Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Nuttx CRITICAL 9.8
CVE-2025-35003

Improper Restriction of Operations within the Bounds of a Memory Buffer and Stack-based Buffer Overflow vulnerabilities were discovered in Apache Nut…

Fix: 12.9.0+
Fix from $2,300 2025-05-26
Orc CRITICAL 9.8
CVE-2025-47436

Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially …

Fix: 1.8.9 / 1.9.6+
Fix from $2,300 2025-05-14
Iotdb CRITICAL 9.8
CVE-2024-24780

Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious fu…

Fix: 1.3.4+
Fix from $2,300 2025-05-14
Tomcat CRITICAL 9.8
CVE-2025-31651

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, i…

Fix: 9.0.104 / 10.1.40+
Fix from $2,300 2025-04-28
Activemq Nms Openwire CRITICAL 9.8
CVE-2025-29953

Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache ActiveMQ NMS OpenWire Client befor…

Fix: 2.1.1+
Fix from $2,300 2025-04-18
Pinot CRITICAL 9.8
CVE-2024-56325EPSS 79%

Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Normal Request and Response Examp…

Fix: 1.3.0+
Fix from $2,300 2025-04-01
Parquet Java CRITICAL 9.8
CVE-2025-30065EPSS 41%

Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are reco…

Fix: 1.15.1+
Fix from $2,300 2025-04-01
Seata CRITICAL 9.8
CVE-2024-47552

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): from 2.0.0 before 2.…

Fix: 2.2.0+
Fix from $2,300 2025-03-20
Tomcat CRITICAL 9.8
CVE-2025-24813 KEVEPSS 100%

Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploade…

Fix: 9.0.99 / 10.1.35+
Fix from $2,300 2025-03-10
Ranger CRITICAL 9.8
CVE-2024-55532

Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade…

Fix: 2.6.0+
Fix from $2,300 2025-03-03
Eventmesh CRITICAL 9.8
CVE-2024-56180

CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windo…

Fix: 1.11.0+
Fix from $2,300 2025-02-14
Ignite CRITICAL 9.0
CVE-2024-52577

In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerabili…

Fix: 2.17.0+
Fix from $2,300 2025-02-14
Ranger CRITICAL 9.1
CVE-2024-45479

SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger…

Fix: 2.5.0+
Fix from $2,300 2025-01-21
Openmeetings CRITICAL 9.8
CVE-2024-54676EPSS 65%

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions …

Fix: 8.0.0+
Fix from $2,300 2025-01-08
Mina CRITICAL 9.8
CVE-2024-52046EPSS 24%

The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary…

Fix: 2.0.27 / 2.1.10+
Fix from $2,300 2024-12-25
Hugegraph CRITICAL 9.8
CVE-2024-43441EPSS 69%

Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 bef…

Fix: 1.5.0+
Fix from $2,300 2024-12-24
Tomcat CRITICAL 9.8
CVE-2024-56337EPSS 9%

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, f…

Fix: 9.0.98 / 10.1.34+
Fix from $2,300 2024-12-20
Tomcat CRITICAL 9.8
CVE-2024-50379EPSS 44%

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file syste…

Fix: 9.0.98 / 10.1.34+
Fix from $2,300 2024-12-17
Struts CRITICAL 9.8
CVE-2024-53677EPSS 78%

File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances th…

Fix: 6.4.0+
Fix from $2,300 2024-12-11
Superset CRITICAL 9.8
CVE-2024-53947

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-s…

Fix: 4.1.0+
Fix from $2,300 2024-12-09
Arrow CRITICAL 9.8
CVE-2024-52338

Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execut…

Fix: 17.0.0+
Fix from $2,300 2024-11-28
Tomcat CRITICAL 9.8
CVE-2024-52316EPSS 6%

Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuth…

Fix: 9.0.96 / 10.1.31+
Fix from $2,300 2024-11-18
Ofbiz CRITICAL 9.8
CVE-2024-47208

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apac…

Fix: 18.12.17+
Fix from $2,300 2024-11-18
Traffic Server CRITICAL 9.1
CVE-2024-50306

Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through…

Fix: 9.2.6 / 10.0.2+
Fix from $2,300 2024-11-14
Cloudstack CRITICAL 9.9
CVE-2024-50386

Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the primary storage for deploying instan…

Fix: 4.18.2.5 / 4.19.1.3+
Fix from $2,300 2024-11-12
Zookeeper CRITICAL 9.1
CVE-2024-51504

When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofing -- this only impacts IP bas…

Fix: 3.9.3+
Fix from $2,300 2024-11-07
Kylin CRITICAL 9.1
CVE-2024-23590

Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to versio…

Fix: 5.0.0+
Fix from $2,300 2024-11-04
Solr CRITICAL 9.8
CVE-2024-45216EPSS 92%

Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authen…

Fix: 8.11.4 / 9.7.0+
Fix from $2,300 2024-10-16
Seata CRITICAL 9.8
CVE-2024-22399

Deserialization of Untrusted Data vulnerability in Apache Seata.  When developers disable authentication on the Seata-Server and do not use the Seat…

Fix: 1.8.1+
Fix from $2,300 2024-09-16
Ofbiz CRITICAL 9.8
CVE-2024-45507EPSS 93%

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apac…

Fix: 18.12.16+
Fix from $2,300 2024-09-04