Where
AND
-Infinity
0

Apache CamelApache Camel Mail: The mail producer applied attacker-supplied message headers as JavaMail session properties, allowing an attacker to influence SMTP parameters

Risk 20
Severity
3.7
First published (updated )

Apache KvrocksApache Kvrocks: Replication Fullsync Path Traversal via Unvalidated Filename Handling

Risk 49
Severity
2.4
First published (updated )

Apache Apache ShiroApache Shiro: Remember-me cookie isn't checked for expiry on the server

Risk 15
Severity
2
First published (updated )

Apache nifiApache NiFi: Incorrect Authorization for Configuration Verification Requests

Risk 48
Severity
2.3
First published (updated )

Apache APISIXApache APISIX: cas-auth login CSRF / session injection issue

Risk 69
Severity
2.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache APISIXApache APISIX: Cas-auth Host header influence on CAS service URL

Risk 46
Severity
2.1
First published (updated )

Apache APISIXApache APISIX: Identity spoofing issue in APISIX opa plugin

Risk 36
Severity
2.3
First published (updated )

Apache APISIXApache APISIX: Cas-auth plugin open redirect via unsanitized cookie value

Risk 40
Severity
2.1
First published (updated )

Apache Apache APISIXApache APISIX: wolf-rbac plugin Identity Spoofing

Risk 31
Severity
2.3
First published (updated )

pypi/apache-airflowApache Airflow: Log server JWT authorization bypass via Python lstrip() character stripping allows cross-Dag log access

Risk 18
Severity
3.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pypi/apache-airflowApache Airflow: DAG authorization bypass on /ui/structure/structure_data

Risk 18
Severity
3.1
First published (updated )

Apache TomcatObservable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue …

Risk 5
Severity
1
First published (updated )

Apache TomcatApache Tomcat: AJP secret compared in non-constant time

Risk 22
Severity
3.7
First published (updated )

Apache HTTP ServerNull Pointer Dereference

Risk 5
Severity
1
First published (updated )

Apache MINAApache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes…

Risk 5
Severity
1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache Apache AirflowApache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1

Risk 22
Severity
3.7
First published (updated )

Apache TomcatImproper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache …

Risk 5
Severity
1
First published (updated )

Apache TomcatInsertion of Sensitive Information into Log File vulnerability in the cloud membership for clusterin…

Risk 5
Severity
1
First published (updated )

Apache TomcatOccasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via th…

Risk 5
Severity
1
First published (updated )

Apache TomcatInconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Ap…

Risk 5
Severity
1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache ARTEMISApache Artemis, Apache ActiveMQ Artemis: Temporary address auto-created for OpenWire consumer without createAddress permission

Risk 24
Severity
2.3
First published (updated )

Apache TomcatInput Validation

Risk 5
Severity
1
First published (updated )

Apache ShiroApache Shiro: Brute force attack possible to determine valid user names

Risk 11
Severity
2.5
EPSS
0.01%
First published (updated )

Apache Karaf DecanterApache Karaf: Decanter log-socket collector has deserialization vulnerability

Risk 15
Severity
3.7
EPSS
0.03%
First published (updated )

Apache NimBLEApache Mynewt NimBLE: Out-of-Bounds Write Vulnerability in NimBLE HCI H4 driver

Risk 18
Severity
3.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache Commons LangUncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang…

Risk 5
Severity
1
First published (updated )

Apache TomcatInteger Overflow

Risk 5
Severity
1
First published (updated )

Apache TomcatAuthentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using…

Risk 5
Severity
1
First published (updated )

Apache TomcatImproper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a …

Risk 5
Severity
1
First published (updated )

Apache ActiveMQ ArtemisApache ActiveMQ Artemis: Address routing-type can be updated by user without the createAddress permission

Risk 24
Severity
2.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203