| Sep 30 | Apache WSS4J: integer overflow High7.5Sep 30 | High7.5 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: insufficient authenticity check Critical9.1Sep 30 | Critical9.1 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: protection mechanism failure High7.5Sep 30 | High7.5 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: authentication bypass by spoofing Medium4.8Sep 30 | Medium4.8 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: expression injection Critical9.1Sep 30 | Critical9.1 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: authentication bypass Critical9.8Sep 30 | Critical9.8 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: resource exhaustion High7.5Sep 30 | High7.5 | 4.0.2+2 more |
| Sep 30 | Apache MINA SSHD: resource exhaustion Medium6.5Sep 30 | Medium6.5 | 2.20.0+1 more |
| Sep 30 | A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache... Critical9.1Sep 30 | Critical9.1 | 2.20.0+1 more |
| Sep 30 | Apache MINA SSHD: authentication bypass Critical9.1Sep 30 | Critical9.1 | 2.20.0+1 more |
| Sep 30 | Apache MINA SSHD: authentication bypass Critical9.1Sep 30 | Critical9.1 | 2.20.0+1 more |
| Sep 30 | Apache MINA SSHD: authentication bypass High8.1Sep 30 | High8.1 | 2.20.0+1 more |
| Sep 30 | Apache MINA SSHD: improper input validation Medium6.5Sep 30 | Medium6.5 | 2.20.0+1 more |
| Sep 30 | Apache MINA SSHD: resource exhaustion Medium6.5Sep 30 | Medium6.5 | 2.20.0+1 more |
| Sep 30 | Apache MINA SSHD: resource exhaustion High7.5Sep 30 | High7.5 | 2.20.0+1 more |
| Sep 30 | Apache PLC4X: denial of service High8.7Sep 30 | High8.7 | 1.0.0+1 more |
| Sep 30 | Apache PLC4X: integer overflow High8.7Sep 30 | High8.7 | 1.0.0 |
| Sep 30 | Apache PLC4X: improper array index validation High8.5Sep 30 | High8.5 | 1.0.0+2 more |
| Sep 30 | Apache PLC4X: improper certificate validation Critical9.2Sep 30 | Critical9.2 | 1.0.0 |
| Sep 29 | Apache Polaris: missing authorization High8.1Sep 29 | High8.1 | 1.8.0 |
| Sep 29 | Apache DolphinScheduler: improper authorization Medium4.3Sep 29 | Medium4.3 | 3.4.3 |
| Sep 29 | Apache DolphinScheduler: missing authorization Medium6.5Sep 29 | Medium6.5 | 3.4.3 |
| Sep 29 | Apache DolphinScheduler: authentication bypass Medium5.3Sep 29 | Medium5.3 | 3.4.3 |
| Sep 29 | Apache DolphinScheduler: improper authorization Medium4.3Sep 29 | Medium4.3 | 3.4.3 |
| Sep 29 | Apache DolphinScheduler: improper authorization Medium4.3Sep 29 | Medium4.3 | 3.4.3 |
| Sep 29 | Apache DolphinScheduler: command injection High8.8Sep 29 | High8.8 | 3.4.3 |
| Sep 29 | Apache DolphinScheduler: missing authentication Medium6.5Sep 29 | Medium6.5 | 3.4.3 |
| Sep 29 | Apache XMLSchema: denial of service High7.5Sep 29 | High7.5 | 2.3.3 |
| Sep 29 | Apache XMLSchema: denial of service High7.5Sep 29 | High7.5 | 2.3.3 |
| Sep 29 | Apache XMLSchema: denial of service High7.5Sep 29 | High7.5 | 2.3.3 |
| Sep 29 | Apache Airflow Teradata provider: secrets in logs Medium6.5Sep 29 | Medium6.5 | 3.7.0 |
| Sep 29 | Apache Airflow's Google provider built Google Drive search expressions by... Medium4.3Sep 29 | Medium4.3 | 22.6.0 |
| Sep 29 | Apache Airflow Snowflake provider: weakly protected credentials Medium6.3Sep 29 | Medium6.3 | 6.18.0 |
| Sep 29 | Apache Airflow Teradata provider: SQL injection Medium6.3Sep 29 | Medium6.3 | 3.7.0 |
| Sep 29 | Apache Karaf: code execution Critical9.8Sep 29 | Critical9.8 | 4.4.12 |
| Sep 29 | Apache Karaf: missing authorization Medium6.3Sep 29 | Medium6.3 | 4.4.12 |
| Sep 29 | Apache Karaf: improper access control High8.8Sep 29 | High8.8 | 4.4.12 |
| Sep 29 | Apache Karaf: path traversal Critical9.8Sep 29 | Critical9.8 | 4.4.12 |
| Sep 28 | Apache Karaf: command injection High8.8Sep 28 | High8.8 | 4.4.12 |
| Sep 28 | LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and... High7.3Sep 28 | High7.3 | 4.4.12 |
| Sep 28 | Apache Roller: cross-site scripting Medium6.1Sep 28 | Medium6.1 | No fix yet |
| Sep 28 | Apache Roller: cross-site scripting Medium6.1Sep 28 | Medium6.1 | No fix yet |
| Sep 28 | Apache Roller: cross-site scripting Medium6.1Sep 28 | Medium6.1 | No fix yet |
| Sep 28 | Apache Roller: missing authentication High8.2Sep 28 | High8.2 | No fix yet |
| Sep 28 | Apache Roller: unsafe deserialization Critical9.8Sep 28 | Critical9.8 | No fix yet |
| Sep 28 | Apache Roller: information disclosure Medium6.5Sep 28 | Medium6.5 | No fix yet |
| Sep 28 | Apache Roller: XML external entity High7.7Sep 28 | High7.7 | No fix yet |
| Sep 28 | Apache Roller: cross-site scripting Medium5.4Sep 28 | Medium5.4 | No fix yet |
| Sep 28 | Apache Roller: cross-site scripting Medium6.1Sep 28 | Medium6.1 | No fix yet |
| Sep 28 | Apache Roller: cross-site scripting Medium6.1Sep 28 | Medium6.1 | No fix yet |
| Sep 28 | Apache Roller: server-side request forgery High7.4Sep 28 | High7.4 | No fix yet |
| Sep 28 | Apache Roller: XML external entity High7.7Sep 28 | High7.7 | No fix yet |
| Sep 28 | Apache Roller: missing authorization Critical9.9Sep 28 | Critical9.9 | No fix yet |
| Sep 28 | Apache Roller: improper authorization Critical9.0Sep 28 | Critical9.0 | No fix yet |
| Sep 28 | Apache Roller: authentication bypass High7.7Sep 28 | High7.7 | No fix yet |
| Sep 28 | Apache Roller: cross-site request forgery High8.1Sep 28 | High8.1 | No fix yet |
| Sep 28 | Apache Roller: cross-site scripting Medium5.4Sep 28 | Medium5.4 | No fix yet |
| Sep 28 | Apache Roller: insecure direct object reference High7.7Sep 28 | High7.7 | No fix yet |
| Sep 25 | Apache Qpid Broker-J: denial of service High7.5Sep 25 | High7.5 | No fix yet |
| Sep 23 | Improper Check for Certificate Revocation vulnerability in Apache Tomcat Medium6.5Sep 23 | Medium6.5 | No fix yet |