| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-3203 | Buffer Over-read in Wireshark | Wireshark Foundation | Wireshark | Medium | 5.5 | 2026-02-25 14:36:01 | Deep Dive |
| CVE-2026-3202 | NULL Pointer Dereference in Wireshark | Wireshark Foundation | Wireshark | Medium | 4.7 | 2026-02-25 14:35:56 | Deep Dive |
| CVE-2026-3201 | Improperly Controlled Sequential Memory Allocation in Wireshark | Wireshark Foundation | Wireshark | Medium | 4.7 | 2026-02-25 14:35:51 | Deep Dive |
| CVE-2026-23969 | Apache Superset: Exposure of Sensitive Information via Incomplete ClickHouse Function Filtering | Apache Software Foundation | Apache Superset | 中危 | - | 2026-02-24 13:02:55 | Deep Dive |
| CVE-2026-23980 | Apache Superset: Improper Neutralization of Special Elements used in a SQL Command | Apache Software Foundation | Apache Superset | 中危 | - | 2026-02-24 12:54:10 | Deep Dive |
| CVE-2026-23982 | Apache Superset: Improper Authorization in Dataset Creation Allows Access Control Bypass | Apache Software Foundation | Apache Superset | 中危 | - | 2026-02-24 12:52:44 | Deep Dive |
| CVE-2026-23983 | Apache Superset: Sensitive Data Exposure via REST API (disabled by default) | Apache Software Foundation | Apache Superset | 中危 | - | 2026-02-24 12:52:11 | Deep Dive |
| CVE-2026-23984 | Apache Superset: SQLLab Read-Only Bypass on PostgreSQL | Apache Software Foundation | Apache Superset | 中危 | - | 2026-02-24 12:51:07 | Deep Dive |
| CVE-2025-27555 | Apache Airflow: Connection Secrets not masked in UI when Connection are added via Airflow cli | Apache Software Foundation | Apache Airflow | - | - | 2026-02-24 10:10:00 | Deep Dive |
| CVE-2024-56373 | Apache Airflow: SSTI to Code Execution in Airflow through Shared DB Information | Apache Software Foundation | Apache Airflow | - | - | 2026-02-24 10:06:41 | Deep Dive |
| CVE-2026-25747 | Apache Camel LevelDB: Deserialization of Untrusted Data in Camel LevelDB | Apache Software Foundation | Apache Camel LevelDB | - | - | 2026-02-23 08:45:46 | Deep Dive |
| CVE-2026-23552 | Apache Camel: Camel-Keycloak: Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy | Apache Software Foundation | Apache Camel | - | - | 2026-02-23 08:45:36 | Deep Dive |
| CVE-2025-65995 | Apache Airflow: Disclosure of secrets to UI via kwargs | Apache Software Foundation | Apache Airflow | - | - | 2026-02-21 02:14:26 | Deep Dive |
| CVE-2026-24734 | Apache Tomcat Native, Apache Tomcat: OCSP revocation bypass | Apache Software Foundation | Apache Tomcat Native | - | - | 2026-02-17 18:53:12 | Deep Dive |
| CVE-2026-24733 | Apache Tomcat: Security constraint bypass with HTTP/0.9 | Apache Software Foundation | Apache Tomcat | - | - | 2026-02-17 18:50:44 | Deep Dive |
| CVE-2025-66614 | Apache Tomcat: Client certificate verification bypass due to virtual host mapping | Apache Software Foundation | Apache Tomcat | - | - | 2026-02-17 18:48:31 | Deep Dive |
| CVE-2026-25087 | Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering | Apache Software Foundation | Apache Arrow | - | - | 2026-02-17 13:18:25 | Deep Dive |
| CVE-2026-25903 | Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates | Apache Software Foundation | Apache NiFi | - | - | 2026-02-17 09:54:44 | Deep Dive |
| CVE-2025-33042 | Apache Avro Java SDK: Code injection on Java generated code | Apache Software Foundation | Apache Avro Java SDK | 中危 | - | 2026-02-13 11:47:04 | Deep Dive |
| CVE-2026-24343 | Apache HertzBeat: Uncontrolled Resource Consumption via Crafted XPath Expressions | Apache Software Foundation | Apache HertzBeat | - | - | 2026-02-10 09:28:52 | Deep Dive |