4472a2da26aaf107","ID":"CVE-2026-63037","title":"Unauthenticated SQL injection in Manager OpenAPI audit alert rule list endpoint","state":"PUBLIC","updated":"2026-08-20T15:37:30.661Z","owner":"inlong"},{"_id":"6a57011f4472a2da26aaf135","ID":"CVE-2026-63038","title":"SQL Injection via String Concatenation Vulnerability Report","state":"PUBLIC","updated":"2026-08-20T15:42:40.312Z","owner":"inlong"},{"_id":"6a5702f74472a2da26aaf14d","ID":"CVE-2026-63039","title":"SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAlertRuleService","state":"PUBLIC","updated":"2026-08-20T15:43:51.402Z","owner":"inlong"},{"_id":"6a5706614472a2da26aaf1df","ID":"CVE-2026-63040","title":"Missing authorization in StreamSource forceDelete","state":"PUBLIC","updated":"2026-08-20T15:48:42.564Z","owner":"inlong"},{"_id":"6a57273c4472a2da26aaf3ea","ID":"CVE-2026-63042","title":"Missing authorization on DataNode management endpoints","state":"PUBLIC","updated":"2026-08-20T15:50:01.022Z","owner":"inlong"},{"_id":"6a572bee4472a2da26aaf402","ID":"CVE-2026-63043","title":"Agent path traversal via unvalidated file source path","state":"PUBLIC","updated":"2026-08-20T15:53:04.708Z","owner":"inlong"},{"_id":"6a5731f94472a2da26aaf42a","ID":"CVE-2026-63044","title":"Authenticated SSRF via POST /api/node/testConnection","state":"PUBLIC","updated":"2026-08-20T15:56:57.925Z","owner":"inlong"},{"_id":"6a573ae44472a2da26aaf4bc","ID":"CVE-2026-63046","title":"Agent Installer — Command Injection to RCE via Default Credentials","state":"PUBLIC","updated":"2026-08-21T08:37:55.621Z","owner":"inlong"},{"_id":"6a577dff4472a2da26aaf758","ID":"CVE-2026-63071","title":"RCE via Groovy Sandbox bypass","state":"PUBLIC","updated":"2026-07-20T14:19:15.560Z","owner":"syncope"},{"_id":"6a58db414472a2da26aafb2f","ID":"CVE-2026-63317","title":"Arbitrary Class Instantiation in GeneratorFactory via Feature Descriptor XML","state":"PUBLIC","updated":"2026-07-28T16:57:50.528Z","owner":"opennlp"},{"_id":"6a5a13a04472a2da26aafdb1","ID":"CVE-2026-63621","title":"Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy","state":"PUBLIC","updated":"2026-08-24T14:06:32.101Z","owner":"camel"},{"_id":"6a5a56474472a2da26aafe82","ID":"CVE-2026-63687","title":"JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters","state":"PUBLIC","updated":"2026-08-06T11:23:42.840Z","owner":"cxf"},{"_id":"6a5ddaa34472a2da26ab00e1","ID":"CVE-2026-64606","title":"Class-registration bypass through an auto-admitted SerializedLambda capturing interface","state":"PUBLIC","updated":"2026-07-21T10:43:47.368Z","owner":"fory"},{"_id":"6a5ddb114472a2da26ab00f1","ID":"CVE-2026-64607","title":"Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS","state":"PUBLIC","updated":"2026-08-13T08:52:34.618Z","owner":"httpcomponents"},{"_id":"6a5ddd404472a2da26ab0118","ID":"CVE-2026-64608","title":"Heap type confusion and out-of-bounds read/write in C++ compatible-mode field-skip paths","state":"PUBLIC","updated":"2026-07-21T09:34:04.322Z","owner":"fory"},{"_id":"6a5de0624472a2da26ab0182","ID":"CVE-2026-64609","title":"Out-of-Bounds Read via sun.misc.Unsafe in zero-copy java deserialization","state":"PUBLIC","updated":"2026-07-21T09:34:51.016Z","owner":"fory"},{"_id":"6a5e51924472a2da26ab040a","ID":"CVE-2026-64640","title":"register endpoint reads attacker-controlled storage location before allowed-locations validation","state":"PUBLIC","updated":"2026-08-06T09:08:05.017Z","owner":"polaris"},{"_id":"6a5f34f24472a2da26ab06a4","ID":"CVE-2026-64958","title":"Denial of service via message header attachments","state":"PUBLIC","updated":"2026-08-06T10:13:02.649Z","owner":"cxf"},{"_id":"6a5f760d4472a2da26ab07da","ID":"CVE-2026-65017","title":"Config API: team-scoped Celery broker secret disclosed to a Viewer (multi-team masking bypass)","state":"PUBLIC","updated":"2026-08-12T15:31:24.771Z","owner":"airflow"},{"_id":"6a5fa7fa4472a2da26ab07fc","ID":"CVE-2026-65100","title":"HPACK encoder desynchronizes from the decoder after a failed header encode","state":"PUBLIC","updated":"2026-07-29T09:06:12.502Z","owner":"trafficserver"},{"_id":"6a5fdd9f4472a2da26ab08b5","ID":"CVE-2026-65324","title":"HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap, allowing memory exhaustion","state":"PUBLIC","updated":"2026-07-29T08:17:42.240Z","owner":"trafficserver"},{"_id":"6a5fddcf4472a2da26ab08c9","ID":"CVE-2026-65325","title":"HTTP/2 multiplexed origin sessions are reused without certificate re-verification","state":"PUBLIC","updated":"2026-07-29T08:23:24.104Z","owner":"trafficserver"},{"_id":"6a607e56758b9363ae1877a4","ID":"CVE-2026-65432","title":"XXE via WSDL/XSD import parsing","state":"PUBLIC","updated":"2026-08-06T10:26:07.597Z","owner":"cxf"},{"_id":"6a609280758b9363ae1877c5","ID":"CVE-2026-65583","title":"Self-issued ID token claims validation skipped","state":"PUBLIC","updated":"2026-08-06T11:23:16.168Z","owner":"cxf"},{"_id":"6a60a834758b9363ae1877e3","ID":"CVE-2026-65613","title":"Webhook Deliveries Incorrect Access","state":"PUBLIC","updated":"2026-08-21T08:23:29.878Z","owner":"cloudstack"},{"_id":"6a62409a758b9363ae187dbe","ID":"CVE-2026-65942","title":"Clients accept TLS certificates issued for other hostnames","state":"PUBLIC","updated":"2026-08-10T10:21:03.965Z","owner":"ranger"},{"_id":"6a6246c9758b9363ae187dec","ID":"CVE-2026-65945","title":"Logs contain replayable JWT bearer tokens","state":"PUBLIC","updated":"2026-08-10T10:20:39.245Z","owner":"ranger"},{"_id":"6a624f4d758b9363ae187e18","ID":"CVE-2026-65948","title":"UnixAuth lacks brute-force protection","state":"PUBLIC","updated":"2026-08-10T10:20:16.518Z","owner":"ranger"},{"_id":"6a627e6f758b9363ae187e4c","ID":"CVE-2026-66053","title":"Python TSSLSocket Hostname Matcher Import","state":"PUBLIC","updated":"2026-07-27T11:18:43.366Z","owner":"thrift"},{"_id":"6a631158758b9363ae18801a","ID":"CVE-2026-66142","title":"Uncontrolled recursion in policy processing","state":"PUBLIC","updated":"2026-07-24T12:07:24.609Z","owner":"ws"},{"_id":"6a6313ba758b9363ae188040","ID":"CVE-2026-66143","title":"Missing global alternative-output budget across policy computation paths","state":"PUBLIC","updated":"2026-07-24T12:07:51.381Z","owner":"ws"},{"_id":"6a6314f5758b9363ae18805a","ID":"CVE-2026-66144","title":"Remote PolicyReference fetch lacks resource bounds","state":"PUBLIC","updated":"2026-07-24T12:08:26.736Z","owner":"ws"},{"_id":"6a6336ac758b9363ae188127","ID":"CVE-2026-66256","title":"Remote Code Execution via XStream deserialization (OpenSocial REST API)","state":"PUBLIC","updated":"2026-08-13T13:53:33.194Z","owner":"shindig"},{"_id":"6a634101758b9363ae188157","ID":"CVE-2026-66257","title":"Unbounded symbol value caching can lead to pre-authentication resource exhaustion","state":"PUBLIC","updated":"2026-08-05T05:17:56.848Z","owner":"qpid"},{"_id":"6a634c1c758b9363ae1882aa","ID":"CVE-2026-66273","title":"Type size/count handling can lead to excessive allocation pre-authentication","state":"PUBLIC","updated":"2026-08-05T05:23:28.044Z","owner":"qpid"},{"_id":"6a634c82758b9363ae1882b8","ID":"CVE-2026-66274","title":"Unbounded type nesting can lead to pre-authentication stackoverflow","state":"PUBLIC","updated":"2026-08-05T05:29:40.499Z","owner":"qpid"},{"_id":"6a634ce1758b9363ae1882be","ID":"CVE-2026-66275","title":"Incoming session flow control window can be exceeded","state":"PUBLIC","updated":"2026-08-05T05:34:44.424Z","owner":"qpid"},{"_id":"6a634d7a758b9363ae1882c4","ID":"CVE-2026-66276","title":"Unbounded disposition range handling can lead to denial of service","state":"PUBLIC","updated":"2026-08-05T05:39:26.606Z","owner":"qpid"},{"_id":"6a635161758b9363ae1882ce","ID":"CVE-2026-66277","title":"Unable to govern the maximum number of transfer frames per incoming delivery","state":"PUBLIC","updated":"2026-08-05T05:42:26.473Z","owner":"qpid"},{"_id":"6a637c57758b9363ae1884e1","ID":"CVE-2026-66299","title":"DoS via WebSocket chat example","state":"PUBLIC","updated":"2026-07-28T14:29:15.948Z","owner":"tomcat"},{"_id":"6a653369758b9363ae188a21","ID":"CVE-2026-66390","title":"crafted Link URL strings can break out of the JavaScript sequence","state":"PUBLIC","updated":"2026-07-28T14:49:11.657Z","owner":"wicket"},{"_id":"6a6534d4758b9363ae188a35","ID":"CVE-2026-66391","title":"leaked and missing CSP headers","state":"PUBLIC","updated":"2026-07-28T14:49:40.413Z","owner":"wicket"},{"_id":"6a6773222d93cf8fee312ebb","ID":"CVE-2026-66721","title":"Authorization issue with listHostTags for domain admins","state":"PUBLIC","updated":"2026-08-21T08:22:59.422Z","owner":"cloudstack"},{"_id":"6a6777682d93cf8fee312edb","ID":"CVE-2026-66722","title":"ProjectRole & ProjectRolePermission authorization issue","state":"PUBLIC","updated":"2026-08-21T08:22:35.208Z","owner":"cloudstack"},{"_id":"6a678a732d93cf8fee313088","ID":"CVE-2026-66755","title":"Arbitrary Local File Read in ISArchiveParser","state":"PUBLIC","updated":"2026-07-30T19:16:23.163Z","owner":"tika"},{"_id":"6a6791a32d93cf8fee3130dd","ID":"CVE-2026-66756","title":"unpack endpoint in tika-server allows configuration with unsecureFeatures=false","state":"PUBLIC","updated":"2026-07-30T19:18:03.257Z","owner":"tika"},{"_id":"6a679ed62d93cf8fee31314c","ID":"CVE-2026-66797","title":"Unauthorised comment creation and disclosure","state":"PUBLIC","updated":"2026-08-21T08:21:57.156Z","owner":"cloudstack"},{"_id":"6a68756c2d93cf8fee31347d","ID":"CVE-2026-66906","title":"Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir","state":"PUBLIC","updated":"2026-08-24T14:07:23.634Z","owner":"camel"},{"_id":"6a6876452d93cf8fee313495","ID":"CVE-2026-66907","title":"Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result","state":"PUBLIC","updated":"2026-08-24T14:07:53.814Z","owner":"camel"},{"_id":"6a6877502d93cf8fee3134a9","ID":"CVE-2026-66908","title":"Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted","state":"PUBLIC","updated":"2026-08-24T16:14:14.095Z","owner":"camel"},{"_id":"6a6879f32d93cf8fee3134b7","ID":"CVE-2026-66909","title":"Unsafe deserialization of inbound JMS ObjectMessage","state":"PUBLIC","updated":"2026-08-06T10:23:22.148Z","owner":"cxf"},{"_id":"6a69d0182d93cf8fee314127","ID":"CVE-2026-67260","title":"DAG-author remote code execution on the Scheduler via awaiting_input next_kwargs deserialization","state":"PUBLIC","updated":"2026-08-12T15:33:01.084Z","owner":"airflow"},{"_id":"6a6a44d12d93cf8fee314491","ID":"CVE-2026-67465","title":"Unbounded symbol value caching can lead to pre-authentication resource exhaustion","state":"PUBLIC","updated":"2026-08-05T05:21:00.415Z","owner":"qpid"},{"_id":"6a6a4ab82d93cf8fee3144bd","ID":"CVE-2026-67551","title":"Type size/count handling can lead to excessive allocation pre-authentication","state":"PUBLIC","updated":"2026-08-05T05:27:20.446Z","owner":"qpid"},{"_id":"6a6a4c6c2d93cf8fee3144f3","ID":"CVE-2026-67552","title":"Unbounded type nesting can lead to pre-authentication stackoverflow","state":"PUBLIC","updated":"2026-08-05T05:32:53.769Z","owner":"qpid"},{"_id":"6a6a4e012d93cf8fee31451a","ID":"CVE-2026-67553","title":"Incoming session flow control window can be exceeded","state":"PUBLIC","updated":"2026-08-05T05:37:23.826Z","owner":"qpid"},{"_id":"6a6a4f2d2d93cf8fee314578","ID":"CVE-2026-67554","title":"Unbounded disposition range handling can lead to denial of service","state":"PUBLIC","updated":"2026-08-05T05:41:21.799Z","owner":"qpid"},{"_id":"6a6a4ffe2d93cf8fee314597","ID":"CVE-2026-67555","title":"Unable to govern the maximum number of transfer frames per incoming delivery","state":"PUBLIC","updated":"2026-08-05T05:43:53.150Z","owner":"qpid"},{"_id":"6a6a58c62d93cf8fee3145c1","ID":"CVE-2026-67587","title":"DAG-author remote code execution on the Scheduler via a Serde `Callback` deserialization gadget","state":"PUBLIC","updated":"2026-08-12T15:32:09.019Z","owner":"airflow"},{"_id":"6a6a5e1c2d93cf8fee3145cd","ID":"CVE-2026-67588","title":"Unbounded symbol value caching can lead to pre-authentication resource exhaustion","state":"PUBLIC","updated":"2026-08-05T05:21:39.842Z","owner":"qpid"},{"_id":"6a6a5fab2d93cf8fee3145f1","ID":"CVE-2026-67589","title":"Type size/count handling can lead to excessive allocation pre-authentication","state":"PUBLIC","updated":"2026-08-05T05:28:10.043Z","owner":"qpid"},{"_id":"6a6a610a2d93cf8fee314611","ID":"CVE-2026-67590","title":"Unbounded type nesting can lead to pre-authentication stackoverflow","state":"PUBLIC","updated":"2026-08-05T05:33:34.406Z","owner":"qpid"},{"_id":"6a6a620f2d93cf8fee314639","ID":"CVE-2026-67591","title":"Incoming session flow control window can be exceeded","state":"PUBLIC","updated":"2026-08-05T05:38:21.990Z","owner":"qpid"},{"_id":"6a6a62df2d93cf8fee3146a7","ID":"CVE-2026-67592","title":"Unable to govern the maximum number of transfer frames per incoming delivery","state":"PUBLIC","updated":"2026-08-05T05:44:14.457Z","owner":"qpid"},{"_id":"6a6b0baf2d93cf8fee314846","ID":"CVE-2026-68060","title":"Type size/count handling can lead to excessive allocation pre-authentication","state":"PUBLIC","updated":"2026-08-05T05:26:23.306Z","owner":"qpid"},{"_id":"6a6b121e2d93cf8fee31487c","ID":"CVE-2026-68073","title":"Unbounded type nesting can lead to pre-authentication stack overflow","state":"PUBLIC","updated":"2026-08-05T05:32:20.617Z","owner":"qpid"},{"_id":"6a6b13872d93cf8fee3148b2","ID":"CVE-2026-68074","title":"Unbounded symbol value caching can lead to pre-authentication resource exhaustion","state":"PUBLIC","updated":"2026-08-05T05:19:51.744Z","owner":"qpid"},{"_id":"6a6b14642d93cf8fee3148ce","ID":"CVE-2026-68075","title":"Incoming session flow control window can be exceeded","state":"PUBLIC","updated":"2026-08-05T05:35:58.182Z","owner":"qpid"},{"_id":"6a6b15142d93cf8fee3148e4","ID":"CVE-2026-68076","title":"Connections test API: team-scope guard bypass resolves another team's environment Connection","state":"PUBLIC","updated":"2026-08-12T15:23:21.465Z","owner":"airflow"},{"_id":"6a6b153e2d93cf8fee3148f4","ID":"CVE-2026-68077","title":"Unbounded disposition range handling can lead to denial of service","state":"PUBLIC","updated":"2026-08-05T05:41:03.741Z","owner":"qpid"},{"_id":"6a6b16c42d93cf8fee314941","ID":"CVE-2026-68078","title":"Unable to govern the maximum number of transfer frames per incoming delivery","state":"PUBLIC","updated":"2026-08-05T05:43:32.321Z","owner":"qpid"},{"_id":"6a6b17c22d93cf8fee3149cf","ID":"CVE-2026-68079","title":"DefaultEncryptingCodeDataProvider allows unlimited authorization code replay","state":"PUBLIC","updated":"2026-08-06T11:22:56.675Z","owner":"cxf"},{"_id":"6a6b182a2d93cf8fee314a23","ID":"CVE-2026-68080","title":"Unbounded echo flow responses can lead to denial of service","state":"PUBLIC","updated":"2026-08-05T05:51:18.656Z","owner":"qpid"},{"_id":"6a6b19c82d93cf8fee314abb","ID":"CVE-2026-68481","title":"Revocation bypass in DefaultEncryptingOAuthDataProvider","state":"PUBLIC","updated":"2026-08-06T11:22:36.450Z","owner":"cxf"},{"_id":"6a6c9c382d93cf8fee3156d6","ID":"CVE-2026-68745","title":"SAML2 Signature Validation Silently Skipped for Cert-less IdP","state":"PUBLIC","updated":"2026-08-21T08:21:27.609Z","owner":"cloudstack"},{"_id":"6a6cf99a2d93cf8fee3158a5","ID":"CVE-2026-68868","title":"google Secret Manager backend: team scope is never applied, exposing every team's Connections and Variables","state":"PUBLIC","updated":"2026-08-12T10:33:13.058Z","owner":"airflow"},{"_id":"6a6cf9d62d93cf8fee3158a9","ID":"CVE-2026-68870","title":"microsoft.azure Key Vault backend: team-scope guard bypass resolves another team's Connection or Variable","state":"PUBLIC","updated":"2026-08-10T18:10:29.342Z","owner":"airflow"},{"_id":"6a6cf9fa2d93cf8fee3158ab","ID":"CVE-2026-68871","title":"yandex Lockbox backend: team-scope guard bypass resolves another team's Connection or Variable","state":"PUBLIC","updated":"2026-08-10T18:18:18.472Z","owner":"airflow"},{"_id":"6a6cfa1d2d93cf8fee3158ad","ID":"CVE-2026-68872","title":"amazon SSM / Secrets Manager backends: team-scope guard bypass resolves another team's Connection or Variable","state":"PUBLIC","updated":"2026-08-10T18:21:17.038Z","owner":"airflow"},{"_id":"6a6d66512d93cf8fee31594d","ID":"CVE-2026-68968","title":"Authorization bypass in the Backfill API through conflicting interpretations of the backfill id","state":"PUBLIC","updated":"2026-08-18T16:43:04.336Z","owner":"airflow"},{"_id":"6a6d66652d93cf8fee31594f","ID":"CVE-2026-68969","title":"Bulk Variable and Connection endpoints record secret values in the audit log in cleartext","state":"PUBLIC","updated":"2026-08-18T16:43:40.170Z","owner":"airflow"},{"_id":"6a6d667b2d93cf8fee315951","ID":"CVE-2026-68970","title":"Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UI","state":"PUBLIC","updated":"2026-08-12T15:24:51.786Z","owner":"airflow"},{"_id":"6a6d66902d93cf8fee315953","ID":"CVE-2026-68971","title":"Cross-team authorization bypass in the asset materialization and dag-run result endpoints","state":"PUBLIC","updated":"2026-08-12T15:24:09.501Z","owner":"airflow"},{"_id":"6a6e52fb2d93cf8fee315af6","ID":"CVE-2026-68979","title":"Missing Authorization for Components Referenced by Parameter Context Updates","state":"PUBLIC","updated":"2026-08-03T20:00:00.439Z","owner":"nifi"},{"_id":"6a6e534e2d93cf8fee315b00","ID":"CVE-2026-68980","title":"Authorization Bypass for Parameter Context Asset Deletion","state":"PUBLIC","updated":"2026-08-03T19:58:50.048Z","owner":"nifi"},{"_id":"6a6e539f2d93cf8fee315b0a","ID":"CVE-2026-68981","title":"Uncontrolled Resource Consumption through Decompression of HTTP Requests","state":"PUBLIC","updated":"2026-08-19T04:13:13.429Z","owner":"nifi"},{"_id":"6a70e7a54484f70561eddad3","ID":"CVE-2026-69223","title":"Server-side request forgery","state":"PUBLIC","updated":"2026-08-11T17:03:03.256Z","owner":"allura"},{"_id":"6a732d004484f70561edea66","ID":"CVE-2026-71290","title":"TLS hostname verification silently disabled on the async transport (default config, MITM)","state":"PUBLIC","updated":"2026-08-13T08:56:10.759Z","owner":"httpcomponents"},{"_id":"6a736e344484f70561edebd7","ID":"CVE-2026-71300","title":"Camel-Atmosphere-Websocket: WebSocket dispatch header injection","state":"PUBLIC","updated":"2026-08-24T16:21:12.809Z","owner":"camel"},{"_id":"6a7582b24484f70561edf47b","ID":"CVE-2026-71558","title":"Heap type confusion in C++ polymorphic smart-pointer deserialization","state":"PUBLIC","updated":"2026-08-07T08:54:53.115Z","owner":"fory"},{"_id":"6a7582d74484f70561edf485","ID":"CVE-2026-71559","title":"Uncaught panic (remote DoS) in Go meta-string decoder from untrusted metadata","state":"PUBLIC","updated":"2026-08-07T08:56:04.066Z","owner":"fory"},{"_id":"6a7582f64484f70561edf48b","ID":"CVE-2026-71560","title":"Out-of-bounds heap read in C++ struct deserializer tagged-int fast-path","state":"PUBLIC","updated":"2026-08-07T08:53:32.515Z","owner":"fory"},{"_id":"6a7b486f4484f70561ee0456","ID":"CVE-2026-73237","title":"XSS in markdown pipeline","state":"PUBLIC","updated":"2026-08-12T16:42:26.194Z","owner":"allura"},{"_id":"6a7b48814484f70561ee045c","ID":"CVE-2026-73238","title":"XSS in code display","state":"PUBLIC","updated":"2026-08-12T16:41:57.464Z","owner":"allura"},{"_id":"6a7b48be4484f70561ee045e","ID":"CVE-2026-73239","title":"Missing permission checks IDOR","state":"PUBLIC","updated":"2026-08-12T16:41:39.780Z","owner":"allura"},{"_id":"6a7b48df4484f70561ee0460","ID":"CVE-2026-73240","title":"Git command injection","state":"PUBLIC","updated":"2026-08-12T16:41:16.893Z","owner":"allura"},{"_id":"6a7dafbf4484f70561ee0ef5","ID":"CVE-2026-73631","title":"Shared parsing state in the JSON plugin","state":"PUBLIC","updated":"2026-08-15T10:38:27.083Z","owner":"struts"},{"_id":"6a7dafcd4484f70561ee0ef7","ID":"CVE-2026-73632","title":"Shared serialization state in the JSON plugin","state":"PUBLIC","updated":"2026-08-15T10:38:52.132Z","owner":"struts"},{"_id":"6a7dafde4484f70561ee0ef9","ID":"CVE-2026-73633","title":"Unbounded read of a JSON request body","state":"PUBLIC","updated":"2026-08-14T13:48:43.280Z","owner":"struts"},{"_id":"6a7dafed4484f70561ee0efb","ID":"CVE-2026-73634","title":"Unbounded read of a Content Security Policy violation report","state":"PUBLIC","updated":"2026-08-15T10:37:36.431Z","owner":"struts"},{"_id":"6a7db0044484f70561ee0efd","ID":"CVE-2026-73635","title":"Unbounded growth of localized-text caches driven by the request locale","state":"PUBLIC","updated":"2026-08-15T10:38:06.706Z","owner":"struts"},{"_id":"6a833e3d3387f094ecc1e5a6","ID":"CVE-2026-75099","title":"Unauthenticated REST disclosure","state":"PUBLIC","updated":"2026-08-24T16:42:15.529Z","owner":"allura"},{"_id":"6a8c1338518b951358fcb482","ID":"CVE-2026-78329","title":"Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes","state":"PUBLIC","updated":"2026-08-24T16:22:14.568Z","owner":"camel"}]