Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

174 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.8Apache

Critical [CVE-2026-61486] ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy

- * UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2026-61486
Unclassified
Aug 5, 2026
Critical9.8Apache

Critical [CVE-2026-61484] ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy

- * UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2026-61484
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-60023] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Deleted or pending answers could be retrieved by unauthorized users through the single-answer read path when the parent question remained visible, exposing answer content that should not have been accessible. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

CVE-2026-60023
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-48911] Insufficient Verification of Data Authenticity vulnerability in Apache Answer

Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing authorization check in the external-login email binding flow allows unauthenticated attackers to take over arbitrary user accounts by tricking victims into clicking a crafted confirmation link. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

CVE-2026-48911
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-48834] Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer

Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

CVE-2026-48834
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-61485] ** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy

- * UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2026-61485
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-61483] ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy

- * UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2026-61483
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-67592] Apache Qpid ProtonJ2: It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue

CVE-2026-67592
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-67590] Apache Qpid ProtonJ2: pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.

CVE-2026-67590
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-67552] Apache Qpid Proton-Dotnet: pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue

CVE-2026-67552
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-68073] Apache Qpid Broker-J: pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.

CVE-2026-68073
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-66274] Apache Qpid Proton-J: pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.

CVE-2026-66274
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-67589] Apache Qpid ProtonJ2: pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.

CVE-2026-67589
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-67551] Apache Qpid Proton-Dotnet: pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service

pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.

CVE-2026-67551
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-68060] Apache Qpid Broker-J: pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.

CVE-2026-68060
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-66273] Apache Qpid Proton-J: pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.

CVE-2026-66273
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-67588] Apache Qpid ProtonJ2: pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.

CVE-2026-67588
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-67465] Apache Qpid Proton-Dotnet: pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.

CVE-2026-67465
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-68074] Apache Qpid Broker-J: pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.

CVE-2026-68074
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-66257] Apache Qpid Proton-J: pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.

CVE-2026-66257
Unclassified
Aug 5, 2026