Where
AND
-Infinity
0

Apache Shindig CommonApache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via XStream deserialization (OpenSocial REST API)

Risk 70
Severity
7.2
First published (updated )

apache-airflowApache Airflow: Unguarded import_string() of airflow_exc_ser / base_exc_ser exception nodes in BaseSerialization.deserialize enables DAG-author RCE on Scheduler / API Server

Risk 79
Severity
8.8
First published (updated )

Apache AirflowApache Airflow: DAG-author remote code execution on the Scheduler via awaiting_input next_kwargs deserialization

Risk 51
Severity
7.3
First published (updated )

Apache Apache AirflowApache Airflow: DAG-author remote code execution on the Scheduler via a Serde `Callback` deserialization gadget

Risk 79
Severity
8.8
First published (updated )

Apache AirflowApache Airflow: Authorization bypass in the Backfill API through conflicting interpretations of the backfill id

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache Apache TapestryApache Tapestry: Possible classpath file download through URL manipulation

Risk 43
Severity
7.5
First published (updated )

Apache RangerApache Ranger: Download APIs expose plugin data without authentication

Risk 43
Severity
7.5
First published (updated )

Apache Ranger ClientApache Ranger: Clients accept TLS certificates issued for other hostnames

Risk 43
Severity
7.5
First published (updated )

Apache RangerApache Ranger: UnixAuth lacks brute-force protection

Risk 51
Severity
7.3
First published (updated )

Apache IoTDBApache IoTDB: RPC service denial of service via unchecked Thrift string length

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache ForyApache Fory: Uncaught panic (remote DoS) in Go meta-string decoder from untrusted metadata

Risk 43
Severity
7.5
First published (updated )

Apache apr-utilApache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack

Risk 46
Severity
7.5
First published (updated )

Apache Apache Portable Runtime UtilityApache Portable Runtime Utility: Heap buffer overflow in APR redis client

Risk 46
Severity
7.5
First published (updated )

Apache Apache Portable Runtime UtilityApache Portable Runtime Utility: Heap buffer overflow in APR memcached client

Risk 46
Severity
7.5
First published (updated )

Apache CXFApache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider

Risk 79
Severity
8.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache CXFApache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider

Risk 46
Severity
7.5
First published (updated )

Apache CXFApache CXF: XXE via WSDL/XSD import parsing

Risk 46
Severity
7.5
First published (updated )

Apache CXFApache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow

Risk 79
Severity
8.1
First published (updated )

Apache CXFApache CXF: Denial of service via message header attachments

Risk 46
Severity
7.5
First published (updated )

Apache CXFApache CXF: No default restriction on the amount of form parameters per message

Risk 46
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache CXFApache CXF: Denial of Service attack via large attachments

Risk 46
Severity
7.5
First published (updated )

Apache AnswerApache Answer: Unauthorized disclosure of deleted or pending answer content

Risk 46
Severity
7.5
First published (updated )

Apache AnswerApache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow

Risk 46
Severity
7.5
First published (updated )

Apache Apache AnswerApache Answer: Denial of service via crafted Accept-Language header parsing

Risk 46
Severity
7.5
First published (updated )

Apache LucyApache Lucy: Freezer/InStream deserialization bomb - unbounded allocation reading an index

Risk 46
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache LucyApache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow DoS

Risk 46
Severity
7.5
First published (updated )

Apache Qpid ProtonJ2Apache Qpid ProtonJ2: Unable to govern the maximum number of transfer frames per incoming delivery

Risk 46
Severity
7.5
First published (updated )

Apache Qpid ProtonJ2Apache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication stackoverflow

Risk 46
Severity
7.5
First published (updated )

Apache Qpid ProtonJ2Apache Qpid ProtonJ2: Type size/count handling can lead to excessive allocation pre-authentication

Risk 46
Severity
7.5
First published (updated )

Apache Qpid ProtonJ2Apache Qpid ProtonJ2: Unbounded symbol value caching can lead to pre-authentication resource exhaustion

Risk 46
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203