Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Activemq CRITICAL 9.8
CVE-2023-46604 KEVEPSS 100%

The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to…

Fix: 5.15.16 / 5.16.7+
Fix from $2,300 2023-10-27
Inlong CRITICAL 9.8
CVE-2023-43668

Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,  some se…

Fix: after 1.8.0
Fix from $2,300 2023-10-16
Zookeeper CRITICAL 9.1
CVE-2023-44981

Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quoru…

Fix: 3.7.2 / 3.8.3+
Fix from $2,300 2023-10-11
Axis CRITICAL 9.8
CVE-2023-40743

** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "S…

Fix: 2023-08-01+
Fix from $2,300 2023-09-05
Traffic Server CRITICAL 9.1
CVE-2023-33934

Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.

Fix: after 9.2.1
Fix from $2,300 2023-08-09
Helix CRITICAL 9.8
CVE-2023-38647

An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.S…

Fix: 1.3.0+
Fix from $2,300 2023-07-26
Jackrabbit CRITICAL 9.8
CVE-2023-37895

Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (in…

Fix: 2.20.11 / 2.21.18+
Fix from $2,300 2023-07-25
Inlong CRITICAL 9.8
CVE-2023-35088

Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This i…

Fix: after 1.7.0
Fix from $2,300 2023-07-25
Shiro CRITICAL 9.8
CVE-2023-34478

Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used togeth…

Fix: 1.12.0+
Fix from $2,300 2023-07-24
Eventmesh Connector Rabbitmq CRITICAL 9.8
CVE-2023-26512

CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac…

Fix: after 1.8.0
Fix from $2,300 2023-07-17
Rocketmq CRITICAL 9.8
CVE-2023-37582EPSS 90%

The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version …

Fix: after 5.1.1
Fix from $2,300 2023-07-12
Apache Airflow Providers Apache Hive CRITICAL 9.8
CVE-2023-35797

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects Apache Airflow Apache Hive Pro…

Fix: 6.1.1+
Fix from $2,300 2023-07-03
Accumulo CRITICAL 9.8
CVE-2023-34340

Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo: 2.1.0. Accumulo 2.1.0 conta…

Mitigation only
Fix from $2,300 2023-06-21
Rocketmq CRITICAL 9.8
CVE-2023-33246 KEVEPSS 97%

For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, inclu…

Fix: 4.9.6 / 5.1.1+
Fix from $2,300 2023-05-24
Inlong CRITICAL 9.8
CVE-2023-31098

Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.6.0.  Wh…

Fix: after 1.6.0
Fix from $2,300 2023-05-22
Inlong CRITICAL 9.1
CVE-2023-31065

Insufficient Session Expiration vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0.…

Fix: after 1.6.0
Fix from $2,300 2023-05-22
Inlong CRITICAL 9.1
CVE-2023-31066

Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from …

Fix: after 1.6.0
Fix from $2,300 2023-05-22
Inlong CRITICAL 9.8
CVE-2023-31062

Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0.…

Fix: after 1.6.0
Fix from $2,300 2023-05-22
Sling Commons Json CRITICAL 9.8
CVE-2022-47937

Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted inpu…

Fix: after 2.0.20
Fix from $2,300 2023-05-15
Airflow CRITICAL 9.8
CVE-2023-25754

Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0.

Fix: 2.6.0+
Fix from $2,300 2023-05-08
Brpc CRITICAL 9.8
CVE-2023-31039

Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptions::pid_file. An attacker tha…

Fix: 1.5.0+
Fix from $2,300 2023-05-08
Streampark CRITICAL 9.1
CVE-2022-46365

Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a …

Fix: 2.0.0+
Fix from $2,300 2023-05-01
Streampark CRITICAL 9.8
CVE-2022-45802

Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload…

Fix: 2.0.0+
Fix from $2,300 2023-05-01
Superset CRITICAL 9.8
CVE-2023-27524 KEVEPSS 97%

Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_K…

Fix: after 2.0.1
Fix from $2,300 2023-04-24
Spark CRITICAL 9.9
CVE-2023-22946

In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application c…

Fix: 3.4.0+
Fix from $2,300 2023-04-17
Iotdb Web Workbench CRITICAL 9.8
CVE-2023-30771

Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotd…

Mitigation only
Fix from $2,300 2023-04-17
Iotdb CRITICAL 9.8
CVE-2023-24831

Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana Connector: from 0.13.0 throu…

Fix: after 0.13.3
Fix from $2,300 2023-04-17
Apache Sling Engine CRITICAL 9.0
CVE-2022-45064

The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-based cross-site scripting is…

Fix: 2.14.0+
Fix from $2,300 2023-04-13
Linkis CRITICAL 9.8
CVE-2023-27603

In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead…

Fix: after 1.3.1
Fix from $2,300 2023-04-10
Linkis CRITICAL 9.8
CVE-2023-29215

In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC Eengi…

Fix: after 1.3.1
Fix from $2,300 2023-04-10