Apache Latest High & Critical Vulnerabilities
Latest High & Critical vulnerabilities published by apache
Vulnerability Published:
🗓️ Published
- Anytime
Sort By:
🗓️ Published Date
- Descending
Apache CXF: No restriction on attachment headers per message
CVE-2026-50645ApacheApache Cxf7.5HIGHApache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImpl
CVE-2026-50633ApacheApache Cxf8.1HIGHApache CXF: JNDI Injection Vulnerability in JMSConfigFactory
CVE-2026-50632ApacheApache Cxf8.1HIGHApache CXF: OAuth2: TOCTOU Race Condition in Refresh Token Processing
CVE-2026-50631ApacheApache Cxf7.4HIGHApache OFBiz: Privilege Escalation via updateOrRemove Authorization Bypass
CVE-2026-47342ApacheApache Ofbiz8.8HIGHApache OFBiz: DataResource Low-Privileged Authenticated FreeMarker Template Injection Leads to Remote Code Execution
CVE-2026-50223ApacheApache Ofbiz8.8HIGHApache Answer: AdminToken not invalidated after admin deactivation
CVE-2026-25700ApacheApache Answer7.2HIGHApache HTTP Server: mod_http2 denial of service
CVE-2026-49975ApacheApache Http Server📈👾🟡7.5HIGHApache HTTP Server: mod_http2 memory corruption when file handles exhausted
CVE-2026-48913ApacheApache Http Server7.3HIGHApache HTTP Server: mod_xml2enc heap overflow
CVE-2026-42536ApacheApache Http Server7.5HIGHApache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request`
CVE-2026-44185ApacheApache Http Server7.3HIGHApache HTTP Server: mod_proxy_html buffer overflow
CVE-2026-34355ApacheApache Http Server7.5HIGHApache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow
CVE-2026-44631ApacheApache Http Server9.8CRITICALApache HTTP Server: mod_dav_fs protected directory access
CVE-2026-42535ApacheApache Http Server9.1CRITICALApache HTTP Server: ProxyPassReverseCookieMap buffer overflow
CVE-2026-34356ApacheApache Http Server7.5HIGHApache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp
CVE-2026-44186ApacheApache Http Server7.3HIGHApache HTTP Server: mod_ldap per-dir use-after-free
CVE-2026-29167ApacheApache Http Server9.8CRITICALCordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews
CVE-2026-47430ApacheCordova Plugin Inappbr...9.5CRITICALApache Fory: Java ReplaceResolverSerializer deserialization checks bypass
CVE-2026-50076ApacheApache Fory9.1CRITICALFilter Bypass Vulnerability in Apache Product
CVE-2026-47065ApacheApache Mina9.8CRITICALPath Traversal Vulnerability in Apache MINA SSHD Affecting Git Operations
CVE-2026-48827ApacheApache Mina Sshd7.1HIGHBasic Authentication Flaw in Apache Solr Affects User Security
CVE-2026-44825ApacheApache Solr8.1HIGHDenial of Service Vulnerability in Apache Fluss by The Apache Software Foundation
CVE-2026-49361ApacheApache Fluss (incubating)7.5HIGHLogin Redirect Bypass Vulnerability in Apache Airflow
CVE-2026-40961ApacheApache Airflow7.2HIGHUnauthorized Task Mutation in Apache Airflow Affects Multiple Deployments
CVE-2026-41084ApacheApache Airflow7.5HIGH