Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Linkis CRITICAL 9.8
CVE-2023-29216

In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source and malicious parameters to co…

Fix: after 1.3.1
Fix from $2,300 2023-04-10
Linkis CRITICAL 9.1
CVE-2023-27987

In Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy for attackers to obtain the de…

Fix: after 1.3.1
Fix from $2,300 2023-04-10
Linkis CRITICAL 9.8
CVE-2023-27602

In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recomme…

Fix: after 1.3.1
Fix from $2,300 2023-04-10
Airflow Hive Provider CRITICAL 9.8
CVE-2023-28706

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects…

Fix: 6.0.0+
Fix from $2,300 2023-04-07
Openmeetings CRITICAL 9.8
CVE-2023-28326

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privi…

Fix: 7.0.0+
Fix from $2,300 2023-03-28
Dubbo CRITICAL 9.8
CVE-2023-23638

A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.…

Fix: after 3.1.5
Fix from $2,300 2023-03-08
HTTP Server CRITICAL 9.8
CVE-2023-25690EPSS 85%

Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affec…

Fix: after 2.4.55
Fix from $2,300 2023-03-07
Apache Airflow Providers Google CRITICAL 9.8
CVE-2023-25691

Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.1…

Fix: 8.10.0+
Fix from $2,300 2023-02-24
Apache Airflow Providers Apache Sqoop CRITICAL 9.8
CVE-2023-25693

Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop Provider versions before 3.1.1.

Fix: 3.1.1+
Fix from $2,300 2023-02-24
Apache Airflow Providers Apache Hive CRITICAL 9.8
CVE-2023-25696

Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3.

Fix: 5.1.3+
Fix from $2,300 2023-02-24
Kerby Ldap Backend CRITICAL 9.8
CVE-2023-25613

An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3. 

Fix: 2.0.3+
Fix from $2,300 2023-02-20
Inlong CRITICAL 9.8
CVE-2023-24997

Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.…

Fix: after 1.5.0
Fix from $2,300 2023-02-01
Portable Runtime CRITICAL 9.8
CVE-2022-24963

Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a …

Mitigation only
Fix from $2,300 2023-01-31
Portable Runtime CRITICAL 9.8
CVE-2022-28331

On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of int…

Fix: after 1.7.0
Fix from $2,300 2023-01-31
Airflow CRITICAL 9.8
CVE-2023-22884EPSS 11%

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apach…

Fix: 2.5.1 / 4.0.0+
Fix from $2,300 2023-01-21
HTTP Server CRITICAL 9.0
CVE-2022-36760

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to sm…

Fix: 2.4.55+
Fix from $2,300 2023-01-17
Dolphinscheduler CRITICAL 9.8
CVE-2022-45875

Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects…

Fix: 3.0.2+
Fix from $2,300 2023-01-04
Dubbo CRITICAL 9.8
CVE-2021-32824

Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arb…

Fix: 2.6.10 / 2.7.10+
Fix from $2,300 2023-01-03
Kylin CRITICAL 9.8
CVE-2022-44621

Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.

Fix: 4.0.3+
Fix from $2,300 2022-12-30
Shardingsphere CRITICAL 9.8
CVE-2022-45347

Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session completely after client authentic…

Fix: 5.3.0+
Fix from $2,300 2022-12-22
Karaf CRITICAL 9.8
CVE-2022-40145

This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function …

Fix: 4.3.8 / 4.4.2+
Fix from $2,300 2022-12-21
Apache Airflow Providers Apache Hive CRITICAL 9.8
CVE-2022-46421

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive P…

Fix: 5.0.0+
Fix from $2,300 2022-12-20
Cxf CRITICAL 9.8
CVE-2022-46364

A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attack…

Fix: 3.4.10 / 3.5.5+
Fix from $2,300 2022-12-13
Tapestry CRITICAL 9.8
CVE-2022-46366

Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-1…

Fix: 4.0.0+
Fix from $2,300 2022-12-02
Dolphinscheduler CRITICAL 9.8
CVE-2022-45462

Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade…

Fix: 2.0.6+
Fix from $2,300 2022-11-23
Airflow CRITICAL 9.8
CVE-2022-40189

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airfl…

Fix: 2.3.0 / 4.0.0+
Fix from $2,300 2022-11-22
Airflow CRITICAL 9.8
CVE-2022-38649

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Air…

Fix: 2.3.0 / 4.0.0+
Fix from $2,300 2022-11-22
Sshd CRITICAL 9.8
CVE-2022-45047

Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized j…

Fix: after 2.9.1
Fix from $2,300 2022-11-16
Jena Sdb CRITICAL 9.8
CVE-2022-45136

Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the u…

Fix: after 3.17.0
Fix from $2,300 2022-11-14
Soap CRITICAL 9.8
CVE-2022-45378

In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invok…

Fix: after 2.3
Fix from $2,300 2022-11-14