CVE-2026-92414 - apache jackrabbit
Versions of Apache Jackrabbit from 2.20.0 up to 2.20.17, 2.22.0 to 2.22.4, and 2.23.0 to 2.23.5 may let a user reuse another person's logged‑in…
Too many irrelevant or confusing CVEs? Use stackflag.com

CVE-2026-92414 - apache jackrabbit
Versions of Apache Jackrabbit from 2.20.0 up to 2.20.17, 2.22.0 to 2.22.4, and 2.23.0 to 2.23.5 may let a user reuse another person's logged‑in…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-97720 - apache impala
The web server used by Impala’s executors can be tricked into accepting any login token, letting an attacker view or interact with the service when token…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-104711 - apache struts
Versions of Apache Struts that use the old RESTful action mapper can be tricked by a specially crafted web request to run arbitrary code on the server. This risk…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-85086 - thrift
The Perl version of Apache Thrift can fail to properly check security certificates and starts with unsafe default settings. This could let attackers pretend to be…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-83632 - thrift
Versions of Apache Thrift older than 0.25.0 can be tricked into using unlimited memory, which can cause the service to stop working or become vulnerable to attacks.…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-91135 - thrift
Versions of Apache Thrift older than 0.25 that use the ZLIB compression option can write beyond the allocated memory area, potentially causing crashes or allowing an…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-91048 - apache karaf
In Apache Karaf, a missing permission file means even a user with only view rights can execute all JDBC‑related shell commands. One of those commands can store a…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-91012 - apache karaf
Apache Karaf lets users with the manager role change any configuration file the service can write to, including files that control admin permissions. By supplying…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-82384 - apache roller
Apache Roller version 6.1.5 lets anyone send specially crafted XML-RPC messages that are processed before anyone logs in. This can let an attacker make the server…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-82377 - apache roller
Apache Roller version 6.1.5 lets anyone who can log in use the old XML‑RPC interface to view, change or delete posts that belong to other blogs, because it does…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-82378 - apache roller
If your Roller site uses a site‑wide OAuth connection, an attacker who discovers a pending request token can attach that token to any user account, even an…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-92609 - apache qpid broker-j
When a user logs into the management interface of Apache Qpid Broker-J, the system keeps the same session identifier instead of creating a new one. This allows a remote…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-86350 - apache tomcat
Versions of Apache Tomcat 9.0.118‑9.0.121, 10.1.55‑10.1.59, and 11.0.22‑11.0.25 can misinterpret incoming HTTP/2 traffic, causing request headers to…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-86248 - apache tomcat
Certain versions of Apache Tomcat (11.0.0-M14 to 11.0.25, 10.1.22 to 10.1.59, and 9.0.92 to 9.0.121) can incorrectly allow client certificate…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-76183 - apache tomcat
Apache Tomcat versions up to 11.0.25, 10.1.59, and 9.0.121 let users bypass security checks on WebSocket connections, potentially letting anyone…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-82331 - apache buildstream
The tar handling part of Apache BuildStream may follow symbolic links inside a malicious source archive and create or overwrite files on the…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachebuildstream #apachefoundation #Debian12 #CVE #infosec
CVE-2026-86473 - apache airflow
When users sign out of Apache Airflow using a bearer token in the Authorization header, the system only clears the browser cookie and leaves the token active…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-94301 - apache mina
Versions 2.0.30, 2.0.29, 2.1.14 and 2.1.13 of Apache MINA do not include a fix that blocks a way to bypass security checks using Java proxy objects. This means an…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-68536 - apache myfaces
Certain versions of Apache MyFaces can be told to access internal network locations or read files on the server, which could expose sensitive information. This…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-76187 - apache airflow keycloak provider
If your Airflow installation uses the Keycloak authentication manager and shares the Keycloak realm with other applications, any of those applications can…
Too many irrelevant or confusing CVEs? Use stackflag.com