Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-29216 In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source and malicious parameters to co… Linkis after 1.3.1 Fix from $2,3002023-04-10 CRITICAL 9.1 CVE-2023-27987 In Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy for attackers to obtain the de… Linkis after 1.3.1 Fix from $2,3002023-04-10 CRITICAL 9.8 CVE-2023-27602 In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recomme… Linkis after 1.3.1 Fix from $2,3002023-04-10 CRITICAL 9.8 CVE-2023-28706 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects… Airflow Hive Provider 6.0.0+ Fix from $2,3002023-04-07 CRITICAL 9.8 CVE-2023-28326 Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privi… Openmeetings 7.0.0+ Fix from $2,3002023-03-28 CRITICAL 9.8 CVE-2023-23638 A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.… Dubbo after 3.1.5 Fix from $2,3002023-03-08 CRITICAL 9.8 CVE-2023-25690EPSS 85% Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affec… HTTP Server after 2.4.55 Fix from $2,3002023-03-07 CRITICAL 9.8 CVE-2023-25691 Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.1… Apache Airflow Providers Google 8.10.0+ Fix from $2,3002023-02-24 CRITICAL 9.8 CVE-2023-25693 Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop Provider versions before 3.1.1. Apache Airflow Providers Apache Sqoop 3.1.1+ Fix from $2,3002023-02-24 CRITICAL 9.8 CVE-2023-25696 Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3. Apache Airflow Providers Apache Hive 5.1.3+ Fix from $2,3002023-02-24 CRITICAL 9.8 CVE-2023-25613 An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3.  Kerby Ldap Backend 2.0.3+ Fix from $2,3002023-02-20 CRITICAL 9.8 CVE-2023-24997 Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.… Inlong after 1.5.0 Fix from $2,3002023-02-01 CRITICAL 9.8 CVE-2022-24963 Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a … Portable Runtime Mitigation only Fix from $2,3002023-01-31 CRITICAL 9.8 CVE-2022-28331 On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of int… Portable Runtime after 1.7.0 Fix from $2,3002023-01-31 CRITICAL 9.8 CVE-2023-22884EPSS 11% Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apach… Airflow 2.5.1 / 4.0.0+ Fix from $2,3002023-01-21 CRITICAL 9.0 CVE-2022-36760 Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to sm… HTTP Server 2.4.55+ Fix from $2,3002023-01-17 CRITICAL 9.8 CVE-2022-45875 Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects… Dolphinscheduler 3.0.2+ Fix from $2,3002023-01-04 CRITICAL 9.8 CVE-2021-32824 Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arb… Dubbo 2.6.10 / 2.7.10+ Fix from $2,3002023-01-03 CRITICAL 9.8 CVE-2022-44621 Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request. Kylin 4.0.3+ Fix from $2,3002022-12-30 CRITICAL 9.8 CVE-2022-45347 Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session completely after client authentic… Shardingsphere 5.3.0+ Fix from $2,3002022-12-22 CRITICAL 9.8 CVE-2022-40145 This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function … Karaf 4.3.8 / 4.4.2+ Fix from $2,3002022-12-21 CRITICAL 9.8 CVE-2022-46421 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive P… Apache Airflow Providers Apache Hive 5.0.0+ Fix from $2,3002022-12-20 CRITICAL 9.8 CVE-2022-46364 A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attack… Cxf 3.4.10 / 3.5.5+ Fix from $2,3002022-12-13 CRITICAL 9.8 CVE-2022-46366 Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-1… Tapestry 4.0.0+ Fix from $2,3002022-12-02 CRITICAL 9.8 CVE-2022-45462 Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade… Dolphinscheduler 2.0.6+ Fix from $2,3002022-11-23 CRITICAL 9.8 CVE-2022-40189 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airfl… Airflow 2.3.0 / 4.0.0+ Fix from $2,3002022-11-22 CRITICAL 9.8 CVE-2022-38649 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Air… Airflow 2.3.0 / 4.0.0+ Fix from $2,3002022-11-22 CRITICAL 9.8 CVE-2022-45047 Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized j… Sshd after 2.9.1 Fix from $2,3002022-11-16 CRITICAL 9.8 CVE-2022-45136 Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the u… Jena Sdb after 3.17.0 Fix from $2,3002022-11-14 CRITICAL 9.8 CVE-2022-45378 In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invok… Soap after 2.3 Fix from $2,3002022-11-14