CVE Vulnerability Database

Search and browse 397,836 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-9024HIGH8.7A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer...
CVE-2026-8474MEDIUM5.3A vulnerability was discovered on Stormshield Network Security  * 4.3.0 to 4.3.41,  * 4.8.0 to 4.8.15,  * ...
CVE-2026-7858CRITICAL9.8A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic ...
CVE-2026-49361HIGH7.5Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maxi...
CVE-2026-49298HIGH8.8A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution...
CVE-2026-49270MEDIUM5.9Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache Acti...
CVE-2026-49267MEDIUM5.9Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections wi...
CVE-2026-49157HIGH8.8Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from...
CVE-2026-48827HIGH7.1Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receiv...
CVE-2026-48726MEDIUM6.5A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked lo...
CVE-2026-46764MEDIUM4.3The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched audit-log rows directly b...
CVE-2026-46605MEDIUM4.3Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections t...
CVE-2026-45505HIGH8.8Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br...
CVE-2026-45426LOW3.1Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log-server JWT issued f...
CVE-2026-45360HIGH7.3Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported ...
CVE-2026-44825CRITICAL9.8Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 throug...
CVE-2026-42588HIGH8.1Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br...
CVE-2026-42360MEDIUM6.5A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` /...
CVE-2026-42359HIGH8.8A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user wit...
CVE-2026-42358MEDIUM6.5A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names l...
CVE-2026-42253MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, A...
CVE-2026-42252CRITICAL9.1Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") show...
CVE-2026-41084HIGH7.5A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstance...
CVE-2026-41017MEDIUM5.9Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Ai...
CVE-2026-41014MEDIUM4.3The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization...