VulnScope — package-centric CVE lookup- HIGH8.8CVE-2026-34197⚠ KEVEPSS 83.5%Authenticated Apache ActiveMQ Broker and Apache ActiveMQ users could perform RCE via Jolokia MBeans
- HIGH8.2⚠ KEVEPSS 81.4%GeoServer is vulnerable to Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
- HIGH8.0⚠ KEVEPSS 0.60%Git allows arbitrary code execution through broken config quoting
- HIGH8.1⚠ KEVEPSS 70.8%freetype - security update
- CRITICAL9.8⚠ KEVEPSS 94.1%tomcat10 - security update
- CRITICAL9.8⚠ KEVEPSS 93.7%XWiki Platform allows remote code execution as guest via SolrSearchMacros request
- CRITICAL9.8⚠ KEVEPSS 94.4%Remote Code Execution (RCE) vulnerability in geoserver
- CRITICAL9.1⚠ KEVEPSS 93.9%Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
- CRITICAL9.8⚠ KEVEPSS 94.3%Apache HugeGraph-Server: Command execution in gremlin
- CRITICAL9.8⚠ KEVEPSS 94.5%Arbitrary file read vulnerability through the Jenkins CLI can lead to RCE
- CRITICAL10.0⚠ KEVEPSS 94.4%Apache ActiveMQ is vulnerable to Remote Code Execution
- MEDIUM5.3⚠ KEVEPSS 94.4%nghttp2 - security update
- CRITICAL9.8⚠ KEVEPSS 94.0%Improper Control of Generation of Code ('Code Injection') in jai-ext
- HIGH8.8⚠ KEVEPSS 93.3%thunderbird - security update
- CRITICAL9.8⚠ KEVEPSS 94.4%Apache RocketMQ may have remote code execution vulnerability when using update configuration function
- HIGH8.6⚠ KEVEPSS 94.4%Administration Console authentication bypass in openfire xmppserver
- HIGH7.5⚠ KEVEPSS 93.9%ZK Framework vulnerable to malicious POST
- HIGH8.8⚠ KEVEPSS 93.5%Apache Spark UI can allow impersonation if ACLs enabled
- CRITICAL9.8⚠ KEVEPSS 94.4%Deserialization of Untrusted Data in Liferay Portal
- HIGH8.1⚠ KEVEPSS 85.3%Elasticsearch Improper Access Control vulnerability
- —⚠ KEVEPSS 92.3%Improper Access Control in Elasticsearch
- CRITICAL9.8⚠ KEVEPSS 94.3%Improper Access Control in Apache Shiro
- CRITICAL9.8⚠ KEVEPSS 94.3%Improper Input Validation in Apache ActiveMQ
- HIGH8.1⚠ KEVEPSS 94.4%tomcat7 - security update
- HIGH7.5⚠ KEVEPSS 39.7%Jenkins discloses project names via fingerprints