Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Hertzbeat CRITICAL 9.8
CVE-2024-42361

Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoin…

Fix: 1.6.0+
Fix from $2,300 2024-08-20
Dolphinscheduler CRITICAL 9.8
CVE-2024-43202

Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgr…

Fix: 3.2.2+
Fix from $2,300 2024-08-20
Ofbiz CRITICAL 9.8
CVE-2024-38856 KEVEPSS 99%

Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to versi…

Fix: 18.12.15+
Fix from $2,300 2024-08-05
Apache Airflow Providers Fab CRITICAL 9.8
CVE-2024-42447

Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB. This issue affects Apache Airflow Providers FAB: 1.2.1 (when used wit…

Patch available
Fix from $2,300 2024-08-05
Inlong CRITICAL 9.8
CVE-2024-36268

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.10.0 through 1.12…

Fix: 1.13.0+
Fix from $2,300 2024-08-02
Seatunnel CRITICAL 9.1
CVE-2023-48396

Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can forge any token to log in an…

Mitigation only
Fix from $2,300 2024-07-30
Streampark CRITICAL 9.1
CVE-2024-29070

On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" …

Fix: 2.1.4+
Fix from $2,300 2024-07-23
Cxf CRITICAL 9.1
CVE-2024-29736

A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style att…

Fix: 3.5.9 / 3.6.4+
Fix from $2,300 2024-07-19
Superset CRITICAL 9.8
CVE-2024-39887

An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certa…

Fix: 4.0.2+
Fix from $2,300 2024-07-16
Wicket CRITICAL 9.8
CVE-2024-36522

The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when processing input from an untruste…

Fix: 8.16.0 / 9.18.0+
Fix from $2,300 2024-07-12
Cloudstack CRITICAL 9.8
CVE-2024-39864

The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via integratio…

Fix: 4.18.2.1 / 4.19.0.2+
Fix from $2,300 2024-07-05
Cloudstack CRITICAL 9.8
CVE-2024-38346

The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and …

Fix: 4.18.2.1 / 4.19.0.2+
Fix from $2,300 2024-07-05
HTTP Server CRITICAL 9.8
CVE-2024-38474

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by th…

Fix: 2.4.60+
Fix from $2,300 2024-07-01
HTTP Server CRITICAL 9.8
CVE-2024-38476EPSS 42%

Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend a…

Fix: 2.4.60+
Fix from $2,300 2024-07-01
HTTP Server CRITICAL 9.1
CVE-2024-38475 KEVEPSS 100%

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are p…

Fix: 2.4.60 / 10.2.1.14-75sv+
Fix from $2,300 2024-07-01
Streampipes CRITICAL 9.1
CVE-2024-29868EPSS 6%

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery …

Fix: after 0.93.0
Fix from $2,300 2024-06-24
Submarine CRITICAL 9.8
CVE-2024-36265

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Co…

Mitigation only
Fix from $2,300 2024-06-12
Submarine CRITICAL 9.8
CVE-2024-36264

** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submari…

Patch available
Fix from $2,300 2024-06-12
Ofbiz CRITICAL 9.1
CVE-2024-36104EPSS 87%

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before…

Fix: 18.12.14+
Fix from $2,300 2024-06-04
Karaf Cave CRITICAL 9.1
CVE-2024-34365

** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Karaf Cave.This issue affects all versions of Apache Karaf Cave. A…

Mitigation only
Fix from $2,300 2024-05-14
Ofbiz CRITICAL 9.8
CVE-2024-32113 KEVEPSS 99%

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before …

Fix: 18.12.13+
Fix from $2,300 2024-05-08
Inlong CRITICAL 9.8
CVE-2024-26579

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0,  the attackers can by…

Fix: 1.12.0+
Fix from $2,300 2024-05-08
Hugegraph CRITICAL 9.8
CVE-2024-27348 KEVEPSS 99%

RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & …

Fix: 1.3.0+
Fix from $2,300 2024-04-22
Hugegraph CRITICAL 9.1
CVE-2024-27349

Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0. User…

Fix: 1.3.0+
Fix from $2,300 2024-04-22
Zeppelin CRITICAL 9.8
CVE-2024-31864

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malic…

Fix: 0.11.1+
Fix from $2,300 2024-04-09
Zeppelin CRITICAL 9.8
CVE-2024-31866

Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or malicious code by overriding co…

Fix: 0.11.1+
Fix from $2,300 2024-04-09
Cloudstack CRITICAL 9.8
CVE-2024-29006

By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an API request. This could lead t…

Fix: 4.18.1.1+
Fix from $2,300 2024-04-04
Fineract CRITICAL 9.8
CVE-2024-23538

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Finer…

Fix: 1.9.0+
Fix from $2,300 2024-03-29
Fineract CRITICAL 9.8
CVE-2024-23539

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Finer…

Fix: 1.9.0+
Fix from $2,300 2024-03-29
Doris CRITICAL 9.8
CVE-2024-27438

Download of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is not checked and may resulting …

Fix: 2.0.5+
Fix from $2,300 2024-03-21