CVE Watchtower

Advanced Threat Data Export

Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.

Data export is locked. Upgrade your package to enable filtering and downloading.

πŸ”” Premium Features
πŸ” Filter Threats
Title
SeverityEPSS (30-Day)
PoCActively ExploitedSourceDate
CVE-2026-48726
A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked logout in the UI: the logou...
MEDIUMπŸ”’ LOCKED??????????NVD2 days ago
CVE-2026-46764
The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched audit-log rows directly by numeric ID after only the ge...
MEDIUMπŸ”’ LOCKED??????????NVD2 days ago
CVE-2026-46605
Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations...
MEDIUMπŸ”’ LOCKED??????????NVD2 days ago
CVE-2026-45505
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveM...
HIGHπŸ”’ LOCKED??????????NVD2 days ago
CVE-2026-45426
Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log-server JWT issued for at least one Dag. Apache Ai...
LOWπŸ”’ LOCKED??????????NVD2 days ago
CVE-2026-45360
Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported and dispatched arbitrary ...
HIGHπŸ”’ LOCKED??????????NVD2 days ago
CVE-2026-44825
Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a r...
HIGHπŸ”’ LOCKED??????????NVD2 days ago
CVE-2026-42588
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveM...
HIGHπŸ”’ LOCKED??????????NVD2 days ago
CVE-2026-42360
A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` / `token` / `secret` / `ap...
MEDIUMπŸ”’ LOCKED??????????NVD2 days ago
CVE-2026-42359
A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user with XCom write permission o...
HIGHπŸ”’ LOCKED??????????NVD2 days ago
CVE-2026-42358
A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names like `password`, `token`, ...
MEDIUMπŸ”’ LOCKED??????????NVD2 days ago
CVE-2026-42253
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. ...
MEDIUMπŸ”’ LOCKED??????????NVD2 days ago
CVE-2026-42252
Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a verbatim `...
CRITICALπŸ”’ LOCKED??????????NVD2 days ago
CVE-2026-41084
A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstances`) evaluated authorizati...
HIGHπŸ”’ LOCKED??????????NVD2 days ago
CVE-2026-41017
Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Airflow API server behind a...
MEDIUMπŸ”’ LOCKED??????????NVD2 days ago
CVE-2026-41014
The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization. An authenticated UI/API user...
MEDIUMπŸ”’ LOCKED??????????NVD2 days ago
CVE-2026-40963
The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking whether the caller had read pe...
LOWπŸ”’ LOCKED??????????NVD2 days ago
CVE-2026-40961
A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe_url` check, enabling redirect...
HIGHπŸ”’ LOCKED??????????NVD2 days ago
CVE-2026-40861
A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable by the API server process ...
MEDIUMπŸ”’ LOCKED??????????NVD2 days ago
CVE-2026-10517
A flaw was found in Clair. The fetcher component makes outbound HTTP requests to attacker-supplied URIs from manifest layer descriptors without IP or ...
MEDIUMπŸ”’ LOCKED??????????NVD2 days ago