Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

911
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1 - 17 of 17 CVEs
CVE-2026-46586 HIGH - 7.3

Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.0...

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-45434 HIGH - 8.8

Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-45187 MEDIUM - 6.5

Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-41919 CRITICAL - 9.1

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-35086 MEDIUM - 6.5

Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-31986 CRITICAL - 9.1

Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-31910 HIGH - 7.5

Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-31909 HIGH - 7.5

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-31906 MEDIUM - 6.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-31388 MEDIUM - 5.3

Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-31387 MEDIUM - 5.3

Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-31380 MEDIUM - 6.5

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-31379 MEDIUM - 6.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue aff...

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-31378 MEDIUM - 6.5

Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-29226 HIGH - 7.3

Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-29220 MEDIUM - 6.5

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-29207 MEDIUM - 6.5

Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. Please note that in the updated version, "Data Resource" re...

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD