Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Cxf CRITICAL 9.3
CVE-2024-28752

A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style att…

Fix: 3.5.8 / 3.6.3+
Fix from $2,300 2024-03-15
Pulsar CRITICAL 9.9
CVE-2024-27135EPSS 6%

Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function w…

Fix: 2.10.6 / 2.11.4+
Fix from $2,300 2024-03-12
Pulsar CRITICAL 9.9
CVE-2024-27317EPSS 57%

In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip files, are extracted by the Fu…

Fix: 2.10.6 / 2.11.4+
Fix from $2,300 2024-03-12
Doris CRITICAL 9.8
CVE-2023-41313

The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended to upgrade to version 2.0.0 +…

Fix: 1.2.8+
Fix from $2,300 2024-03-12
Inlong CRITICAL 9.1
CVE-2024-26580

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.10.0, the attackers can use…

Fix: 1.11.0+
Fix from $2,300 2024-03-06
Ofbiz CRITICAL 9.1
CVE-2024-25065EPSS 48%

Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

Fix: 18.12.12+
Fix from $2,300 2024-02-29
Xerces C\+\+ CRITICAL 9.8
CVE-2024-23807

The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. User…

Fix: 3.2.5+
Fix from $2,300 2024-02-29
Aurora CRITICAL 9.1
CVE-2024-27905

** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Aurora. An endpoint exposing inte…

Mitigation only
Fix from $2,300 2024-02-27
James CRITICAL 9.8
CVE-2023-51518

Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserialisation of untrusted data. Gi…

Mitigation only
Fix from $2,300 2024-02-27
Hertzbeat CRITICAL 9.8
CVE-2023-51388

Hertzbeat is a real-time monitoring system. In `CalculateAlarm.java`, `AviatorEvaluator` is used to directly execute the expression function, and no …

Fix: 1.4.1+
Fix from $2,300 2024-02-22
Hertzbeat CRITICAL 9.8
CVE-2023-51389

Hertzbeat is a real-time monitoring system. At the interface of `/define/yml`, SnakeYAML is used as a parser to parse yml content, but no security co…

Fix: 1.4.1+
Fix from $2,300 2024-02-22
Hertzbeat CRITICAL 9.8
CVE-2023-51653

Hertzbeat is a real-time monitoring system. In the implementation of `JmxCollectImpl.java`, `JMXConnectorFactory.connect` is vulnerable to JNDI injec…

Fix: 1.4.1+
Fix from $2,300 2024-02-22
Answer CRITICAL 9.1
CVE-2024-22393

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack b…

Fix: 1.2.5+
Fix from $2,300 2024-02-22
Apache Airflow Providers Mongo CRITICAL 9.1
CVE-2024-25141

When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpecte…

Fix: 4.0.0+
Fix from $2,300 2024-02-20
Camel CRITICAL 9.8
CVE-2024-23114

Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserializa…

Fix: 3.21.4 / 4.0.4+
Fix from $2,300 2024-02-20
Dolphinscheduler CRITICAL 9.8
CVE-2023-49109

Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgr…

Fix: 3.2.1+
Fix from $2,300 2024-02-20
Iotdb CRITICAL 9.8
CVE-2023-46226

Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2. Users are recommended to upgrade to v…

Fix: 1.3.0+
Fix from $2,300 2024-01-15
Inlong CRITICAL 9.8
CVE-2023-51784

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, …

Fix: 1.10.0+
Fix from $2,300 2024-01-03
Ofbiz CRITICAL 9.8
CVE-2023-51467EPSS 96%

The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code

Fix: 18.12.11+
Fix from $2,300 2023-12-26
Iotdb CRITICAL 9.8
CVE-2023-51656

Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4. Users are recommended t…

Fix: after 0.13.4
Fix from $2,300 2023-12-21
Dubbo CRITICAL 9.8
CVE-2023-29234EPSS 7%

A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 throug…

Fix: after 3.2.4
Fix from $2,300 2023-12-15
Dubbo CRITICAL 9.8
CVE-2023-46279

Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the …

Mitigation only
Fix from $2,300 2023-12-15
Struts CRITICAL 9.8
CVE-2023-50164EPSS 81%

An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file whic…

Fix: 2.5.33 / 6.3.0.2+
Fix from $2,300 2023-12-07
Ofbiz CRITICAL 9.8
CVE-2023-49070EPSS 95%

Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Us…

Fix: 18.12.10+
Fix from $2,300 2023-12-05
Cocoon CRITICAL 9.8
CVE-2023-49733

Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. User…

Fix: 2.3.0+
Fix from $2,300 2023-11-30
Cocoon CRITICAL 9.8
CVE-2022-45135

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This issue affects Apache Cocoon:…

Fix: 2.3.0+
Fix from $2,300 2023-11-30
Submarine CRITICAL 9.8
CVE-2023-37924EPSS 7%

Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can result in unauthorized login. Now …

Fix: 0.8.0+
Fix from $2,300 2023-11-22
Derby CRITICAL 9.8
CVE-2022-46337

A cleverly devised username might bypass LDAP authentication checks. In LDAP-authenticated Derby installations, this could let an attacker fill up …

Fix: 10.14.3.0 / 10.15.2.1+
Fix from $2,300 2023-11-20
Submarine CRITICAL 9.8
CVE-2023-46302

Apache Software Foundation Apache Submarine has a bug when serializing against yaml. The bug is caused by snakeyaml https://nvd.nist.gov/vuln/detail…

Fix: 0.8.0+
Fix from $2,300 2023-11-20
Pyarrow CRITICAL 9.8
CVE-2023-47248EPSS 15%

Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is …

Fix: after 14.0.0
Fix from $2,300 2023-11-09